Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SAMA CSF compared with the NCA ECC

SAMA CSF vs NCA ECC: A Clear Guide for Saudi Firms in 2026

The SAMA CSF and the NCA Essential Cybersecurity Controls are the two frameworks a Saudi financial institution is most likely to be measured against, and they are not alternatives. They come from different authorities, use different assessment models, and can apply to the same organization at the same time.

This guide sets out who each one binds, how a maturity assessment differs from a compliance assessment, and how to run one control set that answers both without maintaining two documentation estates.

SAMA CSF vs NCA ECC: authority, scope, structure and assessment model compared
Two regulators, two assessment models — and one control estate underneath.

SAMA CSF vs NCA ECC at a glance

  SAMA CSF NCA ECC
Authority Saudi Central Bank, through the SAMA Rulebook National Cybersecurity Authority
Who it binds Banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure Government agencies and their affiliates, and private-sector entities owning, operating or hosting Critical National Infrastructure
Current version Cyber Security Framework issued under Circular 381000091275, 24 May 2017, recorded In-Force ECC 2-2024, which replaced ECC-1:2018
Structure Four domains, each with subdomains stating a principle, an objective and control considerations Four domains, 28 subdomains, 109 controls
How you are judged A maturity level from 0 to 5, determined by SAMA Assessed for compliance against the controls

Whether the SAMA CSF applies to you

The SAMA CSF question is the simpler of the two: it turns on what kind of institution you are. If you are a bank operating in the Kingdom, an insurer or reinsurer, a financing company, a credit bureau or part of the Financial Market Infrastructure, the Framework applies to you, and the Rulebook is where you confirm its status rather than a consultant’s summary.

The NCA question turns on what you operate rather than what you are. The ECC reaches government agencies, their affiliated companies and entities inside and outside the Kingdom, and private-sector entities that own, operate or host Critical National Infrastructure. Financial services is among the sectors where that test can be met, so the honest answer for many institutions is “both” — and the way to settle it is to establish whether any of your systems are designated critical national infrastructure, in writing, rather than assuming either way.

Two further NCA sets are worth checking at the same time, because they apply according to what you run rather than who you are: the Cloud Cybersecurity Controls where you use or provide cloud services, and the Critical Systems Cybersecurity Controls where you operate critical systems. Our guide to the seven NCA control sets covers which is which — the abbreviations are easy to confuse, and citing a superseded edition is the most common documentation error in the Kingdom.

The difference that changes your programme

SAMA does not assess you as compliant or non-compliant. It assesses the maturity level you have reached, on a scale from nought to five, and it audits to determine which one that is. The NCA regime asks a different question: are the controls implemented as stated.

That distinction has real consequences for how you plan:

  • A compliance regime rewards implementation. The control exists, it is documented, it is applied. Evidence is largely about presence.
  • A maturity regime rewards operation and improvement. Higher levels require evidence that controls are measured, reviewed and improved over time — which cannot be assembled in the month before an audit, because the evidence is a history.

An institution in scope of both should therefore plan for the maturity target first, since a control set built to satisfy a maturity assessment will comfortably evidence a compliance assessment, while the reverse is not true. Our guide to the SAMA maturity levels covers what each level demands.

Running one control set for the SAMA CSF and the ECC

The overlap between the SAMA CSF and the ECC is substantial — governance, risk management, asset management, identity and access, operations, incident management, third-party risk and resilience appear in both, phrased differently. What follows is the mapping discipline that keeps one estate serving two regulators:

  1. Build the control library once, in your own numbering. Then map each internal control to the SAMA subdomain and the NCA control it satisfies. Never number your documents after one framework — that is how a re-edition forces a rewrite.
  2. Keep a single mapping table under version control. When the NCA moved from ECC-1:2018 to ECC 2-2024 the domain structure changed and controls moved; a maintained mapping turns that into an afternoon rather than a project.
  3. Record the evidence once, tag it twice. The access review that satisfies a SAMA subdomain is the same review an NCA assessor wants. What differs is the argument you attach to it.
  4. Cite editions in every document. “ECC” is not a citation. ECC 2-2024 is. A document citing a superseded edition looks exactly like a correct one until an assessor checks.

Frequently asked questions

Does the SAMA CSF replace the NCA ECC for banks?
No. They come from different authorities with different scope tests. Where both apply, both apply.

Which SAMA framework version is current?
The Cyber Security Framework issued under Circular 381000091275 of 24 May 2017, recorded in the SAMA Rulebook as In-Force. Check the Rulebook entry rather than a secondary summary, because each item there carries a status.

Which ECC edition should we cite?
ECC 2-2024, which replaced ECC-1:2018 and reduced the framework from five main domains to four. Documentation still citing the 2018 edition is citing controls that in some cases no longer sit in the ECC at all.

Is either one a certification?
Neither works like ISO 27001. SAMA determines a maturity level through its own audit; NCA compliance is assessed rather than certified by an accredited body.

Does ISO 27001 cover us for both?
It gives you most of the management system and a large share of the controls, but neither regulator accepts it as a substitute. Map it in as evidence, not as an answer.

Where this leaves you

Settle scope first: the SAMA CSF follows what you are, the NCA ECC follows what you operate, and many financial institutions meet both tests. Plan to the maturity target rather than the compliance floor, because maturity evidence is a history you cannot backfill. Then build one control library in your own numbering with a maintained mapping to both frameworks, and cite editions precisely — ECC 2-2024, not “the ECC” — because the cheapest finding either assessor can raise is a document that quotes a version that no longer exists.

References

  • SAMA Rulebook — where the Cyber Security Framework and its status are published.
  • NCA regulatory documents — the Essential Cybersecurity Controls and the other NCA control sets, with their editions.

More on Saudi cybersecurity regulation

Policies, control mappings and maturity evidence templates are in the SAMA Compliance Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.