Framework National Cyber & Cloud Schemes
ECC
The Essential Cybersecurity Controls (ECC) are Saudi Arabia's baseline cybersecurity requirements, issued by the National Cybersecurity Authority.
The first edition (ECC-1:2018) was replaced by ECC-2:2024, which contains 108 controls with 92 subcontrols across four domains: cybersecurity governance, cybersecurity defense, cybersecurity resilience, and third-party and cloud cybersecurity, organized into 28 subdomains.
The controls require a formal cybersecurity function reporting to the head of the organization, a strategy and policy set, risk management, asset management, identity and access controls, network and endpoint protection, logging and monitoring, vulnerability and patch management, incident response with notification to the NCA, business continuity, and controls over outsourcing and cloud.
Sector regulators such as SAMA and the Communications, Space and Technology Commission layer their own frameworks on top, and the NCA publishes companion control sets (Cloud Cybersecurity Controls, Critical Systems Cybersecurity Controls, Telework, OSMACC for social media, and Data Cybersecurity Controls).
In writing, an in-scope organization needs a cybersecurity strategy, a charter for the cybersecurity function and steering committee, a full policy and procedure set mapped to each ECC subdomain, a risk register, asset inventory and classification, incident response plan and NCA notification procedure, business continuity plans with test records, third-party and cloud contracts with the required clauses, awareness program records, and periodic compliance self-assessments filed with the NCA.
help
Who has to comply
All Saudi government organizations (ministries, authorities, establishments and others) and their companies and entities inside or outside the Kingdom, and private sector organizations that own, operate, or host critical national infrastructure. Other organizations are encouraged to adopt the controls, and many sector regulators and large buyers require them contractually.
What the assessor asks to see
Cybersecurity strategy and roadmap; cybersecurity function charter and committee minutes; policy and procedure set per subdomain; risk register and treatment plans; asset inventory and classification; identity and access management records including privileged access; network security architecture; endpoint and email protection configuration; logging and monitoring coverage; vulnerability scans and patching records; penetration test reports; incident response plan, incident register, and NCA notifications; business continuity and disaster recovery plans and tests; third-party and cloud contracts and assessments; awareness training records; compliance self-assessment reports to the NCA.
Assessors
Who assesses ECC
Self-assessment and reporting by the organization, reviewed by the NCA, which may audit and verify directly; sector regulators may conduct their own reviews. No private certification scheme exists for the ECC. the NCA is the regulator and reviewer.
No firm has claimed a ECC assessor listing yet. Claim yours →
Consultants
Who helps with ECC
A large Saudi and regional market: cybersecurity consultancies, the local arms of global firms, and GRC platform vendors offer gap assessments, policy libraries mapped to the ECC, and compliance reporting. Engagements run six to eighteen months for a full program.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a ECC consultant listing yet. Claim yours →
Software
Tools for ECC
Tools that name this framework in their own material.
No firm has claimed a ECC tool listing yet. Claim yours →
Related reading
- Saudi Arabia's Essential Cybersecurity Controls 2024 (ECC-2): key updates and implicationsExplains what ECC-2 changed from ECC-1, including the staffing mandate and where data localisation obligations moved to.Clyde & Co
- Saudi Arabia: cybersecurity controls for private entitiesCovers how the NCA controls now reach private sector organisations, not only government and critical infrastructure.Baker McKenzie
- Cybersecurity compliance handbook for the Kingdom of Saudi ArabiaPlaces the ECC within the wider set of Saudi cybersecurity and data frameworks an organisation may have to satisfy at once.PwC Middle East
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for ECC
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with ECC
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.