TL;DR
NCA ECC-2:2024 asks Saudi organizations to meet 108 controls across 4 domains. Small teams panic because the number sounds like a hiring plan. It is not. The real work is proof, not paperwork, and most of that proof already lives in tools you own. This guide gives you an evidence checklist you can run with the team you have.
Introduction
A three person security team in Riyadh once told me they were bracing for their first ECC assessment like it was a hurricane. They counted the controls, counted their staff, and felt the math was against them. Here is the part they had missed. The assessment does not ask each person to own a control. It asks the organization to show evidence. Once they mapped what proof they already had, the gap shrank fast.
What ECC-2:2024 Actually Requires
The National Cybersecurity Authority updated its Essential Cybersecurity Controls in October 2024. ECC-2:2024 replaced the older ECC-1:2018. The new version is leaner. It moved from 5 domains and 114 controls down to 4 domains, 28 subdomains, 108 main controls, and 92 subcontrols.
Here’s how the four domains break down.
- Cybersecurity Governance: strategy, policies, roles, risk management, and compliance.
- Cybersecurity Defense: the technical core, with asset management, identity and access, network security, and cryptography. This domain holds about 15 subdomains and 60 controls, so most of your work sits here.
- Cybersecurity Resilience: business continuity and recovery.
- Third Party and Cloud Security: vendor risk and cloud controls, now folded into the main four instead of a separate fifth domain.
One honest note. Control counts differ across third party write ups. Some vendors publish 110 controls and 90 subcontrols. The NCA regulatory document is the source that governs your audit, so treat the official NCA figures as final and confirm against the current published version before you cite a number in a board deck.
Why the Number 108 Scares Small Teams
The fear comes from a simple mental model. One control feels like one project, and one project feels like one owner. Multiply that out and you get a staffing nightmare.
That model is wrong. Many controls share the same evidence. A single access review log can support governance, defense, and third party controls at once. A patch record can prove both vulnerability management and resilience readiness. When you map evidence to controls instead of people to controls, the workload collapses into a handful of recurring proof sources.
The ECC Evidence Checklist
Group your controls by the proof they need. That way you gather evidence once and reuse it across many controls. Here is a working checklist a lean team can run.
Governance evidence
- A written and approved cybersecurity strategy signed by leadership.
- Current policies and procedures with review dates.
- A risk register with owners and status.
- Records of security awareness training and completion rates.
Defense evidence
- Asset inventory with owners and classification.
- Access reviews showing who has access to what and when it was last checked.
- Vulnerability scan reports with patch timelines.
- Configuration baselines and records of drift fixes.
Resilience evidence
- A business continuity plan with test dates.
- Incident response records with timelines and lessons learned.
- Backup and recovery logs.
Third party and cloud evidence
- Vendor security assessments and contracts.
- Cloud configuration records.
- Proof that vendor access is reviewed and revoked when it ends.
Print this list. Next to each item, write where the proof lives today. You will find most of it already exists inside tools you run every week.
How to Cover Controls Without Adding Headcount
Lean teams win by removing manual collection, not by adding people. Three moves do most of the work.
First, collect evidence continuously instead of once a year. A point in time scramble burns weeks and still leaves gaps. Continuous collection means the proof is ready the day the auditor asks.
Second, reuse evidence across frameworks. If you already track ISO 27001 or PDPL, many of those artifacts map straight to ECC controls. You are gathering less than you think.
Third, automate the boring parts. Pulling access logs, patch timelines, and configuration records by hand is where small teams drown. Automated collection frees your people for the judgment work that actually needs a human.
How Secure.com Helps
Secure.com gives lean teams a Compliance Teammate that gathers ECC evidence for you and keeps it audit ready. You get proof without the manual grind, and your small team keeps its focus on real security work.
- Maps evidence from across your stack against framework controls, so one artifact covers many requirements.
- Collects access reviews, patch timelines, and configuration fixes automatically.
- Builds audit ready reports you can export for leadership and assessors.
- Tracks compliance drift so you catch a gap before the auditor does.
- Links high risk gaps to your risk register so you fix what matters first.