Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NCA ECC implementation step by step

NCA ECC Implementation: A Clear Guide in 6 Steps

NCA ECC implementation is a compliance exercise, not a certification project, and that distinction changes how you should run it. Saudi Arabia’s National Cybersecurity Authority assesses organizations against the Essential Cybersecurity Controls — currently ECC 2-2024, with four domains, 28 subdomains and 109 controls — rather than issuing a certificate through an accredited body.

This guide sets out the implementation sequence, what evidence each control needs, and the two mistakes that make an otherwise complete programme fail an assessment.

NCA ECC implementation: the sequence from scope to assessment
Six steps, and the first two decide how much of the work you actually have to do.

Before NCA ECC implementation: confirm scope and edition

Two checks come before any NCA ECC implementation work, and both are cheap to do and expensive to skip.

Which entity type are you? The ECC reaches government agencies, their affiliated companies and entities inside and outside the Kingdom, and private-sector entities that own, operate or host Critical National Infrastructure. If you are a financial institution you may also sit under the SAMA Cyber Security Framework — a different authority with a maturity-based assessment. Our guide to SAMA CSF versus NCA ECC covers the overlap.

Which control sets apply? The ECC is the baseline, but the NCA publishes a family. If you use or provide cloud services the Cloud Cybersecurity Controls apply; if you run operational technology the OTCC does; critical systems and data have their own sets. Establishing this at the start prevents the most expensive failure mode — building a programme against the ECC alone and discovering a second control set during assessment. See our guide to the seven NCA control sets.

And cite the edition. ECC 2-2024 replaced ECC-1:2018 and reduced the framework from five main domains to four; documentation still quoting the 2018 numbering is quoting controls that in some cases no longer sit in the ECC at all.

The NCA ECC implementation sequence

  1. Scope and asset baseline. Which entities, sites, systems and data are in. An asset inventory that is incomplete at this stage produces gaps everywhere downstream, because most controls are asset-scoped.
  2. Gap assessment against all applicable control sets. Control by control, with three states — implemented, partially implemented, not implemented — and the evidence reference for anything claimed as implemented.
  3. Governance first. The strategy, the policies, the roles, the steering committee and the risk process. Technical controls without the governance layer will be assessed as partial, because the ECC asks for defined, approved and reviewed as well as done.
  4. Close the technical gaps in risk order, keeping the evidence as you go rather than reconstructing it before the assessment.
  5. Run an internal review as a rehearsal of the assessment: same controls, same evidence requests, different people.
  6. Assessment and remediation. Findings become a plan with owners and dates, and the plan itself is evidence of a functioning programme.

What “implemented” has to mean

Each control needs three things, and most programmes produce only the first two:

  • A document — the policy or standard that requires it, approved and dated.
  • A mechanism — the configuration, tool or process that does it.
  • A record — evidence it ran: the review that happened, the log that was examined, the exception that was approved.

The record is the one that decides an assessment. A policy requiring quarterly access reviews plus an identity platform capable of them is not implementation; four quarters of completed reviews with names against them is.

The two NCA ECC implementation mistakes that cost the most

Building against the ECC alone. The other control sets apply by what you operate, not by who you are, and they are written as extensions rather than alternatives. An organization with cloud services and OT systems is in scope for three sets at once and its documentation has to cite them accurately.

Treating the ECC as a document-writing exercise. The controls are phrased around defined, implemented and periodically reviewed practice. A complete policy library with no operating records reads as a programme designed for the assessment rather than for the organization — and assessors have seen a great many of those.

Where ISO 27001 helps, and where it does not

NCA ECC implementation is faster if you hold ISO 27001: you already have the management system, most of the governance layer and a large share of the technical controls. That is a genuine head start, and mapping your Statement of Applicability to the ECC is usually the fastest first pass at the gap assessment.

What it does not do is satisfy the ECC. The NCA has its own control text, its own numbering and Kingdom-specific expectations that no international standard reaches. Map ISO 27001 in as evidence; do not offer the certificate as an answer.

Frequently asked questions

Is NCA ECC compliance a certification?
No. Organizations are assessed for compliance against the controls rather than certified by an accredited body the way ISO 27001 works.

Which ECC edition applies?
ECC 2-2024, which replaced ECC-1:2018 and moved from five main domains to four. Documentation citing the older edition should be rewritten rather than renumbered.

Do we need the other NCA control sets?
It depends on what you operate — cloud services, operational technology, critical systems and certain data types each bring their own set, written as extensions of the ECC.

How long does implementation take?
For an organization with an existing ISMS, months rather than a year, with the evidence history being the constraint. Starting from nothing, plan for a full cycle of reviews and audits before you can evidence “periodically reviewed”.

Who owns it internally?
A named cybersecurity function reporting at a level that can enforce governance. The ECC expects defined roles and authority, and an assessment will look for them.

Where this leaves you

Start NCA ECC implementation with scope, edition and the question of which control sets apply — those three answers determine the size of the work. Build the governance layer before the technical fixes, keep the operating record as you implement rather than reconstructing it later, and rehearse the assessment internally. And cite ECC 2-2024 explicitly everywhere, because a document quoting a superseded edition looks exactly like a correct one until somebody checks.

References

  • NCA regulatory documents — the Essential Cybersecurity Controls and the rest of the control family, with editions.
  • ISO/IEC 27001 — the management system most Kingdom programmes map in as supporting evidence.

More on Saudi cybersecurity compliance

Policies, control mappings and assessment evidence templates are in the NCA Cybersecurity Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.