TL;DR
ECC-2:2024 has 108 main controls and 92 subcontrols spread across four domains. Auditors do not want your checklist. They want dated, approved artifacts that prove a control ran on schedule. Spreadsheets can record that a control exists, but they cannot show it operated. This post walks each domain, names the evidence auditors ask for, and explains why the tracking method matters as much as the control.
Your Checklist Says 94 Percent. Your Auditor Says Prove It.
Here is the moment that catches teams out. The compliance lead opens the tracker. Ninety four percent green. Then the auditor asks a simple question about control 2-2-3-5: show me the last access review. Not the policy saying you do them. The review itself, dated, with names on it.
Silence.
The control existed. Nobody could prove it ran.
That gap between “we have a control” and “here is the artifact” is where most ECC assessments get uncomfortable. And a spreadsheet is very good at recording the first thing and completely blind to the second.
What ECC-2:2024 Actually Contains
Per the NCA’s published control document, ECC-2:2024 consists of 4 main domains, 28 subdomains, 108 main controls, and 92 subcontrols.
One change from ECC-1:2018 catches people out. Domain 5, Industrial Control Systems Cybersecurity, was removed. Those controls moved to the OTCC, the Operational Technology Cybersecurity Controls. If your gap analysis still references a fifth ECC domain, it is built on the old version.
Two more updates worth flagging. Control 1-2-2 was rewritten. The old rule covered the cybersecurity function head and related supervisory positions. The new text says all cybersecurity positions shall be filled by full time and qualified Saudi cybersecurity professionals.
That is a broader requirement than most teams remember. And subcontrol 2-5-3-9 is new, covering protection against DDoS attacks.
Domain 1: Cybersecurity Governance
Ten subdomains, and the heaviest documentation load in the framework. Governance evidence is almost entirely paper, which sounds easy until you realize every piece of paper needs a date and an approval.
Evidence auditors ask for
- The cybersecurity strategy, documented and approved by the Authorized Official, with the action plan that applies it and records of review at planned intervals
- Proof the cybersecurity department is independent from the IT and Communications department, per High Order No. 37140
- Charter for the cybersecurity supervisory committee, naming members, responsibilities, and the head of the cybersecurity department as a member
- The risk management methodology, plus risk assessments run at the four trigger points named in 1-5-3: early in technology projects, before major infrastructure changes, when planning third party services, and before releasing new technology services
- Audit results reviewed by a party other than the cybersecurity department, presented to the supervisory committee, with scope, observations, recommendations, and remediation plans
- Screening records for personnel in cybersecurity and privileged technical positions, and evidence powers were revoked immediately on employment ending
The cybersecurity function reports into IT. This is the single conflict Domain 1 is built to prevent, and control 1-2-1 names it directly. An org chart showing a dotted line to the CIO undoes the whole governance domain.
Domain 2: Cybersecurity Defense
Fifteen subdomains and the largest technical surface in the framework. This is where evidence stops being documents and becomes system output, which is exactly where spreadsheets fall apart.
Evidence auditors ask for
- Asset inventory that is accurate and current, with classification and labeling, and the acceptable use policy both approved and implemented
- MFA configuration, with the impact assessment that justified your choice of authentication factors for remote access and privileged accounts
- Dated periodic reviews of identities and access rights under 2-2-3-5
- Cryptography aligned to the National Cryptographic Standards published by the NCA, with key management across the lifecycle and encryption in transit and at rest
- Backup restoration testing, not just backup configuration. Control 2-9-3-3 asks for periodic testing of recovery effectiveness
- Vulnerability records showing assessment, severity classification, remediation, and patch verification in a non production environment before rollout
- Event logs retained for at least 12 months per 2-12-3-5, with evidence of continuous monitoring
- Penetration test reports covering all externally provided services: infrastructure, websites, web applications, mobile apps, email, and remote access
- Email domain validation using SPF, DKIM, and DMARC. All three are named in 2-4-3-5, not just SPF
Where teams lose points
Logs get collected and nobody watches them. Control 2-12-3-4 asks for continuous monitoring, and a SIEM with no alert history and no response records proves the opposite of what you want it to prove. Backups are the twin of this: configured everywhere, restore tested almost nowhere.
Domain 3: Cybersecurity Resilience
One subdomain, four controls, and the smallest domain by far. Do not read that as low effort. Resilience evidence is about exercise records, and those are the hardest artifacts to produce after the fact.
Evidence auditors ask for
- Business continuity requirements that specifically cover cybersecurity, approved and implemented
- Incident response plans for cyber events that could disrupt business continuity
- Disaster recovery plans, per 3-1-3-3
- Records showing all of the above were reviewed periodically
Where teams lose points
The plan is beautiful. It has never been run. A continuity plan with no test record is a document, not a control, and an auditor can tell the difference in about ninety seconds.
Domain 4: Third Party and Cloud Computing Cybersecurity
Two subdomains covering the risk you inherit from everyone else.
Evidence auditors ask for
- Third party contracts carrying non disclosure clauses, secure data removal on service end, incident communication procedures, and an obligation on the vendor to apply your cybersecurity requirements
- Risk assessments completed before contracts were signed, per 4-1-3-1
- Evidence that cybersecurity managed service centers using remote access are located inside the Kingdom, per 4-1-3-2
- Cloud data protected per classification level, with data returned in usable format when service ends
- Separation of your environment, especially virtual servers, from other tenants
One clarification worth having
Data localization moved. Subcontrol 4-2-3-3, which required hosting inside the Kingdom, was removed from the ECC. Those requirements now sit with the National Data Management Office at SDAIA. Same for data privacy, which came out of control 2-7-3. Check with the NDMO before acting on either. Both are still requirements, just not this document’s requirements.
Why the Spreadsheet Breaks
Not because spreadsheets are bad. Because of what ECC keeps asking for.
Read the control text closely and a phrase repeats: shall be periodically reviewed. It closes nearly every subdomain in the framework. Periodic review is not a state you reach. It is an event that has to keep happening, and every occurrence needs a date on it.
A spreadsheet captures a moment. Someone fills a cell in March. By June the access review is overdue, three servers dropped off the patch schedule, and the cell still says green because cells do not change on their own.
Then there is evidence volume. Twelve months of logs. Every access review across the year. Every restore test. Every risk assessment tied to a project trigger. A tracker can point at where that lives. It cannot produce it, and it cannot tell you when something quietly stopped happening.
The gap is simple. Your spreadsheet knows what you decided. Your auditor asks what you did.
How Secure.com Helps
Secure.com’s Compliance Teammate pulls evidence from the systems that already generate it, so audit prep stops being a scramble through screenshots and shared drives.
- Collects evidence automatically from asset inventory, vulnerability management, identity systems, and configuration governance, then maps it to framework controls
- Tracks control drift continuously, so a review that stops happening shows up as a gap instead of a stale green cell
- Generates audit ready reports with drilldowns per control, exportable to PDF, CSV, or JSON
- Links compliance gaps to your risk register, so remediation runs by regulatory exposure rather than by list order
- Preserves an immutable log of everything ingested and exported, which is the audit trail auditors ask for anyway