The Essential Cybersecurity Controls (ECC) are the baseline the National Cybersecurity Authority (NCA) sets for protecting systems in Saudi Arabia. A control is a single requirement, such as “review user access regularly”, that your entity must meet and be able to prove.
Who they apply to
Government entities and their agencies, and private companies that own, operate or host critical national infrastructure. Other private companies follow them too, because government clients expect the same level of protection from their suppliers.
What they cover
The controls are grouped into main domains:
- Cybersecurity governance: a dedicated function, approved policies, clear roles and risk management.
- Cybersecurity defense: asset inventory, identity and access, protection of email, networks and data, backups, vulnerability management, penetration testing and monitoring of security events.
- Cybersecurity resilience: keeping critical services running during and after an incident.
- Third-party and cloud computing cybersecurity: security requirements for suppliers and cloud services.
- Industrial control systems cybersecurity, where your entity runs them.
What an auditor asks for
A policy on its own is not enough. For each control, be ready to show the approved document that says what you do, the records that prove you did it, such as an access review or a patch report, and the person who owns the control.
Where to start
Start with a gap assessment: compare what your entity does today with each control, then rank the gaps by risk. Hide runs these assessments against NCA ECC, and Wathiq, our GRC platform, tracks every control and every piece of evidence, so the gaps show up before the audit does.
