NCA ECC third-party cybersecurity controls set out what Saudi organizations must do when suppliers, outsourcers and managed service providers handle their systems or data. The Essential Cybersecurity Controls issued by the National Cybersecurity Authority include a subdomain dedicated to third parties, and it is one of the areas where assessors look closely at contracts and evidence. This guide explains the requirements, what to put in contracts, how to handle managed services and how to show compliance.
The control wording below comes from the official ECC document that our research tools could open, which is labelled ECC-1:2018. A newer edition, ECC-2:2024, exists, and control numbers or wording may differ. Confirm each point in the current edition before you use it in policy. For the wider framework, see our guides to NCA cybersecurity controls and ECC implementation.
Free gap assessment
How much of ECC-2:2024 is actually in place?
Score all 28 subdomains, free, plus the other NCA control sets that apply alongside the ECC.
Run the free NCA ECC gap assessment → or View premium report sample
What the third-party subdomain covers
In ECC-1:2018 the subdomain on third-party cybersecurity states an objective: to ensure the protection of assets against the cybersecurity risks related to third parties, including outsourcing and managed services, in line with organizational policies and applicable laws. It contains four controls, summarised below.
| Control (ECC-1:2018) | Requirement in summary |
|---|---|
| 4-1-1 | Identify, document and approve cybersecurity requirements for contracts and agreements with third parties |
| 4-1-2 | Include in contracts non-disclosure clauses, secure removal of the organization’s data at the end of service, incident communication procedures, and third-party compliance with the organization’s policies and applicable laws |
| 4-1-3 | For IT outsourcing and managed services, assess cybersecurity risk before the contract or on regulatory change, and locate managed cybersecurity monitoring and operations centres inside the Kingdom |
| 4-1-4 | Review third-party cybersecurity requirements periodically |
The official document uses language such as “must”, so treat these as mandatory for organizations in scope. If your organization also falls under sector rules, compare them, since some regulators add their own supplier requirements.
Control 4-1-1: define approved requirements
Start with a standard set of cybersecurity requirements for suppliers, approved by management and mapped to your policies. Vary the set by supplier risk: a supplier with access to sensitive systems needs the full set, while a supplier that only delivers office furniture needs little. Record who approved it and when, and store it where procurement and legal can find it. The evidence assessors ask for is the approved requirements document and examples of it applied in real contracts.
Control 4-1-2: contract clauses
Contracts with third parties must include several specific clauses. Build them into your standard terms.
- Non-disclosure. Confidentiality obligations that continue after the contract ends.
- Secure removal of data. A duty to remove the organization’s data securely when the service ends, with evidence such as a deletion certificate.
- Incident communication. Contacts, timing and format for reporting cybersecurity incidents.
- Compliance. A duty to comply with your policies and with applicable laws and regulations.
Add supporting terms such as audit rights, subcontractor approval and change notification. Check existing contracts for gaps, and update them at renewal. Our guide to the NCA CSCC covers additional requirements for critical systems.
Control 4-1-3: outsourcing and managed services under NCA ECC third-party cybersecurity
For IT outsourcing and managed services, the official text says contracts must be preceded by a cybersecurity risk assessment, or triggered again when regulatory requirements change. It also says that managed cybersecurity services centres for monitoring and operations must be completely present inside the Kingdom of Saudi Arabia. In practice, this means that a foreign security operations centre cannot monitor your systems remotely under a standard contract, so check provider locations and staff. Ask providers where monitoring is performed, and record the answer in the contract.
Free third-party risk assessment
How much risk does this vendor bring?
Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.
Start the free vendor risk assessment → or View premium report sample
Managed services assessment steps
- Define the scope of the service and the data and systems involved.
- Assess risks, including access level, sensitivity and dependency.
- Verify where operations centres and staff are located.
- Agree security requirements and monitoring in the contract.
- Approve the assessment and the contract at the right level.
- Reassess when regulations or the service change.
Control 4-1-4: periodic review
Requirements should not be written once and forgotten. Review them on a defined schedule, for example annually, and after regulatory changes. Record the review, any changes to the standard set of clauses and the actions for existing contracts. Keep a supplier register showing which contracts contain the current clauses and which are due for update.
Finally, keep contract templates aligned with the framework. When the authority updates the controls, review your clauses so that new contracts and renewals reflect NCA ECC third-party cybersecurity expectations, and log the version of the framework each template follows.
Cloud and third-party overlap
The same ECC domain also deals with cloud computing, and cloud providers are third parties too. Apply the third-party controls to them, and add the cloud-specific requirements. See our guide to the cloud cybersecurity controls for details.
Evidence for an NCA ECC third-party cybersecurity assessment
- Approved third-party cybersecurity requirements.
- A supplier register with risk ratings and contract status.
- Sample contracts showing the required clauses.
- Pre-contract risk assessments for outsourcing and managed services.
- Evidence of where managed service operations are located.
- Records of periodic reviews of requirements.
- Data removal certificates for ended services.
Our NCA ECC self-assessment guide shows how to map evidence to controls.
Building a third-party risk process that meets NCA ECC third-party cybersecurity controls
A working process ties the four controls together. Procurement raises a request, the security team classifies the supplier by risk, and legal drafts the contract with the approved clauses. For outsourcing and managed services, the security team completes the risk assessment before signature. After go-live, a relationship owner tracks performance, incidents and changes, and the supplier register records review dates. Write the process as a short procedure with roles and forms, and train procurement and legal staff so they know when to involve security. Many findings arise not from missing policies but from staff who never knew the policy applied.
Classifying suppliers by risk
Not every supplier deserves the same effort. Create three or four tiers based on access to systems and data, criticality of the service and replaceability. Critical suppliers, such as those with privileged access or hosting sensitive data, get a full assessment, strong contract terms and regular reviews. Lower tiers receive lighter checks. Record the tier in the register, and use it to decide the evidence required. This keeps the workload manageable while giving the authority a clear, risk-based rationale.
Monitoring and exit
Contracts are only the start. Ask critical suppliers for periodic evidence such as assurance reports, test summaries and incident reports, and review it. Track service levels and complaints. For exit, plan ahead: define how data will be returned or removed, how access will be revoked and how services will move to another provider. The requirement for secure data removal at the end of service is easier to meet when the process is agreed from the start. Ask for written confirmation of deletion, and keep it with the contract file.
Working with providers on evidence
Providers are more likely to cooperate when they know what you need. Share a short list of requirements and evidence expectations at the start, and agree contacts on both sides. If a provider cannot meet a requirement, record the gap, agree a plan or decide on an alternative. Do not leave issues open without owners, because open gaps are the easiest findings for assessors to raise.
A hypothetical example
A hypothetical Saudi logistics company plans to outsource security monitoring. It first performs a risk assessment covering the data the provider will see and the access it will need. It asks shortlisted providers where their monitoring centres and analysts are located, and rejects one whose operations centre is abroad. The contract includes the four required clause types, and at the end of the previous supplier’s contract the company obtains a data deletion certificate. The requirements document is reviewed each year. The example is invented for illustration.
Common findings on NCA ECC third-party cybersecurity
- No approved set of third-party cybersecurity requirements.
- Contracts missing data removal or incident communication clauses.
- Managed security services delivered from outside the Kingdom.
- No risk assessment before outsourcing.
- Requirements never reviewed after regulatory change.
- Incomplete supplier register.
The primary source is the official NCA ECC document. Use the current edition and consult the authority or a qualified adviser if the wording is unclear.
Templates for NCA ECC third-party cybersecurity
To avoid drafting supplier requirements, contract clauses and review records from scratch, the NCA Cybersecurity Toolkit provides documents you can adapt. Have a qualified Saudi adviser confirm them against the current edition.
NCA ECC third-party cybersecurity FAQ
Which controls cover third parties?
In ECC-1:2018, the third-party subdomain has controls 4-1-1 to 4-1-4. Check the numbering in ECC-2:2024.
Can a foreign provider run our security monitoring?
The ECC-1:2018 text requires managed cybersecurity monitoring and operations centres to be completely present inside the Kingdom. Confirm the current rule.
What must contracts include?
Non-disclosure, secure data removal at the end, incident communication and compliance with your policies and applicable laws.
How often should we review requirements?
The control calls for periodic review. Many organizations do so annually and after regulatory changes.
Do these controls apply to cloud providers?
Yes, cloud providers are third parties, and additional cloud controls apply.