Article2 min read

NCA ECC: what the Essential Cybersecurity Controls ask of your entity

A plain reading of the National Cybersecurity Authority's baseline controls: what they cover, who they apply to, and what evidence an auditor will ask for.

Sample cover

The Essential Cybersecurity Controls (ECC) are the baseline the National Cybersecurity Authority (NCA) sets for protecting systems in Saudi Arabia. A control is a single requirement, such as “review user access regularly”, that your entity must meet and be able to prove.

Who they apply to

Government entities and their agencies, and private companies that own, operate or host critical national infrastructure. Other private companies follow them too, because government clients expect the same level of protection from their suppliers.

What they cover

The controls are grouped into main domains:

  • Cybersecurity governance: a dedicated function, approved policies, clear roles and risk management.
  • Cybersecurity defense: asset inventory, identity and access, protection of email, networks and data, backups, vulnerability management, penetration testing and monitoring of security events.
  • Cybersecurity resilience: keeping critical services running during and after an incident.
  • Third-party and cloud computing cybersecurity: security requirements for suppliers and cloud services.
  • Industrial control systems cybersecurity, where your entity runs them.

What an auditor asks for

A policy on its own is not enough. For each control, be ready to show the approved document that says what you do, the records that prove you did it, such as an access review or a patch report, and the person who owns the control.

Where to start

Start with a gap assessment: compare what your entity does today with each control, then rank the gaps by risk. Hide runs these assessments against NCA ECC, and Wathiq, our GRC platform, tracks every control and every piece of evidence, so the gaps show up before the audit does.