Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NCA CSCC critical systems cybersecurity controls: 4 domains, 32 controls and 73 subcontrols, built on the ECC

NCA CSCC: The Essential 2026 Guide to the Critical Systems Cybersecurity Controls

NCA CSCC is the Critical Systems Cybersecurity Controls issued by Saudi Arabia’s National Cybersecurity Authority (NCA) as CSCC-1:2019, a set of additional requirements for systems whose failure or compromise could have a national-level impact. It sits on top of the Essential Cybersecurity Controls (ECC) rather than replacing them, so organizations that own or operate a critical system have more to do than those covered by the ECC alone.

This guide explains who NCA CSCC applies to, how it relates to the ECC, how the controls are organized, what it takes to prepare, and where organizations most often go wrong. It is written for security leads, compliance managers and system owners working in or with the Kingdom.

Free gap assessment

How much of ECC-2:2024 is actually in place?

Score all 28 subdomains, free, plus the other NCA control sets that apply alongside the ECC.

Run the free NCA ECC gap assessment →  or  View premium report sample

What NCA CSCC is and who it applies to

According to the NCA document, the controls set the minimum cybersecurity requirements for critical systems so that organizations can build protection and resilience capabilities for systems that support national interests. They apply to government organizations and their subsidiaries, and to private sector entities that own or operate critical systems. The NCA describes the CSCC as an extension and complement to the ECC, designed for the needs of national critical systems. You can read the source on the NCA Critical Systems Cybersecurity Controls page.

A critical system, in the NCA’s wording, is one whose failure or unauthorized access could affect business availability or cause economic, financial, security or social impact at national level. The document sets out the criteria for identifying such systems, so do not decide by intuition. Use the criteria in the current NCA text, record the assessment for each candidate system, and keep it for your regulator. If you are unsure whether a system qualifies, ask the NCA or your sector regulator.

How NCA CSCC relates to the ECC

The NCA states that continuous compliance with the ECC is a prerequisite for CSCC compliance. In practice, this means an organization with a critical system cannot treat the CSCC as a separate project. The ECC baseline must already work, and the CSCC then adds stronger requirements for the systems in scope. Our guides to the NCA ECC and to ECC implementation cover the base layer, and ECC-2:2024 explains the updated version of the ECC. Check the current NCA guidance on how the CSCC maps to the updated ECC, because the CSCC document itself is dated 2019.

AspectECCNCA CSCC
PurposeBaseline cybersecurity for organizationsAdditional controls for critical systems
ScopeThe organizationIdentified critical systems
RelationshipFoundationExtension and complement
PrerequisiteNoneContinuous ECC compliance

The structure of NCA CSCC

The NCA document is organized into four main domains, 21 subdomains, 32 main controls and 73 subcontrols. The four domains are:

  • Cybersecurity Governance. Policies, roles, risk management and the management of critical system programs.
  • Cybersecurity Defense. The technical protection layer: architecture, access, monitoring and operations.
  • Cybersecurity Resilience. Continuity of critical systems and recovery from disruption.
  • Third-Party and Cloud Computing Cybersecurity. Supplier and hosting arrangements for critical systems.

The control text is the authority. Use the domain descriptions above as a map, but read the exact wording of every control in the NCA document before you write your policies or evidence.

How to prepare for NCA CSCC compliance

1. Identify and document your critical systems

Start with an inventory of systems and apply the NCA criteria. Record the decision for each system, including those you decide are out of scope, with the reasoning. This is your scoping evidence and it will be the first thing a reviewer asks for.

2. Confirm your ECC baseline

Assess your ECC status honestly, since the NCA treats it as a prerequisite. Use the ECC self-assessment to find gaps in the foundation before you look at the additional CSCC requirements.

3. Map CSCC controls to your systems

For every CSCC control, decide which systems it applies to, what your current practice is, and what evidence shows it. A spreadsheet with one row per control and one column per system is enough to begin. Where the control has several subcontrols, track each one, since partial implementation is the norm.

4. Treat operational technology separately

Many critical systems include industrial control or operational technology components. These have their own NCA controls, covered in our guide to the OTCC operational technology controls. Do not assume that satisfying the CSCC settles an industrial environment, and check which NCA documents your system falls under.

5. Cover cloud and third parties

The fourth domain addresses third parties and cloud computing. If a critical system is hosted or supported externally, review contracts, access and monitoring arrangements against the control text, and read our overview of the NCA cloud cybersecurity controls.

6. Plan for evaluation

The NCA states that compliance is evaluated through self-assessment and on-site audits, and that organizations must implement the controls within the timeframes the NCA defines. Keep an evidence pack per control, with policy, procedure, configuration or log extracts, and the name of the owner. Preparing this before a request arrives saves weeks.

An illustrative scoping example

The following is a hypothetical example, not a real entity. A utility runs a customer billing platform, a corporate email system and a control room application that manages supply to a large city. The billing platform holds sensitive data but an outage would be inconvenient rather than dangerous. The control room application is different: if it fails, service could be disrupted at a scale that matters nationally. The team applies the NCA criteria to each system, records the reasoning, and concludes that the control room application and the platforms it depends on, such as its identity service and time synchronization, fall within scope. Billing and email stay under the ECC baseline. The written decision, signed by the system owner and the security lead, becomes the first item in the evidence pack.

What goes in a control evidence pack

An evidence pack should let someone who has never met your team understand how each control works and see proof that it runs. For every control and subcontrol, gather the following:

  • The policy or standard that states the requirement, with version and approval date.
  • The procedure that explains how staff carry it out.
  • Operating evidence: a configuration export, a log extract, a ticket, a review record or a test result from the last cycle.
  • The named owner and the date of the last review.
  • Known gaps, with an action, an owner and a target date.

Keep the pack in one location and index it against the control numbers in the NCA document, so that any request can be answered by pointing to a folder rather than assembling material from several teams.

A realistic ninety-day starting plan

Organizations new to the framework often stall because the whole control set looks enormous. Break it into stages.

  1. Days 1 to 30: confirm scope, complete the critical system inventory, and run the ECC self-assessment. Appoint an owner for each critical system.
  2. Days 31 to 60: map every control and subcontrol to each system, record current practice, and rank the gaps by risk to the system’s function.
  3. Days 61 to 90: close the quickest gaps, start longer projects such as architecture changes, and build the first evidence pack. Report status to senior management with a clear list of decisions needed.

After the first ninety days, move to a regular rhythm: monthly progress reporting, quarterly evidence reviews and a full self-assessment each year, so that you are always ready for a request from the regulator.

Common mistakes with NCA CSCC

  • Treating it as a standalone project. Without a working ECC baseline, CSCC evidence will not hold up.
  • Scoping too narrowly. Supporting systems, such as identity, monitoring and backup platforms, can become part of the critical system’s attack surface.
  • Policy without operation. A well-written policy does not show that the control runs day to day. Reviewers look for records of operation.
  • Ignoring third parties. Hosted components and support contractors are within the fourth domain, so cover them in contracts and monitoring.
  • Losing track of subcontrols. Reporting a control as compliant when one of its subcontrols is missing hides the real position.

Building your NCA CSCC documentation set

Most of the evidence an assessor wants is documentary: policies, standards, procedures, risk assessments, registers and records of review. The NCA Cybersecurity Toolkit gives you a structured set of templates aligned to the NCA framework that you can adapt to your organization and to any critical systems in scope. Whatever tool you use, keep the documents specific to your systems and make sure each one names an owner and a review date.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

NCA CSCC FAQ

Who has to comply with NCA CSCC?

The NCA states that it applies to government organizations, their subsidiaries and private entities that own or operate critical systems. Confirm your position with the NCA or your sector regulator.

Does NCA CSCC replace the ECC?

No. It extends and complements the ECC, and the NCA treats continuous ECC compliance as a prerequisite.

How many controls does NCA CSCC have?

The CSCC-1:2019 document contains 32 main controls and 73 subcontrols across four domains and 21 subdomains.

How is compliance assessed?

The NCA states that it evaluates compliance through self-assessments and on-site audits. Keep evidence ready for both.

Is there a newer version of NCA CSCC?

The NCA page reviewed for this guide lists CSCC-1:2019 and does not show a later version. Check the NCA website for updates before you rely on this guide.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.