Back to Frameworks
Frameworks

Saudi National Cybersecurity Authority Essential Cybersecurity Controls (ECC) (Saudi Arabia)

Framework Name

Essential Cybersecurity Controls (ECC), version ECC-2:2024

Type

Mandatory for Saudi government entities and private-sector organizations that own, operate, or host Critical National Infrastructure

Region / Jurisdiction

Saudi Arabia

Enforcing Body / Certifying Party

National Cybersecurity Authority (NCA), Saudi Arabia's national cybersecurity regulator

Penalty / Consequence of Non-Compliance

Regulatory sanctions, exclusion from government contracts, legal action, and mandatory audits. NCA has also gained expanded regulatory inspection powers as part of its broader 2024-2026 regulatory push

What It Is & Why It Matters

ECC is the NCA's foundational cybersecurity framework, the minimum set of requirements that in-scope organizations in Saudi Arabia must meet, covering government ministries, authorities, and affiliated entities, as well as private-sector companies operating Critical National Infrastructure. The 2024 update restructured the original 2018 version into 4 domains, 28 subdomains, and 108 main controls, a genuinely different shape than the 2018 version's structure, and one specific reference figure worth getting right, since 110 controls is widely quoted online but is actually incorrect for the current version.

The single biggest operational change in the update, and the one many foreign firms operating in the Kingdom have reportedly not fully registered yet, is a Saudization requirement: every cybersecurity role, not just senior leadership positions as under the 2018 version, must now be filled by a qualified Saudi national. This has direct staffing and hiring implications for any multinational company with Saudi operations, well beyond the technical control changes themselves. Data localization responsibility has also shifted to a separate body, the National Data Management Office, with a related Cloud Cybersecurity Controls document updated to match.

Who Needs It

  • You are a Saudi government ministry, authority, or affiliated entity
  • You are a private-sector organization that owns, operates, or hosts Critical National Infrastructure in Saudi Arabia
  • You operate in the Kingdom with foreign cybersecurity staff and need to understand the Saudization requirement's impact on your team structure
  • You're relying on older guidance describing ECC-1:2018 and need to understand what specifically changed in the 2024 update
Book A Demo