Seclore | NCA Compliance
Skip to content

The regulation emphasizes identifying sensitive data while utilising a risk based approach. It also requires the administration of relevant security measures based on data sensitivity.

Strict access management policies are mandated, ensuring that only authorized personnel can access sensitive data.

The ECC requires organizations to establish detailed incident response and recovery plans that include data protection measures during and after an attack.

What are the Essential Cybersecurity Controls (ECC) of the NCA in the Kingdom of Saudi Arabia?

The ECC is a document that was released in 2018 and subsequently updated in October 2024. The objective of the document is to establish a minimum cybersecurity baseline for all national organisations. Compliance with the ECC is mandatory for government organizations and private sector entities operating critical national Infrastructure in order to ensure a robust minimum baseline when it comes to cybersecurity.

Thematically the ECC-2:2024 framework is split into 4 main domains and 110 cybersecurity controls and 90 sub controls. The October 2024 update is designed to enhance the clarity and improve security measures across its main domains, ensuring better alignment with current global cybersecurity practices and addressing evolving threats.