ECC 2-2024 is the current edition of Saudi Arabia’s Essential Cybersecurity
Controls, and it did something unusual for a control framework update: it removed an entire main
domain. Anyone still working from ECC-1:2018 is working from a structure that no longer exists.

What changed in ECC 2-2024
The National Cybersecurity Authority published ECC-1:2018 as the Kingdom’s baseline cybersecurity
control set. ECC 2-2024 replaced it. The document runs to 56 pages and is published openly on
nca.gov.sa, classified TLP: White.
The headline structural change is set out in the standard’s own Appendix C, its list of updates:
main domain 5 was deleted, and its controls moved to the OTCC — the Operational
Technology Cybersecurity Controls. Domain 5 was Industrial Control Systems Cybersecurity.
So the framework went from five main domains to four:
| # | Main domain |
|---|---|
| 1 | Cybersecurity Governance |
| 2 | Cybersecurity Defense |
| 3 | Cybersecurity Resilience |
| 4 | Third-Party and Cloud Computing Cybersecurity |
Underneath those four domains sit 28 subdomains and 109 controls, numbered
domain-subdomain-control — 1-1-1 through to the domain 4 controls. The framework is built around
four cybersecurity pillars: strategy, people, process and technology.
Why the domain 5 deletion matters more than it sounds
Domains 1 to 4 kept their numbering. A control cited as 1-2-2 under the old edition is still 1-2-2,
so most existing references survive the transition intact. That is unusual and genuinely helpful
— it means a documentation set citing ECC controls does not need renumbering.
The exception is anything about industrial control systems. Under ECC-1:2018, a sentence saying
“ICS cybersecurity controls are covered by the ECC” was true. Under ECC 2-2024 it is false, because
those controls are no longer in the ECC at all. If you operate OT or ICS, the relevant control set is
now the OTCC, not the
ECC.
This is the trap in any mechanical version relabel: swapping “ECC-1:2018” for “ECC 2-2024”
throughout a policy set turns a correct sentence about ICS into an incorrect one. Grep for the subject
that moved before treating a relabel as routine.
Who ECC 2-2024 applies to
The standard states its own scope plainly. The controls apply to government agencies in the Kingdom
— ministries, authorities, establishments and others — and to their affiliated companies
and entities, inside and outside the Kingdom. They also apply to all private sector
entities owning, operating or hosting Critical National Infrastructure.
Two consequences are easy to miss. The extraterritorial reach means a subsidiary operating outside
Saudi Arabia can still be in scope through its parent. And a private company with no government
relationship at all can be in scope purely by hosting CNI.
Beyond the mandatory scope, the standard is widely adopted voluntarily as a security baseline in the
Kingdom, in much the same way NIST CSF is used outside its federal origins.
Documentation written to ECC 2-2024, not the 2018 edition.
The NCA Cybersecurity Toolkit ships 83 editable documents — 31 policies and 34 technical standards paired to them, plus procedures, checklists, forms and registers — with alignment clauses citing ECC 2-2024, CCC-2:2024, CSCC-1:2019, DCC-1:2022 and OTCC-1:2022. The OT and ICS standard points at the OTCC, where those controls now live.
What ECC 2-2024 expects you to produce
The ECC is a control framework rather than a certification scheme, so the output is a documented,
implemented and assessable set of controls rather than a certificate. In practice that means:
- A cybersecurity strategy and governance structure. Domain 1 covers strategy,
roles, the cybersecurity function, risk management, compliance and audit. A named head of the
cybersecurity function is explicit in the controls. - A policy and standard hierarchy. The Kingdom’s convention is a policy stating
intent with a technical standard beneath it stating configuration — which is why a serious ECC
document set has roughly as many standards as policies. - A Statement of Applicability. The ECC has its own, distinct from ISO 27001’s,
recording which controls apply and why. - Evidence of implementation. Registers, logs and records, not just documents
— the controls are assessed against practice. - Third-party and cloud coverage. Domain 4 reaches suppliers and cloud services;
the cloud detail lives in the
Cloud Cybersecurity Controls.
A Statement of Applicability, but not ISO 27001’s
Organisations holding ISO 27001 often assume their existing SoA carries over. It does not. The
control sets are different, the numbering is different, and the ECC’s applicability logic is its own.
An ISO 27001 ISMS is a substantial head start on the governance, risk and audit machinery — but
the mapping work is real, and the ECC SoA is a separate artefact.
Moving from ECC-1:2018 to ECC 2-2024
- Re-baseline against the four domains. Confirm which of your existing controls map
to the current structure, and note that nothing in domain 5 exists any more. - Move ICS and OT to the OTCC. Anything that cited ECC domain 5 needs re-pointing,
not relabelling. - Check every alignment clause. Policy sets typically carry a boilerplate sentence
naming the frameworks they align to. Those sentences are where stale edition references hide, and they
are often written several different ways across a document set. - Re-issue the Statement of Applicability against the 109 current controls.
- Check the sibling control sets. Cloud moved to CCC-2:2024; data is DCC-1:2022.
Getting the ECC right while citing a superseded cloud edition solves half the problem.
What ECC 2-2024 does not do
Being clear about the limits saves a lot of misdirected effort.
It does not certify you. There is no ECC certificate in the way there is an ISO
27001 certificate. Entities in scope are assessed for compliance, and the output is an assessment
result rather than a mark you display.
It does not cover everything. The ECC is deliberately the baseline. Cloud, data,
operational technology, critical systems, telework and social media each have their own control set,
and an organisation is routinely in scope for several at once.
It does not tell you how. Like most control frameworks, it states what must be achieved rather than which product or configuration achieves it. NCA publishes a separate
implementation guide for that, and the technical detail belongs in your own standards.
The mistake that costs the most time
Treating an ECC programme as a documentation exercise. The controls reach strategy, people, process
and technology — the framework’s own four pillars — and an assessment looks for evidence in all four.
A complete policy set with no training records, no access review logs and no risk register produces a
programme that reads well and assesses badly.
The corollary is that the registers and logs deserve as much planning as the policies. They are
slower to produce because they accumulate over time, which is why starting them late is the most
common reason an ECC programme misses its date.
If you already hold ISO 27001
An ISO 27001 ISMS is a genuine head start on ECC 2-2024 and not a substitute for it. The
governance machinery transfers well — risk management, internal audit, management review, corrective
action, document control and awareness are all recognisable in domain 1, and evidence produced for one
usually serves the other.
What does not transfer is the control set itself. The numbering is different, the applicability
logic is different, and the ECC has its own Statement of Applicability. Expect the mapping to be real
work, and expect the ECC to reach places ISO 27001 leaves to your discretion, because it is a national
baseline rather than a risk-driven framework. See our guide to
the ISO 27001 Statement of
Applicability for the contrast.
Frequently asked questions
Is ECC 2-2024 the current edition?
Yes. It replaced ECC-1:2018 and is the version published on NCA’s regulatory documents pages.
How many domains and controls does ECC 2-2024 have?
Four main domains, 28 subdomains and 109 controls. The previous edition had five main domains.
What happened to the industrial control systems domain?
It was deleted from the ECC and its controls moved to the OTCC, the Operational Technology
Cybersecurity Controls.
Do the control numbers change?
Domains 1 to 4 keep their numbering, so citations to those controls remain valid. Only domain 5
references need re-pointing.
Is there an ECC certification?
No. The ECC is a mandatory control framework for entities in scope, assessed for compliance rather
than certified in the way ISO 27001 is.
Where this leaves you
If your documentation still names ECC-1:2018, the work is smaller than it looks and more precise
than a find-and-replace. Domains 1 to 4 kept their numbering, so most control citations survive
untouched. What needs real attention is anything about industrial control systems, because those
controls left the ECC entirely, and the alignment clauses scattered through a policy set, because
they are where the edition label actually lives.
Re-issue the Statement of Applicability against the 109 current controls, check the sibling control
sets while you are in there, and remember that the edition is assessed on evidence rather than on the
policy set alone.
References
- Essential Cybersecurity Controls (ECC 2-2024) — the standard, on NCA’s own site.
- NCA regulatory documents — the full set of published control frameworks.
More on NCA compliance
- ECC 2-2024 — you are here
- The NCA control sets explained
- Cloud Cybersecurity Controls (CCC-2:2024)
- The OTCC
- NCA ECC compliance for Saudi firms
All of these are covered by the NCA Cybersecurity Toolkit, or start with the free ISO templates.