Suspect a breach? Report it immediately — response within 1 hour.Report an incident

NCA ECC-2:2024 Essential Cybersecurity Controls (Saudi Arabia)

Saudi Arabia's essential cybersecurity controls framework, issued by the National Cybersecurity Authority (NCA), structured into 4 domains, 28 sub-domains, and roughly 110 controls.

Last updatedAugust 22, 2026

Who's affected

Saudi organizations classified as Class A or Class B entities based on their criticality, along with their cybersecurity service providers. Additional sector-specific rules apply depending on the activity, notably from SAMA (financial sector), CITC (telecoms), and SDAIA (data and artificial intelligence).

What the framework requires

Implementation of roughly 110 controls spanning the 4 domains and 28 sub-domains of ECC-2:2024, with the level of stringency differentiated by the entity's classification (Class A or Class B). The framework also mandates Saudization of key cybersecurity roles, which directly shapes how a foreign provider can operate in this market.

Compliance steps

01

Determine the entity's classification (Class A or Class B)

02

Gap analysis against the roughly 110 ECC-2:2024 controls

03

Structure the compliance plan by domain and sub-domain

04

Implement the required technical and organizational controls

05

Document compliance for NCA review purposes

Common mistakes

  • Overlooking the Saudization requirement for key cybersecurity roles, which conditions how a foreign provider can operate
  • Neglecting the additional sector-specific rules (SAMA, CITC, SDAIA) that layer on top of ECC-2:2024
  • Confusing ECC-2:2024 with NCNICC-1:2025, a separate and adjacent framework issued within the same regulatory ecosystem

Cross-mapping to other frameworks (UCM)

FrameworkCovered
sama-csf

Downloadable resource

Get the checklist by email.

Frequently asked questions

What is the difference between Class A and Class B?

The classification reflects the entity's criticality level and determines the degree of rigor expected in implementing the controls; it is determined by the NCA.

What does Saudization actually require?

ECC-2:2024 requires that certain key cybersecurity roles be filled by Saudi nationals, which structurally limits direct market entry for foreign providers on this scope.

Can EBH Security operate directly in Saudi Arabia on this scope?

On roles subject to Saudization, EBH Security delivers its services alongside local Saudi actors — providing methodological support and technical expertise, while its Saudi partners handle direct work within the regulated market, in line with the Saudization requirement.

What is NCNICC-1:2025?

An adjacent framework issued within the same Saudi regulatory ecosystem as ECC-2:2024, whose detailed content falls outside the scope of this page.

Do SAMA, CITC, and SDAIA apply on top of ECC-2:2024?

Yes, for entities within their respective sectors — finance for SAMA, telecommunications for CITC, data and AI for SDAIA — these rules apply in addition to, not instead of, the ECC-2:2024 controls.