TL;DR
ECC-2:2024 trimmed the framework from 5 domains and 114 controls down to 4 domains, 28 subdomains, and 108 controls. It merged overlapping rules, expanded who is in scope, and added one big staffing change: every cybersecurity role now needs a full-time, qualified Saudi professional.
Most companies do not fail audits because they lack controls. They fail because they cannot prove the controls worked over time. This guide covers what changed, who must comply, and how to get audit-ready.
Introduction
In October 2024, the National Cybersecurity Authority replaced ECC-1:2018 with ECC-2:2024. If your organization touches critical systems in the Kingdom, this is the baseline your security posture gets measured against. The update did not just tweak wording. It changed how compliance is scoped, structured, staffed, and checked.
What Is NCA ECC and Why Does It Matter?
The Essential Cybersecurity Controls are a mandatory set of minimum security rules from Saudi Arabia’s National Cybersecurity Authority. The NCA was set up in 2017 to protect the Kingdom’s critical infrastructure.
ECC is not a suggestion. It is the regulatory floor. Government entities and critical infrastructure operators must meet it, no matter their size or sector.
The NCA built ECC by studying national laws, global standards, and past attacks on Saudi institutions. Think of it the way Australia uses the Essential Eight or Germany uses IT-Grundschutz. It is the national cybersecurity baseline.
What Changed From ECC-1:2018 to ECC-2:2024?
This is a real revision, not a cosmetic one. Here are the changes that carry the most weight.
A Leaner Control Set
ECC-1 had 5 main domains, 29 subdomains, and 114 controls. ECC-2 was consolidated to 4 main domains, 28 subdomains, 108 controls, and 92 subcontrols.
The old Domain 5 was removed. Overlapping requirements were merged, and organizations were pointed to other specific NCA standards where needed. The goal was less duplication, not weaker security.
The Four Domains Now Are
- Cybersecurity Governance: strategy, policies, roles, risk management, human resources security, compliance, and awareness training.
- Cybersecurity Defense: the largest domain. Covers asset management, identity and access management, network security, cryptography, and vulnerability management.
- Cybersecurity Resilience: builds security into business continuity and disaster recovery so you can survive and recover from an incident.
- Third-Party and Cloud Computing Cybersecurity: two subdomains and eight controls covering vendor risk and cloud hosting.
The Staffing Clause Most Companies Miss
Under ECC-1, only senior roles like the CISO needed to be filled by Saudi nationals. ECC-2:2024 changed control 1-2-2. The updated wording states that all cybersecurity positions shall be filled with full-time and qualified Saudi cybersecurity professionals.
This moves Saudization from a leadership question to a whole-workforce question. It reaches SOC analysts, incident responders, IAM admins, GRC analysts, and cloud security owners.
Data Localization Moved
Responsibility for data hosting and localization shifted toward the National Data Management Office under SDAIA. It is no longer prescribed directly inside ECC. You still need to map it, just against the right authority.
Scope Got Wider
ECC-2:2024 clarified that the controls also apply to Saudi government entities operating outside the Kingdom. This reflects the country’s growing footprint through sovereign investments and state-owned operations abroad.
Who Must Comply?
The official scope names Saudi government agencies and their affiliated entities, inside and outside the Kingdom, plus private-sector entities that own, operate, or host Critical National Infrastructure.
If you are directly in scope, this needs serious attention. If you are a supplier, contractor, cloud provider, healthcare operator, or financial partner to an in-scope entity, your clients will likely ask for ECC-aligned evidence anyway. Even if you are fully outside scope, ECC is a strong benchmark for mature cybersecurity governance, and the NCA encourages other entities to use it.
One caution: do not assume the staffing clause applies to every Saudi company without checking your scope first. Map both ECC and any applicable private-sector NCA requirements before you design your staffing model.
The Offshore Outsourcing Problem
Outsourcing is not automatically a compliance failure. But leaning heavily on offshore teams for core cybersecurity roles creates audit exposure.
Picture a company that says its SOC is offshore, its incident responders are offshore, and its IAM admins are external. An assessor will start asking who actually owns cybersecurity decisions inside the Saudi entity.
- Who approves firewall changes?
- Who leads incident response?
- Who reviews privileged access?
A vendor can support your operations. It cannot become a black box. You still need local accountability, access governance, and evidence you can produce on request.
How to Implement ECC-2:2024, Step by Step
Reaching ECC alignment is a program, not a one-time project. Here is a sequence that holds up.
- Scope your systems and entities. Confirm what falls in scope, including subsidiaries and any hosted CNI.
- Run a gap assessment against the current 108 controls. Use the NCA toolkit and be honest about where you stand.
- Fix the foundations first. Set your governance structure, security policies, access controls, and asset inventory.
- Deploy core defenses. Network segmentation, endpoint protection, backups, and logging.
- Add detection and response. SIEM, intrusion detection, patch management, and a tested incident response plan.
- Build your Saudi staffing coverage. Prioritize SOC, IAM, GRC, incident response, cloud security, and third-party risk.
- Build the evidence trail as you go. This is where most audits are won or lost.
- Move to continuous monitoring. The NCA expects ongoing compliance, backed by the coming ECC-2:2024 Assessment and Compliance Tool. It is not a pass-once exercise.
How ECC Fits With Other Saudi Frameworks
ECC is the cornerstone, but the NCA family is wider. There are also Critical Systems Cybersecurity Controls, Cloud Cybersecurity Controls, Operational Technology Cybersecurity Controls, and Data Cybersecurity Controls. Financial institutions also answer to SAMA where their systems count as critical.
A common mistake is treating “NCA compliance” as if it only means “ECC compliance.” Depending on what your organization does, several of these control sets can apply at once. Map them together so you are not surprised during an inspection.
The Audit Evidence That Actually Gets Checked
Passing an audit means producing proof fast. Assessors may ask for your cybersecurity organization chart, job descriptions, employment and nationality records, qualification and training records, access review logs, privileged access records, SOC shift schedules, vendor contracts, third-party risk assessments, incident ownership logs, and compliance tool reports.
Nationality records alone are not enough. You also have to prove the person is actually doing the cybersecurity role and has the qualifications for it. Here is the pattern to remember: if your documentation is scattered across HR, IT, procurement, and vendor portals, your audit response will be slow and weak. Keep one evidence base.
Common Challenges and How to Handle Them
Evolving requirements. Rules shift, and keeping up drains time. Assign clear ownership and use automated policy management so updates do not fall through the cracks.
Tier confusion. Organizations get classified by criticality, and figuring out which requirements apply can be murky. A thorough risk assessment and experienced guidance clears this up.
New Saudization demands. The staffing clause needs planning, not panic. Build a Saudi talent coverage plan, keep vendor support where it helps, and document who owns each role.
Proving controls operated over time. This trips up most teams. Do not wait for the audit. Capture evidence continuously as controls run.
How Secure.com Helps With NCA ECC-2:2024
Secure.com gives you a Compliance Teammate that turns audit prep from a weeks-long scramble into a continuous, data-driven practice. It maps your live security data straight to framework controls, so you always know where you stand.
- Continuous evidence collection pulls proof from assets, vulnerabilities, applications, incidents, and access reviews, then maps it to the right controls automatically.
- Multi-framework control mapping lets you manage ECC alongside ISO 27001, PDPL, SOC 2, NIST, and more from one place.
- Real-time dashboards show your compliance percentage per framework and flag gaps as they happen, not months later.
- Audit-ready reports generate in minutes with control-level drilldowns you can hand straight to an assessor.
- Risk-based prioritization ties non-compliance to real business risk, so you fix the gaps that carry the biggest regulatory exposure first.
FAQs
How many controls are in ECC-2:2024?
The framework has 4 main domains, 28 subdomains, 108 main controls, and 92 subcontrols. That is down from 114 controls in ECC-1:2018. Always confirm the current published figures on the NCA portal before citing them externally, since the NCA can issue revisions.
Is 100 percent Saudization required for all cybersecurity roles?
For entities inside ECC-2:2024 scope, the control wording states that all cybersecurity positions shall be filled with full-time and qualified Saudi professionals. Confirm whether your entity is directly in scope and how the requirement applies to your structure.
Can I still use an offshore SOC or MSSP?
Yes, but carefully. You need internal Saudi role ownership, documented vendor boundaries, third-party risk assessments, controlled and reviewed offshore access, and contracts that include cybersecurity requirements. The risk is losing internal accountability, not using outside support.
What are the penalties for non-compliance?
Consequences can include warnings, temporary or permanent license or service suspension, mandatory remediation, reputational damage from public disclosure, and fines up to SAR 25,000,000. Amounts depend on the nature and severity of the violation.
Does ECC apply to small businesses and startups?
ECC critically applies to government entities and operators of Critical National Infrastructure. Smaller businesses and startups are not always directly in scope, but the NCA encourages them to adopt the controls as a best practice, and clients may still expect ECC-aligned evidence.