Get Demo
Saudi NCA · ECC–2:2024 · Mandatory for Government & CNI

NCA Essential Cybersecurity Controls (ECC) Compliance Automation

Automate Saudi Arabia’s Essential Cybersecurity Controls — 4 domains, 28 subdomains, 108 main controls, and 92 subcontrols — with continuous evidence collection, SIEM-backed logging for subdomain 2-12, and audit-ready reporting for government entities and CNI operators.

4Main Domains
28Subdomains
108Main Controls
92Subcontrols

What Is NCA ECC — and Who Must Comply?

The Essential Cybersecurity Controls (ECC–2:2024) are the National Cybersecurity Authority’s baseline cybersecurity framework for Saudi Arabia. Issued by the NCA and published on nca.gov.sa, ECC sets the minimum cybersecurity requirements national entities must implement to protect information and technology assets. The current version updates ECC–1:2018 and is structured as 4 main domains, 28 subdomains, 108 main controls, and 92 subcontrols.

ECC–2:2024 is mandatory for government agencies in the Kingdom (ministries, authorities, establishments, and others) and their affiliated companies and entities — including those operating inside and outside Saudi Arabia — as well as private-sector organisations that own, operate, or host Critical National Infrastructure (CNI). Legal obligations referenced in the official controls include Article 10(3) of the NCA Statute and High Order No. 57231. The NCA strongly encourages other entities to adopt ECC as best practice, but that encouragement is not the same as mandatory ECC scope.

Compliance is ongoing. The NCA may evaluate entities through self-assessment, compliance-tool reporting, and/or field audit visits. CyberSilo helps in-scope organisations map controls, collect evidence continuously, and stay ready for assessment — especially for Defense-domain monitoring requirements that depend on centralised logging and SIEM.

Related — but separate: NCNICC-1:2025

Non-CNI private-sector entities notified by the NCA fall under NCNICC-1:2025 (Non-CNI Private Sector Entities Cybersecurity Controls) — a distinct framework derived from ECC and sized for private organisations (with large-entity vs SME tiers). It does not mean ECC itself now applies to every private company. If you are a notified non-CNI private entity, use NCNICC as your primary baseline; if you are government or CNI, ECC–2:2024 remains your mandatory framework. CyberSilo can support both paths with shared monitoring and evidence workflows.

The Four ECC Domains — Governance, Defense, Resilience, Third-Party & Cloud

Official NCA structure: 4 main domains and 28 subdomains spanning strategy and people controls through technical defense, business continuity, and supplier/cloud security.

Domain 1

Cybersecurity Governance

Establishes strategy, management structure, policies, roles, risk management, project security, regulatory compliance, periodic review/audit, HR security, and awareness/training. This domain anchors Board and executive accountability for cybersecurity across the entity.

10 subdomains 1-1 to 1-10
Domain 2

Cybersecurity Defense

The technical core: asset management, IAM, system protection, email, networks, mobile, data protection, cryptography, backup, vulnerability management, penetration testing, event logs & monitoring (2-12), incident/threat management, physical security, and web application security.

15 subdomains 2-1 to 2-15
Domain 3

Cybersecurity Resilience

Embeds cybersecurity requirements into Business Continuity Management (BCM) so critical services can withstand, respond to, and recover from cyber disruption with documented resilience controls.

1 subdomain 3-1 BCM aspects
Domain 4

Third-Party & Cloud Computing Cybersecurity

Covers cybersecurity requirements in contracts and relationships with third parties, plus cloud computing and hosting controls for entities that use or plan to use cloud services (subdomain 4-2 applicability is technology-dependent).

2 subdomains 4-1 · 4-2

Key Requirements — Especially 2-12 Event Logs & Monitoring

ECC spans governance through cloud — but assessment programmes frequently scrutinise whether entities can prove continuous monitoring, privileged-access visibility, and retained cybersecurity event logs.

2-12 Cybersecurity Event Logs and Monitoring Management

Official ECC–2:2024 subdomain 2-12 requires entities to identify, document, approve, implement, and periodically review cybersecurity event-log and monitoring requirements. Control 2-12-3 sets a clear minimum baseline:

  • Activate cybersecurity event logs for critical information assets
  • Activate logs for critical/privileged accounts and remote access events
  • Define techniques for cybersecurity event-log collection
  • Continuously monitor cybersecurity event logs
  • Retain cybersecurity event logs for at least 12 months

The official control text references SIEM as a relevant capability. ThreatHawk SIEM is built for this exact class of obligation — centralised collection, continuous monitoring, privileged-session visibility, and retention aligned to assessment expectations.

Other high-impact ECC themes

Governance (1-x): documented strategy, policies, roles, risk methodology, and awareness programmes with periodic review.

Identity & access (2-2): approved IAM requirements and ongoing access control evidence.

Vulnerability & testing (2-10 / 2-11): managed vulnerability processes and authorised penetration testing.

Incident & threat management (2-13): documented detection, escalation, and response workflows — often fed by SIEM alerts.

Third-party & cloud (4-1 / 4-2): contractual cyber requirements and cloud/hosting controls where applicable.

A full domain-by-domain explainer and interactive checklist are planned next — see Related Content below.

How CyberSilo Helps You Meet ECC–2:2024

ThreatHawk SIEM and Compliance Standards Automation work together — continuous telemetry for Defense controls, structured evidence for Governance, Resilience, and Third-Party domains.

1

Map posture to 108 main controls

Compliance Standards Automation aligns your environment to ECC–2:2024 domains and subdomains, highlighting gaps (including 2-12 logging/monitoring readiness) and producing a prioritised remediation backlog for government and CNI programmes.

2

Operationalise 2-12 with ThreatHawk SIEM

ThreatHawk SIEM centralises cybersecurity event collection, supports continuous monitoring of critical assets and privileged/remote access activity, and helps meet multi-month retention expectations that auditors and NCA assessment mechanisms expect to see evidenced.

3

Collect evidence continuously

Replace point-in-time spreadsheets with ongoing evidence packs — policy versions, access reviews, monitoring configurations, incident records, and vendor control artefacts organised by ECC domain for self-assessment and field-audit readiness.

4

Stay assessment-ready year-round

Drift alerts and refreshed evidence keep you ready for NCA self-assessment cycles, compliance-tool reporting, or on-site reviews — without scrambling when an assessment window opens. See also our ECC implementation services for hands-on delivery.

NCA ECC Frequently Asked Questions

What is NCA ECC-2:2024?

The Essential Cybersecurity Controls (ECC–2:2024) are Saudi Arabia’s National Cybersecurity Authority baseline cybersecurity framework. The current version comprises 4 main domains, 28 subdomains, 108 main controls, and 92 subcontrols. It updates ECC–1:2018 and defines minimum cybersecurity requirements for in-scope national entities. Official documents are published on nca.gov.sa.

Who must comply with NCA ECC?

ECC–2:2024 is mandatory for KSA government agencies and their affiliated entities (inside and outside the Kingdom), and for private-sector entities that own, operate, or host Critical National Infrastructure. Other entities are encouraged to adopt ECC as best practice. Non-CNI private entities notified by the NCA are covered by the related but separate NCNICC-1:2025 framework.

How is NCNICC-1:2025 different from ECC?

NCNICC-1:2025 is a separate NCA control set for Non-CNI private-sector entities (as notified by the Authority). It is derived from ECC but sized for private organisations, with tiered requirements for large entities and SMEs. It does not replace ECC for government or CNI operators.

What does subdomain 2-12 require for logging and monitoring?

Subdomain 2-12 requires documented and implemented cybersecurity event-log and monitoring management. At minimum: logs for critical assets; logs for privileged and remote access; defined collection techniques; continuous monitoring; and retention of at least 12 months. The official text references SIEM. ThreatHawk SIEM is designed to operationalise this control family.

How does CyberSilo help with NCA ECC compliance?

CyberSilo maps ECC–2:2024 into Compliance Standards Automation for continuous evidence and control tracking, while ThreatHawk SIEM addresses Defense logging/monitoring under 2-12. Together they reduce manual audit prep for government and CNI programmes.

How does the NCA assess ECC compliance?

Per the official ECC–2:2024 document, the NCA may evaluate compliance via self-assessment, periodic reports from the compliance tool, and/or field auditing visits. The Authority also references an ECC-2:2024 Assessment and Compliance Tool for organising assessment and measurement.

Ready to operationalise ECC–2:2024?

Get a structured gap assessment across all 4 domains — with a clear plan for 2-12 logging/monitoring using ThreatHawk SIEM and continuous evidence via Compliance Standards Automation.