Skip to main content
NCA ECC · Saudi Arabia

Win and keep Saudi contracts with ECC evidence your board can sign off.

NCA ECC is the baseline cybersecurity standard for Saudi government bodies and operators of critical national infrastructure, and it increasingly shapes who their suppliers can be. Summit gets you assessment-ready with tested evidence and a board-ready report.

Human-led VAPT · NDA first · report in 48h

4
main domains: governance, defense, resilience, and third-party and cloud
28
subdomains in ECC-2:2024, as published by the NCA
2018 → 2024
first issued as ECC-1:2018, then updated to ECC-2:2024
3
related NCA control sets built on it: cloud (CCC), data (DCC) and critical systems (CSCC)
Board and leadership view

Why NCA ECC matters to your board

The work is technical. The consequences of getting NCA ECC wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Contracts and market access

Saudi government and critical-infrastructure customers write ECC into tenders and renewals. Missing evidence can slow a deal or take you out of the running.

Regulatory exposure

Obligations sit with named entities and their leaders. Clear, tested evidence shows management took reasonable steps and knew where the gaps were.

Reputation

A security incident at a supplier to the public sector becomes headline news. Tested controls lower the odds and show you were prepared.

Deadlines and ownership

Reviews and contract dates do not move. A scoped plan with named owners and a single accountable team keeps the work on schedule.

Fit

Who usually needs NCA ECC

Government bodies and their suppliers

Ministries, authorities and the companies that run services for them are held to ECC, and pass those expectations down in contracts.

Energy, utilities and telecoms

Operators of critical national infrastructure are directly in scope and expect their vendors to show the same discipline.

Banks and financial services

Regulated firms use ECC-style controls to structure their own programmes and to review technology providers.

Technology and managed service providers

If you host, build or run systems for Saudi customers, expect ECC requirements in tenders and security reviews.

Scope of work

What Summit delivers for NCA ECC

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

Your controls compared with ECC requirements, with each gap ranked by risk and effort.

Penetration testing

Manual testing of the systems in scope, with proof of impact and clear reproduction steps.

Control validation

We check that controls operate in practice: configurations, access, logging and recovery.

Evidence pack

Findings, test results and artefacts organised by control, ready for your review.

Remediation support and retest

Guidance for your engineers, then a retest that confirms every fix.

Board-ready report

A plain-language summary of risk, progress and next decisions for executives.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A practical ECC readiness path

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Confirm scope and ownership

    Weeks 1 to 2

    Agree which entities, systems and services fall under ECC and who is accountable for each domain.

  2. 2

    Run a gap analysis

    Weeks 2 to 5

    Compare your current controls with each ECC requirement and rank the gaps by risk and effort.

  3. 3

    Close the gaps

    Months 2 to 4

    Write or update policies, fix technical weaknesses and make sure controls leave evidence automatically.

  4. 4

    Validate with testing

    Months 3 to 4

    Penetration testing and control validation prove the controls hold up against a real attacker, not just on paper.

  5. 5

    Retest and build the evidence pack

    Month 4 to 5

    Confirm fixes, organise evidence by control, and prepare the board-ready report.

  6. 6

    Support your review

    Ongoing

    Summit stays with you through questions from the NCA, your regulator or your customer.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • One-page risk summary

    Where you stand against ECC today, in language that needs no technical background.

  • Prioritised decisions

    What needs budget or sign-off, in order, with the business reason.

  • Owners and dates

    Who is responsible for each remediation and when it should be done.

  • Evidence status

    Which controls have proof ready and which still need work.

  • Retest results

    Confirmation that fixes held, to take into reviews with regulators or customers.

The detail

What NCA ECC actually is

The Essential Cybersecurity Controls (ECC) are published by Saudi Arabia’s National Cybersecurity Authority (NCA). They set the minimum cybersecurity requirements for organisations in scope, organised into four main domains: Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience and Third-Party and Cloud Computing Cybersecurity.

The controls apply to Saudi government entities and to private-sector organisations that own, operate or host critical national infrastructure. The NCA also encourages other organisations in the Kingdom to adopt them as good practice. In reality, many companies meet ECC because a government customer or regulated buyer has put it in the contract.

ECC is the foundation for the NCA’s more specific control sets. The Cloud Cybersecurity Controls and Data Cybersecurity Controls are written to sit alongside it, so getting ECC right first saves rework later. Whether your evidence is accepted is decided by the NCA or the entity that requested it.

Key terms in plain English

Control
A single requirement, such as “multi-factor authentication for privileged access”, that you must implement and be able to prove.
Subdomain
A topic group inside a main domain, such as identity and access management or vulnerability management.
CNI
Critical national infrastructure: the systems and services a country’s economy and safety depend on.
Evidence pack
The policies, configurations, logs, test reports and sign-offs that show each control exists and works.
Requirements

What ECC asks for, domain by domain

ECC is written as control statements rather than a checklist. Here is what each domain means in everyday security and operations work.

1

Cybersecurity Governance

Strategy, policies, roles, risk management and awareness. This is where leadership accountability sits: assessors want to see that cybersecurity has an owner, a budget, a risk process and management oversight.

What it looks like in practice

  • An approved cybersecurity strategy and policy set
  • Named roles and a reporting line to senior management
  • A risk register that is reviewed on a schedule
  • Training and awareness records for staff
2

Cybersecurity Defense

The largest domain. It covers asset management, identity and access, system and network protection, email, mobile, data protection and cryptography, backups, vulnerability management, penetration testing, logging and monitoring, and incident management.

What it looks like in practice

  • Asset inventories and secure configuration baselines
  • Multi-factor authentication and privileged access control
  • Vulnerability management and periodic penetration testing
  • Central logging with monitoring and incident handling
3

Cybersecurity Resilience

Continuity of operations when something goes wrong. Assessors look at how cybersecurity fits into business continuity and disaster recovery, and whether those plans have actually been tested.

What it looks like in practice

  • Continuity and recovery plans that include cybersecurity
  • Recovery objectives agreed with the business
  • Exercises and test results, not only documents
4

Third-Party and Cloud Computing Cybersecurity

Security of the suppliers you rely on and the cloud services you use. Contracts, due diligence and ongoing oversight matter here, and for cloud use ECC is complemented by the NCA’s Cloud Cybersecurity Controls.

What it looks like in practice

  • Supplier security requirements written into contracts
  • A register of suppliers and cloud services in use
  • Evidence that supplier controls are reviewed
  • Clear rules for where data is hosted
Where testing fits

How penetration testing supports NCA ECC

ECC expects you to find weaknesses before attackers do and to prove that your controls work. Penetration testing and control validation give you dated, independent evidence to attach to the relevant controls.

Defense

Vulnerability management

Testing finds what scanners miss, and the retest shows each finding was closed.

Defense

Penetration testing

Manual testing of internet-facing and internal systems, with a report mapped to the controls it supports.

Governance

Risk management

Findings feed the risk register with real, evidence-backed ratings instead of estimates.

Third-party

Supplier and cloud security

Testing the cloud and supplier-connected parts of your environment shows how those boundaries hold up.

Avoid these

Common NCA ECC mistakes, and how to avoid them

!

Treating ECC as a document exercise

Assessors look for controls that operate. Policies without configurations, logs and test results leave gaps.

!

Unclear scope

If it is not clear which systems are in scope, evidence is scattered and the review drags on.

!

Testing once and filing the report

Findings need owners, deadlines and a retest. An unfixed report is a liability, not evidence.

!

Ignoring the related control sets

Cloud and data controls build on ECC. Planning them together avoids duplicate effort.

FAQ

NCA ECC questions, answered

Who must meet NCA ECC?

Saudi government entities and private-sector organisations that own, operate or host critical national infrastructure. The NCA encourages everyone else in the Kingdom to use it, and suppliers often meet it because a customer requires it.

Is ECC a certificate?

No. It is a set of control requirements. How your compliance is reviewed and accepted is decided by the NCA or the entity that asked for it.

What version is current?

ECC-2:2024, which updates ECC-1:2018. Check the NCA website for the latest text before you plan.

How is ECC related to CCC and DCC?

The Cloud and Data Cybersecurity Controls are designed to complement ECC. ECC is the baseline, and CCC or DCC add detail where cloud services or data protection apply.

Does ECC require penetration testing?

Yes, its defense domain includes vulnerability management and penetration testing. A manual test with a retest is the clearest way to show it.

How long does readiness take?

It depends on where you start. A well-run organisation can be ready in a few months; those building from scratch should plan for longer.

Is this legal advice?

No. It is educational. For binding interpretation, refer to the NCA’s published documents and your own counsel.

Ready to get NCA ECC sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →