Most organisations do not fail an NCA assessment because their security is weak. They fail because the controls were implemented in the wrong order, the evidence was never captured, or nobody owned the outcome. This guide is the sequence we use on real engagements.
Before you start: confirm which edition of the ECC your assessment will be measured against. The original ECC-1:2018 defines 5 domains and 114 controls; the NCA has since issued an updated edition. Always work from the official document published by the National Cybersecurity Authority — this guide is practitioner commentary, not a substitute for it.
Who has to comply
The ECC is mandatory for:
- Government entities — ministries, authorities, and institutions, including their companies and subsidiaries.
- Critical National Infrastructure operators — private-sector organisations that own, operate, or host CNI, which in practice captures much of banking, energy, telecom, health, and transport.
Every other organisation in the Kingdom is encouraged to adopt it. In our experience that distinction matters less each year: banks increasingly push ECC-aligned requirements down to their suppliers, so if you sell into a regulated entity, you will be asked about it regardless of whether the NCA regulates you directly.
How the framework is structured
The ECC organises controls into five domains. The order below is not arbitrary — governance sits at the top because almost every technical control downstream depends on a decision, an owner, or a policy defined there.
| Domain | What it covers | Where teams struggle |
|---|---|---|
| 1. Cybersecurity Governance | Strategy, cybersecurity management, policies and procedures, roles and responsibilities, risk management, cybersecurity in project management, compliance, periodic review and audit, human resources, and the awareness programme. | Policies exist but were never formally approved, or name owners who have since left. |
| 2. Cybersecurity Defence | Asset management, identity and access management, system and facility protection, email, network security, mobile devices, data protection, cryptography, backup and recovery, vulnerability management, penetration testing, logging and monitoring, incident management, physical security, and web application security. | The largest domain by far. Asset inventory gaps undermine nearly every control in it. |
| 3. Cybersecurity Resilience | Cybersecurity aspects of business continuity — the ability to keep operating through a cyber incident and recover deliberately. | Continuity plans exist for fire and power, but never assumed a ransomware scenario. |
| 4. Third-Party & Cloud Computing | Third-party cybersecurity requirements and cloud computing and hosting cybersecurity. | Contracts signed before the requirements existed, with no right-to-audit clause. |
| 5. Industrial Control Systems | Protection of ICS and OT environments — applicable to entities operating industrial systems. | OT is owned by engineering, not IT security, so it falls outside the programme entirely. |
The checklist, in the order that works
Running these in parallel is how programmes stall. Each phase below produces something the next phase depends on.
Establish the mandate and scope
Appoint a cybersecurity function reporting to the head of the entity, and define scope precisely — which entities, systems, sites, and subsidiaries are in.
- Documented appointment of the cybersecurity function and its authority
- Approved scope statement, including exclusions and the rationale for them
- Steering committee with named members and a meeting cadence
Build the asset inventory first
This is the control we most often see skipped, and it silently blocks a dozen others. You cannot patch, classify, monitor, or restrict access to assets you have not enumerated.
- Inventory of information and technology assets with named owners
- Classification applied to data and systems
- A defined process for keeping the inventory current — not a one-off spreadsheet
Run the gap assessment against every control
Assess each control as implemented, partially implemented, or not implemented — and record the evidence reference for anything you claim as implemented. Claims without references are the single biggest source of assessment findings.
- Control-by-control gap register with current status and target date
- Risk rating for each gap, tied to business impact
- An approved remediation roadmap with named owners
Write the policy set — and get it approved
Documents that were never formally approved do not count. Approval, version, date, and owner matter as much as content.
- Cybersecurity policy, plus supporting standards and procedures per domain
- Formal approval by the authorising body, with dates and version history
- Evidence the policies were communicated to staff
Close the technical controls in dependency order
Identity, logging, and vulnerability management first — they generate the evidence that later controls rely on.
- Identity and access management, including privileged access and periodic access reviews
- Centralised event logging and monitoring, with defined retention
- Vulnerability management with remediation SLAs, plus penetration testing
- Backup and recovery, with restoration actually tested
- Email, network, endpoint, cryptography, and web application controls
Extend to third parties and cloud
Requirements must reach your suppliers contractually, not just internally.
- Third-party cybersecurity requirements embedded in contracts
- Due diligence performed before onboarding, and periodically after
- Cloud responsibilities mapped explicitly — what the provider covers and what you still own
Prove resilience, don't assert it
A plan that has never been exercised is a document, not a capability.
- Cyber scenarios included in business continuity planning
- Incident response plan with defined roles and escalation
- Exercise records — tabletop or technical — with lessons captured and actioned
Operate the review cycle
The ECC expects periodic review and audit. This is what converts a one-time project into sustained compliance — and it is where organisations relapse in year two.
- Scheduled internal cybersecurity review and audit, with results reported upward
- Awareness and training programme running on a defined cycle
- Metrics reported to leadership, with corrective actions tracked to closure
What maturity actually looks like
Assessors are not looking for perfection on day one. They are looking for controls that are defined, applied consistently, evidenced, and reviewed. The distance between "we do this" and "we can prove we do this, every time" is where most of the real work sits.
The five mistakes that cost the most time
- Starting with tools. Buying a SIEM before defining what must be logged, retained, and reviewed produces expensive noise and no evidence.
- Treating it as an IT project. Governance, HR, procurement, and legal controls cannot be delivered by the security team alone.
- Documenting intent instead of practice. A policy stating that access is reviewed quarterly, with no review records, is worse than no policy — it demonstrates a control failure.
- Ignoring OT. Where industrial systems are in scope, they are frequently discovered late, and remediation there is slow and change-controlled.
- Stopping at the assessment. Compliance decays. Without the review cycle in phase eight, the next assessment starts from a worse position than the last.
Realistic timelines
| Starting position | Time to assessment-ready |
|---|---|
| Formal governance, asset inventory, and logging already in place | 3–5 months |
| Partial controls, informal documentation, some logging | 6–9 months |
| No cybersecurity function, no inventory, no centralised logging | 12 months or more |
The variable is rarely technology. It is how quickly decisions get made, owners get named, and evidence starts being captured as routine rather than as an exercise before an audit.
Frequently asked questions
Who must comply with the NCA Essential Cybersecurity Controls?
Government entities in Saudi Arabia — ministries, authorities, and institutions — along with their companies and subsidiaries, and private-sector organisations that own, operate, or host Critical National Infrastructure. All other organisations are encouraged to adopt the controls.
How many controls are in the NCA ECC?
ECC-1:2018 is structured as 5 main domains, 29 subdomains, and 114 main controls. The NCA has since published an updated edition — confirm the applicable version before scoping.
How long does NCA ECC compliance take?
Six to nine months is realistic for a mid-sized organisation with a partial baseline. Starting with no governance, inventory, or logging typically means twelve months or more, because those three foundations gate most other controls.
What is the most common reason organisations fail?
Missing evidence rather than missing controls. Teams often perform the activity but cannot produce dated, approved records proving it happens consistently. Assessors evaluate documented, repeatable practice.
How does the ECC relate to SAMA CSF and ISO 27001?
They overlap substantially. A single control — access review, logging, incident response — usually satisfies requirements in all three. Mapping them once and collecting evidence a single time is significantly cheaper than running three separate programmes, which is how many organisations end up working.
Working through this now? Our Cyber Risk & Compliance practice runs ECC gap assessments, builds the remediation roadmap, and prepares the evidence pack — mapped against SAMA CSF, PDPL, and ISO 27001 at the same time so the work counts once.
How we help with ECC
Start with a gap assessment
Know exactly which of the 114 controls you meet today — and what it takes to close the rest.
Book Your Assessment