The NCA ECC self-assessment is how most organizations in Saudi Arabia actually demonstrate compliance with the Essential Cybersecurity Controls. NCA does not certify entities and does not audit every one of them; it evaluates compliance “through multiple means, such as self-assessment by the entities, periodic reports of the compliance tool, and/or field auditing visits”. For the majority, the self-assessment and the compliance tool are the whole relationship. This guide explains what the ECC-2:2024 Assessment and Compliance Tool is, how the self-assessment is structured and submitted, what NCA does with it, and the mistakes that turn a routine submission into a finding.

What the NCA ECC self-assessment is
ECC-2:2024 states that NCA “will issue a tool (ECC-2:2024 Assessment and Compliance Tool) to organize the process of assessment and measurement of compliance by entities in applying the ECC”. The tool is the structured workbook through which an entity records, control by control, whether each of the ECC’s controls is implemented, and with what evidence. NCA’s self-assessment service then lets national entities “conduct a self-assessment of their compliance with the NCA’s regulations”, after which “NCA reviews the self-assessment results and provides feedback if needed”.
The obligation behind it is not optional. Under Article 10(3) of NCA’s Statute and High Order 57231, every entity in scope “shall take all necessary measures to ensure ongoing and continuous compliance”. The self-assessment is the mechanism NCA uses to see that, and it is the entity’s opportunity to show it on its own terms before an external assessment or field visit does.
Who has to submit a NCA ECC self-assessment
The scope is the ECC scope: government agencies (ministries, authorities, establishments and others) and their affiliated companies and entities inside and outside the Kingdom, plus private sector entities owning, operating or hosting Critical National Infrastructure. ECC-2:2024 widened the government scope explicitly to affiliated entities outside the Kingdom, so overseas subsidiaries of Saudi government companies are now in. Entities outside that scope are encouraged to adopt the ECC but are not required to submit. Our guide to NCA ECC compliance for Saudi firms covers who falls where.
The platform: Haseen
Submissions go through Haseen, NCA’s compliance platform, which is also reachable through the national portal. NCA describes the service as available around the clock, in Arabic and English, with an instant service implementation period and no stated prerequisites beyond being a registered national entity. Two capabilities matter for the compliance function: the platform lets an entity “view current and past compliance results”, so previous submissions remain visible and comparable, and it tracks “the follow-up process of assigned regulations and the submission status based on periods for each regulation” — meaning NCA assigns the control sets an entity must report against and the windows in which to do it. The ECC is one of those regulations; the CCC, DCC, OTCC and others are assigned separately where they apply.
How the NCA ECC self-assessment is structured
The assessment follows the ECC’s own structure: four main domains, 28 subdomains and 109 controls. For each control, the entity records an implementation status and the supporting evidence. The status vocabulary is a compliance scale, not a maturity scale — the four states used across NCA-aligned assessment workbooks are:
| Status | Meaning | What NCA expects to see |
|---|---|---|
| Implemented | The control is fully in place and operating | Approved document, evidence of implementation, evidence of periodic review |
| Partially implemented | Some sub-controls or scope are in place | What is done, what is not, and a dated remediation plan |
| Not implemented | The control is applicable and absent | A remediation plan with an owner and a date |
| Not applicable | The control does not apply to the entity | A written justification — e.g. subdomain 4-2 where no cloud services are used |
The ECC’s own statement of applicability gives the model for justified exclusions: controls under subdomain 4-2, Cloud Computing and Hosting Cybersecurity, are “applicable and binding on entities currently using or planning to use cloud computing and hosting services” — and by implication not applicable to entities that use none. Every other “not applicable” needs an argument of that quality.
The four-part pattern inside most subdomains
Most ECC subdomains follow the same sequence, and the self-assessment is easier once you see it: requirements are identified, documented and approved (the first control), implemented (the second), must include at least a listed minimum (the third, with numbered sub-controls), and are periodically reviewed (the last). Identity and access management, for example, runs 2-2-1 through 2-2-4 in exactly that order. An entity that has a policy but no review record is typically “partially implemented” on the whole subdomain, because the final control fails. Plan the evidence set per subdomain around those four verbs.
What NCA does with the submission
NCA reviews the results and “provides feedback if needed”. Feedback ranges from acceptance to requests for evidence to a directed remediation plan. Two things follow from the ECC’s compliance text that entities should plan for:
- Periodic reports of the compliance tool. The self-assessment is not a one-off. NCA refers to periodic reporting, and Haseen tracks submission periods per regulation. Treat it as a recurring cycle with a standing owner.
- Field auditing visits. NCA reserves the right to verify on site. The self-assessment status you submit is the position an auditor will test, so an optimistic “implemented” is a liability rather than a saving.
Six mistakes that turn a NCA ECC self-assessment into a finding
- Assessing against the old edition. ECC-2:2024 replaced ECC-1:2018. Domain 5 (Industrial Control Systems) was deleted and its controls moved to the OTCC; control 1-2-2 now requires all cybersecurity positions to be filled by full-time, qualified Saudi professionals, not only the head of function. A workbook built on the 2018 structure answers the wrong questions. Our summary of the ECC 2-2024 changes lists what moved.
- Treating “documented” as “implemented”. The first control in each subdomain is satisfied by an approved document. The second is not. Evidence of implementation is configuration, records, tickets, logs — not the policy again.
- No periodic review record. The last control in each subdomain fails silently when nobody has scheduled the review. A review calendar with completed entries is the cheapest evidence in the whole assessment.
- Unjustified “not applicable”. Marking a control N/A because it is hard is the fastest way to a directed finding. Only scope-based exclusions with a written rationale survive review.
- Forgetting the extensions. Entities assigned the CCC, DCC or OTCC report on those separately. An ECC submission that claims full compliance while the DCC submission is missing is inconsistent on its face. The Data Cybersecurity Controls in particular reference ECC controls directly, so the two must agree.
- A single owner with no sign-off. ECC 1-8-3 requires audit and review results to be presented to the cybersecurity supervisory committee and the Authorized Official. A self-assessment that the committee has never seen is itself a gap under 1-8.
Running the assessment internally before you submit
The entities that get clean feedback run the NCA ECC self-assessment twice: once as a genuine internal audit, once as the submission. The internal pass should be led by someone outside the cybersecurity function — ECC 1-8-2 requires review and audit “by parties other than the cybersecurity department”, independently and considering conflict of interest — and should sample evidence rather than accept assertions. The gaps it finds become the remediation plan that accompanies “partially implemented” and “not implemented” entries. Our six-step ECC implementation guide describes the sequence for closing those gaps.
Keep the NCA ECC self-assessment evidence index outside the tool. The compliance tool records status; it is not an evidence repository. A control-by-control index naming each document, record and system, with a location and an owner, is what makes the next cycle a refresh rather than a rebuild, and it is what a field visit will ask for first.
Frequently asked questions
Is the NCA ECC self-assessment mandatory?
For entities in the ECC scope, ongoing compliance is mandatory under Article 10(3) of NCA’s Statute and High Order 57231, and NCA evaluates it through self-assessment, compliance-tool reports and field visits. Entities outside scope are encouraged, not required, to adopt the ECC.
Where is it submitted?
Through Haseen, NCA’s compliance platform, which is also accessible via the national portal. The platform shows current and past results and the submission periods assigned to each regulation.
How many controls does it cover?
The ECC-2:2024 has four main domains, 28 subdomains and 109 controls. The self-assessment records a status and evidence for each applicable control.
Does NCA issue a certificate?
No. NCA reviews the self-assessment and provides feedback if needed. There is no ECC certificate; compliance is a continuing status, not a credential.
What about the CCC, DCC and OTCC?
They are separate regulations assigned to the entities they apply to, with their own submissions. Each extends the ECC and cross-references ECC control numbers, so the assessments should be prepared together.
Where this leaves you
The NCA ECC self-assessment rewards the same discipline every other compliance regime does: an honest status per control, evidence behind every “implemented”, a justification behind every “not applicable”, and a dated plan behind everything else. Run it internally first, get the supervisory committee’s sign-off, then submit — and keep the evidence index so the next period is a review, not a rebuild.
References
- Essential Cybersecurity Controls (ECC-2:2024) — The control set, including the Implementation and Compliance and Assessment and Compliance Tool sections.
- NCA self-assessment service — NCA’s description of the self-assessment service and the Haseen platform.
More on NCA compliance
- The NCA ECC self-assessment — you are here
- NCA ECC: a cybersecurity compliance guide for Saudi firms
- ECC 2-2024: all four domains
- NCA ECC implementation in six steps
- The seven NCA control sets
Policies, the control-by-control evidence index and the review calendar behind an ECC submission are in the NCA Cybersecurity Toolkit, or start with the free templates.