HalaCyber

NCA ECC Assessment in Saudi Arabia

NCA ECC Compliance Assessment in Saudi Arabia, ECC 2:2024 Applicability, Compliance, and Readiness

Assess your organization through an NCA ECC compliance assessment in Saudi Arabia against NCA ECC 2:2024, the Essential Cybersecurity Controls framework, across ECC applicability, control compliance, evidence readiness, and remediation priorities for Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party and Cloud Computing Cybersecurity.

Hala Cyber delivers an evidence-based NCA ECC assessment that helps organizations identify applicable ECC controls, evaluate implementation and supporting evidence, surface material gaps, and build a clearer path toward compliance readiness, audit preparedness, and ongoing cybersecurity compliance management in Saudi Arabia.

Built around

NCA ECC applicability

ECC control evidence

Management-ready outputs

NCA ECC Gap Assessment

This NCA ECC assessment is designed to show leadership and control owners where the organization stands against applicable ECC controls, which evidence gaps are missing or weak, and which remediation actions should be prioritized first to strengthen compliance readiness and audit preparedness.

01

Structured ECC review

A focused assessment aligned to applicable ECC domains and control areas.

02

Evidence gap visibility

A clearer view of missing, weak, or inconsistent control evidence.

03

Prioritised remediation roadmap

Actionable next steps sequenced around material gaps and ownership.

04

Better audit preparedness

Stronger readiness for assurance activity, review cycles, and management reporting.

Assessment Foundations

NCA ECC 2:2024 Assessment Foundations in Saudi Arabia, Applicability, Coverage, Clarity, and Readiness Before Detailed Review

Review the assessment foundations that shape NCA ECC applicability, scope, coverage, evidence clarity, and readiness before detailed control testing begins, helping organizations frame the assessment more accurately and move toward a clearer compliance position in Saudi Arabia.

Assessment Focus Areas
ECC Assessment Foundations

How ECC objectives become assessment foundations before scope, evidence, and control review begin

Review how the main ECC objective areas translate into assessment foundations for scope, evidence expectations, review logic, and remediation direction before detailed control testing begins.

Selected foundation view

Minimum baseline

Minimum cybersecurity requirements become the assessment baseline for scope and review

ECC establishes the minimum cybersecurity requirements for applicable entities in Saudi Arabia, giving the assessment a baseline for scope, control review, and evidence expectations before deeper testing begins.

4 foundation views
What this foundation anchors
This foundation anchors the minimum control baseline that the assessment uses to define the initial review perimeter and the minimum expectations that should already be supportable.
How the assessment uses it

The assessment uses this foundation to determine which applicable requirements should form the minimum control perimeter before deeper maturity or remediation questions are explored.

What becomes clearer
A clearer baseline view that helps show where minimum ECC expectations are already supported, weakly evidenced, or not yet sufficiently implemented.
NEXT FOUNDATION

See how ECC scope and applicability determine the assessment perimeter.

Selected foundation view

Protection priorities

Asset protection objectives become the foundation for assessment relevance and priority

ECC is designed to reduce cyber threats against information and technology assets, making asset protection a core foundation for how the assessment interprets relevance, priority, and exposure.

4 foundation views
What this foundation anchors
This foundation anchors what the assessment should be trying to protect by linking the review to the information assets, technology environments, and services that matter most.
How the assessment uses it
The assessment uses this foundation to determine which assets, environments, services, and dependencies should sit closest to the center of the review and remediation discussion.
What becomes clearer
A more risk-relevant assessment that connects findings to the assets and operating environments most exposed to operational and cybersecurity impact.
NEXT FOUNDATION

See how ECC scope and applicability determine the assessment perimeter.

Selected foundation view

CIA outcome lens

Confidentiality, integrity, and availability become the lens for why findings matter

ECC is anchored in the protection outcomes of confidentiality, integrity, and availability, which shape how the assessment interprets control weaknesses, evidence gaps, and materiality.

4 foundation views
What this foundation anchors
This foundation anchors the outcome lens used to explain whether weaknesses could affect confidentiality, integrity, or availability across relevant systems, services, and information assets.
How the assessment uses it
The assessment uses this foundation to translate control and evidence issues into more decision-useful questions about whether important protection outcomes are exposed or weakly supported.
What becomes clearer
A more outcome-driven assessment view that helps leadership understand why specific weaknesses matter in practice and how they relate to business impact.
NEXT FOUNDATION

See how ECC scope and applicability determine the assessment perimeter.

Selected foundation view

Operating model

Strategy, people, process, and technology become the foundation for operating readiness

ECC is built around strategy, people, process, and technology, showing that cybersecurity is expected to operate through a full management and control model, not only through technical safeguards.

4 foundation views
What this foundation anchors
This foundation anchors the expectation that cybersecurity should operate through governance, ownership, process discipline, people capability, and technology execution together.
How the assessment uses it
The assessment uses this foundation to test whether cybersecurity is embedded as a managed capability across governance, operating procedures, accountability, and technical execution, not just documented on paper.
What becomes clearer

A broader readiness view that helps expose weaknesses in governance, ownership, process discipline, and operating maturity, not only technical controls.

NEXT FOUNDATION

See how ECC scope and applicability determine the assessment perimeter.

NCA ECC Assessment Coverage Areas

How the NCA ECC assessment is organized across governance, defense, resilience, and third-party and cloud computing cybersecurity

The NCA ECC assessment is organized around the framework’s main cybersecurity domains so the review can move in a structured way across governance, technical safeguards, resilience, and external dependency risk, helping teams understand what will be reviewed, where evidence will be needed, and where findings are likely to emerge.

Selected coverage view

Coverage area

NCA ECC Cybersecurity Governance Assessment

Review strategy, oversight, accountability, policy hierarchy, risk management, project governance, compliance obligations, HR-related controls, and awareness maturity.

4 coverage views
Why this coverage area matters
Governance matters because it shows whether cybersecurity is directed, approved, assigned, reviewed, and monitored in a way that supports accountability and defensible compliance.
What the assessment examines
The assessment examines strategy, management structure, roles and responsibilities, policies and procedures, risk management, project governance, compliance obligations, HR-related controls, and awareness and training expectations.
What becomes clearer
A clearer governance picture that shows whether leadership, accountability, policy control, ownership, and governance discipline are strong enough to support ongoing ECC compliance.
NEXT FOUNDATION
See what should be clarified early to reduce rework and strengthen defensibility.

Selected coverage view

Coverage area

NCA ECC Cybersecurity Defense Control Review

Assess asset visibility, access control, systems protection, email security, network security, mobile security, data protection, cryptography, backup, vulnerability management, penetration testing, logging and monitoring, incident and threat management, physical security, and web application security.

4 coverage views
Why this coverage area matters
Defense matters because it is where most operational and technical safeguards are tested, which is why it often drives the heaviest evidence and implementation review effort in the assessment.
What the assessment examines
The assessment examines asset management, identity and access management, systems protection, email security, network security, mobile security, data protection, cryptography, backup and recovery, vulnerability management, penetration testing, event logs and monitoring, incident and threat management, physical security, and web application security.
What becomes clearer
A clearer technical and operational safeguard view showing which controls are well implemented, weakly evidenced, inconsistently operating, or materially exposed.
NEXT FOUNDATION
See what should be clarified early to reduce rework and strengthen defensibility.

Coverage area

Coverage area

NCA ECC Cybersecurity Resilience Readiness

Evaluate business continuity alignment, operational resilience capability, and the organization’s ability to sustain critical services during cyber disruption and recovery scenarios.

4 coverage views
Why this coverage area matters
Resilience matters because it shows whether the organization can sustain critical services when cyber disruption still occurs, making it important for continuity, recovery, and executive readiness.
What the assessment examines
The assessment examines cybersecurity resilience aspects of business continuity management, including continuity-related cybersecurity requirements, response planning, disaster recovery alignment, and the organization’s ability to support service continuity during cyber events.
What becomes clearer
A clearer resilience view showing whether continuity and recovery planning are documented, owned, realistic, and supported by enough evidence to demonstrate readiness.
NEXT FOUNDATION
See what should be clarified early to reduce rework and strengthen defensibility.

Selected coverage view

Coverage area

NCA ECC Third-Party and Cloud Computing Cybersecurity Review

Examine due diligence, contractual safeguards, monitoring obligations, cloud accountability, access restrictions, and assurance evidence across suppliers and cloud computing and hosting environments.

4 coverage views
Why this coverage area matters
Third-party and cloud coverage matters because external dependencies often expand the assessment perimeter and introduce evidence, accountability, and control challenges that are not visible through internal review alone.
What the assessment examines
The assessment examines third-party due diligence, contractual safeguards, provider obligations, outsourcing risk, cloud accountability, hosted environment controls, provider dependency, and supporting assurance evidence.
What becomes clearer
A clearer external dependency view showing how much of the organization’s control exposure depends on third parties or cloud providers, and whether those dependencies are governed and evidenced strongly enough.
NEXT FOUNDATION
See what should be clarified early to reduce rework and strengthen defensibility.
NCA ECC Assessment Clarity

How early clarity decisions shape assessment scope, evidence quality, ownership, and a more defensible ECC compliance position

Assessment clarity matters before detailed review begins because unclear applicability, weak evidence logic, and uncertain compliance positioning often lead to mis-scoping, poor evidence requests, ownership confusion, and late remediation rework. This tab shows the main clarity areas that should be resolved early to support a more defensible NCA ECC assessment.

Selected clarity view

Applicability

Applicability should be clear early because it defines whether ECC is binding and what sits inside the assessment perimeter

Applicability is the first assessment decision because it determines whether ECC is binding, what sits inside the review perimeter, and which domains and controls should actually be assessed.

3 clarity views
Why this needs clarity
Applicability needs clarity because it sets the assessment boundary, determines control relevance, and influences the evidence model from the start.
What the assessment must resolve
The assessment must resolve whether ECC applies to the entity or operating environment, and which services, systems, cloud arrangements, or dependencies should be brought into scope early.
What becomes clearer
A more defensible starting point with clearer scope, stronger control relevance, and fewer late-stage scope changes or avoidable rework.
NEXT FOUNDATION
Review how the assessment supports readiness for evaluation, reporting, and ongoing compliance.

Selected clarity view

Evidence

Evidence should be clarified early so the assessment does not collect the wrong material or misread the real gap

Even when scope is broadly understood, the assessment can still fail if the wrong evidence is requested, if ownership is unclear, or if teams cannot distinguish between a control weakness and an evidence weakness.

3 clarity views
Why this needs clarity
Evidence needs clarity because poor request logic, unclear ownership, and weak evidence discipline quickly create inefficiency and confusion during the review.
What the assessment must resolve
The assessment must resolve which artifacts should be collected, which stakeholders own them, how evidence should be reviewed, and where gaps are caused by missing documentation versus real implementation issues.
What becomes clearer
A more efficient assessment with better-targeted evidence requests, clearer ownership, and findings that are easier to explain, prioritise, and defend.
NEXT FOUNDATION
Review how the assessment supports readiness for evaluation, reporting, and ongoing compliance.

Selected clarity view

Compliance

Compliance should be clarified early because ECC is an ongoing expectation, not a one-time assessment event

ECC is framed as an ongoing compliance expectation, so organizations need clarity not only for the current assessment, but also for self-assessment, compliance tool reporting, and field auditing readiness.

3 clarity views
Why this needs clarity
Compliance needs clarity because the assessment should support reporting, defensibility, and sustainable follow-through after the review ends.
What the assessment must resolve
The assessment must resolve how the current review should support reporting, management visibility, auditability, and a more sustainable compliance position beyond a single assessment cycle.
What becomes clearer
A stronger compliance view that helps the organization use the assessment as a readiness foundation for reporting, auditability, and ongoing compliance management.
NEXT FOUNDATION
Review how the assessment supports readiness for evaluation, reporting, and ongoing compliance.
NCA ECC Scope and Applicability

How ECC applicability determines assessment scope, relevant controls, and evidence expectations

ECC applicability is one of the first assessment decisions because it determines whether ECC is binding, which domains and controls should be reviewed, what evidence will be needed, and how the assessment perimeter should be defined.

Selected applicability view

Minimum baseline

ECC applies to government agencies in Saudi Arabia, including ministries, authorities, establishments, and public bodies that fall within the framework scope.

4 applicability views
Why this matters
Government entities are the clearest binding starting point under ECC, which is why this category often anchors the initial assessment perimeter and scope logic.
What the assessment needs to clarify
The assessment needs to clarify whether the entity itself falls directly within public-sector scope, and which environments, services, and control areas should sit inside the review perimeter from the start.
What becomes in scope
A more clearly defined baseline scope for governance, control applicability, evidence collection, and accountability across the assessed environment.
NEXT FOUNDATION
Review how the assessment is organized across the main ECC coverage areas.

Selected applicability view

Affiliated Entities

ECC is designed to reduce cyber threats against information and technology assets, making asset protection a core foundation for how the assessment interprets relevance, priority, and exposure.

4 foundation views
Why this matters
Affiliated structures often create scope ambiguity, especially where ownership, operating control, or cross-border structure affects whether ECC obligations extend beyond the core government body.
What the assessment needs to clarify
The assessment needs to clarify whether the affiliation is sufficient to bring the entity, operating unit, or part of its services into ECC scope, and how that changes the review boundary.
What becomes in scope
A more defensible assessment perimeter for affiliated operations, shared services, and inherited obligations that would otherwise remain unclear.
NEXT FOUNDATION
Review how the assessment is organized across the main ECC coverage areas.

Selected applicability view

Private CNI Entities

ECC is applicable to private sector entities that own, operate, or host Critical National Infrastructures, making the framework binding for those in-scope operating environments.

4 foundation views
Why this matters
This is the most commercially important private-sector applicability question because ECC becomes binding where critical national infrastructure ownership, operation, or hosting is involved.
What the assessment needs to clarify
The assessment needs to clarify whether the organization’s operational role, services, or infrastructure position place it within ECC scope, and which domains or control areas should be prioritised first.
What becomes in scope
A more risk-relevant assessment perimeter tied to critical services, operational dependence, and supporting evidence expectations.
NEXT FOUNDATION
Review how the assessment is organized across the main ECC coverage areas.

Selected applicability view

Cloud and Hosting Users

Cloud Computing and Hosting Cybersecurity controls are applicable and binding on entities currently using or planning to use cloud computing and hosting services, based on their business and technology use.

4 foundation views
Why this matters
Cloud and hosting use can materially affect applicability and can expand the control areas that need to be reviewed, especially around third-party and hosted environments.
What the assessment needs to clarify
The assessment needs to clarify whether current or planned cloud use makes relevant ECC controls binding, and how hosted environments, provider dependencies, and evidence access affect the review.
What becomes in scope
A clearer perimeter for cloud-related control assessment, provider evidence expectations, and hosted environment review.
NEXT FOUNDATION
Review how the assessment is organized across the main ECC coverage areas.
NCA ECC Assessment Readiness

How the NCA ECC assessment helps organizations prepare for self-assessment, reporting, auditability, and ongoing compliance

The NCA ECC assessment should not stop at control review. It should help the organization become more ready for self-assessment, compliance tool reporting, field audit activity, and ongoing compliance management by improving scope clarity, evidence quality, ownership, and remediation follow-through.

Selected readiness view

Readiness area

Self-assessment readiness

Strengthen the scope, evidence, and ownership needed for a more credible internal review against applicable ECC requirements.

4 readiness views
Why this readiness area matters
Self-assessment matters because it only works when applicability, control relevance, evidence expectations, and ownership are clear enough to support an internal review that is credible.
What the assessment helps prepare
The assessment helps prepare scope, expected artifacts, responsible stakeholders, and the control areas where evidence or implementation is too weak for a reliable internal evaluation.
What becomes easier
Internal review becomes more structured, repeatable, and credible, with fewer surprises when the organization assesses itself against applicable ECC requirements.
NEXT STEP
See how Hala Cyber delivers the assessment from applicability review to remediation direction.

Selected readiness view

Readiness area

Compliance tool reporting readiness

Improve evidence structure, ownership visibility, and reporting support for periodic compliance measurement and reporting activity.

4 readiness views
Why this readiness area matters
Reporting readiness matters because periodic reporting becomes difficult when evidence is inconsistent, weakly structured, or spread across unclear owners and control areas.
What the assessment helps prepare
The assessment helps prepare what evidence should exist, where it should come from, who owns it, and where control findings or documentation weaknesses could undermine reporting quality.
What becomes easier
Periodic reporting becomes more supportable, more defensible, and less reactive because evidence expectations and weak points are clearer earlier.
NEXT STEP
See how Hala Cyber delivers the assessment from applicability review to remediation direction.

Selected readiness view

Readiness area

Field audit visit readiness

Improve explainability, evidence retrieval, and stakeholder readiness before formal review activity or field audit engagement begins.

4 readiness views
Why this readiness area matters
Field audit readiness matters because formal review activity often exposes gaps not only in controls, but in explainability, evidence retrieval, and stakeholder readiness.
What the assessment helps prepare
The assessment helps prepare where artifacts are incomplete, where remediation status is unclear, and where teams may struggle to explain how applicable controls are implemented in practice.
What becomes easier
Audit-facing discussions become more structured, evidence becomes easier to retrieve and explain, and the organization is better positioned to handle assurance-oriented review activity.
NEXT FOUNDATION
See how Hala Cyber delivers the assessment from applicability review to remediation direction.

Selected readiness view

Readiness area

Ongoing compliance management

Turn assessment findings into a more sustainable compliance model through clearer priorities, stronger evidence discipline, and follow-through.

4 readiness views
Why this readiness area matters
Ongoing compliance management matters because ECC is framed as a continuing compliance expectation, so the organization needs more than a one-time assessment snapshot.
What the assessment helps prepare
The assessment helps prepare a more sustainable operating model by clarifying priorities, exposing repeated evidence weaknesses, and supporting ownership and remediation follow-through after the review ends.
What becomes easier
The organization gains a stronger base for sustained compliance management, including prioritization, accountability, remediation tracking, and future review readiness.
NEXT STEP
See how Hala Cyber delivers the assessment from applicability review to remediation direction.
NCA ECC 2:2024 Structure

How NCA ECC 2:2024 is structured across domains, subdomains, controls, and subcontrols for assessment and compliance review

Understanding the ECC 2:2024 structure is important before an NCA ECC compliance assessment begins. The framework is organized into four main domains, 28 subdomains, 108 main controls, and 92 subcontrols, helping organizations determine applicability, review control requirements, organize evidence, and structure remediation across the framework.

Structure View

4

Main Domains

Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party and Cloud Computing Cybersecurity.

28

Subdomains

The four domains are further divided into 28 subdomains that organize the framework into practical thematic areas for implementation and review.

108

Main Controls

Across the 28 subdomains, ECC contains 108 main controls that set out the core cybersecurity requirements applicable under the framework.

92

Subcontrols

ECC also includes 92 subcontrols that provide more detailed control elements within the broader framework structure.

How the NCA ECC Assessment Works

Hala Cyber’s NCA ECC Assessment Methodology in Saudi Arabia, From Applicability Review and Evidence Analysis to Gap Mapping and Remediation Direction

Hala Cyber delivers the NCA ECC assessment through a structured methodology that starts with applicability and scope, moves into evidence and control review, and then converts findings into gap visibility and remediation direction. The sequence is designed to reduce mis-scoping, improve evidence quality, and produce a more defensible compliance position.

Assessment Methodology
STEP 01

Applicability

First Conversation >

Once scope is clearer, evidence must be defined before detailed review begins. Hala Cyber identifies the policies, records, technical outputs, logs, inventories, approvals, and stakeholder inputs needed to support the assessment so evidence expectations, ownership, and likely weak points are clearer before deeper testing starts.

What this step is designed to do
Define scope before deeper review begins.
Step 02

Evidence

First Conversation >
Once scope is clearer, evidence must be defined before detailed review begins. Hala Cyber identifies the policies, records, technical outputs, logs, inventories, approvals, and stakeholder inputs needed to support the assessment so evidence expectations, ownership, and likely weak points are clearer before deeper testing starts.
What this step is designed to do
Align evidence before testing begins.
Step 03

Control Review

First Conversation >
Control review becomes meaningful only after scope and evidence are sufficiently clear. Hala Cyber reviews governance, technical safeguards, resilience measures, and third-party and cloud controls to understand how they are designed, implemented, and operating, giving the organization a clearer view of which controls are working well, weakly evidenced, partially implemented, or materially exposed.
What this step is designed to do
Assess control implementation in practice.
Step 04

Gap Mapping

First Conversation >
Once the review is complete, findings need to be translated into structured assessment outcomes. Hala Cyber separates observations into applicability issues, control weaknesses, evidence weaknesses, ownership gaps, and other assessment findings so the engagement moves from raw observations into structured gap visibility that management and control owners can actually use.
What this step is designed to do
Convert findings into structured gaps.
Step 05

Roadmap

First Conversation >
Remediation direction should come after findings are structured, not before. Hala Cyber prioritises next actions, remediation direction, and ownership focus based on material gaps and readiness priorities so the client leaves with a more actionable path toward compliance improvement, management reporting, and ongoing readiness.
What this step is designed to do
Prioritise remediation and reporting next steps.
What You Receive

The assessment deliverables Hala Cyber provides across scope, evidence, findings, remediation, and reporting

The NCA ECC assessment engagement should produce more than observations. It should result in structured outputs that help define scope, document findings, organize evidence gaps, support remediation planning, and provide management with a clearer view of compliance readiness.

These deliverables help teams move from applicability and control review into usable artifacts for control owners, leadership, remediation planning, and more sustainable ongoing compliance management.

Assessment outputs that matter

Defined assessment perimeter

Evidence-backed control findings

Prioritised remediation direction

Management-ready reporting outputs

Assessment Deliverables

Deliverable 01

Assessment scope and applicability definition

A defined assessment perimeter showing likely applicability, in-scope domains, key dependencies, and the review boundaries used for the engagement.

Deliverable 02

ECC control findings register

A structured findings register showing assessed controls, evidence reviewed, observed gaps, and implementation issues across applicable ECC areas.

Deliverable 03

Evidence request and validation tracker

A practical tracker covering requested artifacts, evidence status, validation notes, and outstanding items needed to support a defensible review.

Deliverable 04

Control owner input and responsibility mapping

A mapped view of relevant stakeholders, control owners, and responsibility inputs gathered during the engagement to support follow-through and accountability.

Deliverable 05

Prioritised remediation register

A prioritised register of gaps, ownership, and recommended next actions to support remediation sequencing and closure planning.

Deliverable 06

Executive summary and readiness report

A management-ready summary of key findings, material risk themes, and readiness priorities for leadership review and decision-making.

Why Hala Cyber

Why organizations choose Hala Cyber for applicability-led NCA ECC assessments, evidence-backed findings, and management-ready remediation direction

Hala Cyber does not approach the NCA ECC assessment as a generic control checklist. The engagement is structured around applicability, evidence quality, implementation reality, and the practical outputs leadership and control owners need to move from review into remediation and ongoing compliance management in Saudi Arabia.

Assessment Experience

Oversight-heavy environments

Public sector operating context

Assessment experience shaped by environments where governance expectations, accountability, structured oversight, and evidence defensibility matter from the outset, helping the review start with stronger rigor and clearer ownership.

Continuity-critical operations

Private sector critical environments

Assessment context informed by sectors where critical service continuity, operational dependence, resilience pressure, and third-party exposure make ECC assessment a practical readiness issue, not a theoretical compliance exercise.

Hosted dependency models

Cloud and technology-heavy models

Assessment experience across hosted infrastructure, cloud computing, distributed delivery models, and provider-dependent environments where scope, accountability, evidence access, and control defensibility all become harder to manage.

Assessment delivery experience

A methodology built for scope clarity, evidence defensibility, and actionable remediation

Hala Cyber brings together applicability review, evidence analysis, control evaluation, structured gap mapping, executive reporting, and remediation direction so the engagement produces usable outputs, clearer priorities, and a more defensible compliance position.

Applicability-led scoping before deep control testing begins

Evidence-led review across governance, defense, resilience, and third-party and cloud controls

Tangible outputs for control owners, management reporting, and remediation planning

Saudi-focused assessment delivery aligned to ongoing compliance expectations

Get Started

Start with a focused NCA ECC assessment discussion that helps define scope, evidence priorities, and the right next steps

The first discussion is designed to help narrow whether ECC is likely binding, where the assessment should begin, what evidence posture already exists, and which control areas or dependencies may need attention first. This helps the engagement start with clearer direction and less avoidable rework.

First Conversation

Book a focused NCA ECC scoping discussion

Bring your sector context, operating model, cloud or outsourcing footprint, current ECC stage, and main concerns so the discussion can quickly narrow applicability, scope, and likely assessment priorities.

Frequently Asked Questions

Practical answers to the questions organizations usually ask before starting an NCA ECC assessment

These FAQs answer the practical questions organizations usually ask before starting an NCA ECC assessment, including where ECC applies, how the engagement works, what evidence is needed, what the review covers, and how the assessment supports reporting, auditability, and ongoing compliance readiness.

Assessment Focus Areas
What is NCA ECC 2:2024?
NCA ECC 2:2024 is the Essential Cybersecurity Controls framework issued by the National Cybersecurity Authority. It sets the minimum cybersecurity requirements for entities that fall within its scope in Saudi Arabia.
How is ECC 2:2024 structured?
The document states that ECC consists of 4 cybersecurity main domains, 28 cybersecurity subdomains, 108 cybersecurity main controls, and 92 cybersecurity subcontrols.
What are the 4 main ECC domains?
The four main domains are Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party and Cloud Computing Cybersecurity.
What does the NCA ECC assessment engagement usually cover?
The engagement usually covers applicability, scope, evidence review, control assessment, gap identification, remediation direction, and management-ready outputs. The exact scope depends on the operating model, sector context, cloud use, third-party reliance, and current level of readiness.
Do we need to know with certainty whether ECC applies before speaking with Hala Cyber?
No. Applicability is often one of the first issues that needs to be clarified. An early discussion can help determine whether ECC is likely binding, which environments or services may be in scope, and where the assessment should focus first.
How much effort is usually required from our internal team during the assessment?
The engagement usually requires structured participation from relevant control owners and stakeholders, but the effort is easier to manage when scope, evidence expectations, and priorities are defined early. The goal is to keep requests focused on the most relevant control areas, records, and interviews.
What if our documentation or evidence is incomplete?
That is a common starting point. The assessment helps identify where evidence is missing, weak, inconsistent, or not yet structured in a way that supports a defensible control position. Incomplete evidence does not prevent the engagement, it usually becomes one of the areas the review helps clarify.
Will the assessment only identify gaps, or will it also help with next steps?
The engagement is intended to do more than identify observations. It helps translate findings into clearer remediation direction, priority actions, ownership conversations, and management-ready outputs that can support follow-on planning and compliance improvement.
What if we are still early in our ECC readiness journey?
The assessment can still be useful at an early stage. In many cases, organizations need help first with applicability, control interpretation, evidence expectations, and current-state visibility before they can move into structured remediation or broader readiness planning.
What do we usually receive at the end of the engagement?
The engagement is typically designed to produce a clearer assessment perimeter, evidence-backed findings, structured gap visibility, remediation direction, and management-ready outputs that support planning, reporting, and ongoing compliance improvement.
Who must comply with NCA ECC in Saudi Arabia?
ECC applies to government agencies in the Kingdom of Saudi Arabia, including ministries, authorities, establishments and others, and their affiliated companies and entities inside and outside the Kingdom, as well as private sector entities owning, operating, or hosting Critical National Infrastructures.
Is NCA ECC mandatory for all private companies?
The framework text specifically applies to private sector entities owning, operating, or hosting Critical National Infrastructures. It also says the NCA strongly encourages all other entities in the Kingdom to leverage the controls as best practice.
What does the ECC Statement of Applicability mean?
The document says the controls were developed to fulfill the cybersecurity needs of all entities and sectors in the Kingdom, taking into account the diverse nature of their businesses, and that each entity shall comply with all controls applicable thereto.
Does ECC apply if we use cloud computing or hosting services?
Yes. The framework gives controls under subdomain 4.2, Cloud Computing and Hosting Cybersecurity, as an example of controls that are applicable and binding on entities currently using or planning to use cloud computing and hosting services.
Can organizations outside strict ECC scope still use the framework?
Yes. The NCA strongly encourages all other entities in the Kingdom to leverage the controls to implement best practices to improve and enhance their cybersecurity.
Does ECC apply to affiliated entities outside Saudi Arabia?
The framework text states that government agencies and their affiliated companies and entities inside and outside the Kingdom fall within scope, which is why affiliated operating models often need careful applicability review.
Can only part of an organization fall within ECC scope?
In practice, applicability often needs to be reviewed against the entity’s services, operating environment, critical functions, and technology use. That is why scope definition is usually an early assessment step.
Does planned future cloud use affect ECC applicability?
Yes. The framework text says relevant cloud computing and hosting controls are applicable and binding on entities currently using or planning to use those services, which can affect scope even before migration is complete.
If we outsource key services, does that change ECC applicability?
Outsourcing and third-party dependence do not remove ECC obligations. They usually increase the need to assess third-party and cloud-related controls, contractual safeguards, and supporting evidence.
Why is applicability review such an important early step in the assessment?
Applicability determines whether ECC is binding, which control areas should be reviewed, how evidence requests are framed, and whether the final compliance position can be defended. Poor applicability decisions often lead to mis-scoping and rework later.
What does the Governance domain include?
In assessment terms, the Governance domain covers strategy, management structure, policies and procedures, roles and responsibilities, risk management, compliance, review and audit, HR-related controls, and awareness and training expectations.
Does ECC require a cybersecurity department?
Yes. Under Cybersecurity Management, the framework states that a department for cybersecurity shall be established within the entity and that it shall be independent from the Information Technology and Communications Department.
Does ECC require a cybersecurity supervisory committee?
Yes. The framework states that a cybersecurity supervisory committee shall be established pursuant to the instruction of the entity’s Authorized Official to ensure compliance with, support for, and monitoring of the implementation of cybersecurity programs and regulations.
Does ECC require documented cybersecurity policies and procedures?
Yes. The framework states that the cybersecurity department shall identify and document cybersecurity policies and procedures, including cybersecurity controls and requirements, have them approved by the entity’s Authorized Official, and communicate them to relevant personnel and parties inside the entity.
When does ECC expect cybersecurity risk assessment procedures to be applied?
The framework states that cybersecurity risk assessment procedures shall be implemented at least at the early stage of technology projects, before major changes to technology infrastructure, during planning to obtain third-party services, and during planning and before release of new technology services and products.
Does ECC require defined cybersecurity roles and responsibilities?
Yes. The Governance domain requires the entity’s cybersecurity governance structure, roles, responsibilities, and assignment of accountable persons to be identified, documented, and approved.
Does ECC require periodic cybersecurity review and audit?
Yes. The Governance domain includes a dedicated subdomain on periodical review and audit of cybersecurity, and the framework requires results to be documented and presented to the cybersecurity supervisory committee and the Authorized Official.
Does ECC address cybersecurity in HR processes?
Yes. The Governance domain includes Cybersecurity in Human Resources and covers requirements before employment, during employment, and upon employment end or termination.
Does ECC require cybersecurity awareness and training?
Yes. The framework includes a dedicated awareness and training subdomain and requires a cybersecurity awareness program as well as specialized training for relevant roles.
Why does governance matter so much in an ECC assessment?
Governance is what links strategy, accountability, policy control, review, and management oversight. Weak governance often causes evidence gaps, inconsistent ownership, and remediation delay even where technical controls exist.
What does the Cybersecurity Defense domain cover at a high level?
In assessment terms, the Defense domain covers the operational and technical safeguards reviewed across asset management, access control, systems protection, email security, network security, mobile security, data protection, cryptography, backup and recovery, vulnerability management, penetration testing, logging and monitoring, incident and threat management, physical security, and web application security.
What is the objective of Asset Management under ECC?
The objective is to ensure that the entity has an accurate and updated inventory of assets, including details of all information and technology assets, to support operations and cybersecurity requirements.
Does ECC require acceptable use policies for information and technology assets?
Yes. Under Asset Management, the framework states that the policy of acceptable use of information and technology assets of the entity shall be identified, documented, approved, and communicated.
What does ECC say about incident and threat management?
The framework requires timely identification, detection, and effective management of cybersecurity incidents and proactive response to threats, including incident response plans, escalation procedures, incident classification, reporting incidents to the NCA, sharing notifications and threat intelligence with the NCA, and collecting and handling threat intelligence feeds.
Does ECC include physical security and web application security requirements?
Yes. The Defense domain includes both Physical Security and Web Application Security as dedicated subdomains.
Does ECC require multi-factor authentication?
Yes. Under Identity and Access Management, the framework requires multi-factor authentication for remote access and for privileged accounts, with appropriate authentication factors and techniques based on risk and impact assessment.
Does ECC specify how long cybersecurity event logs should be retained?
Yes. Under Event Logs and Monitoring Management, the framework states that the retention period of cybersecurity event logs shall be at least 12 months.
Does ECC require periodic vulnerability assessment and remediation?
Yes. Under Vulnerability Management, the framework requires periodic vulnerability assessment and detection, classification of vulnerabilities, and remediation based on severity and associated cyber risk.
Does ECC require periodic penetration testing?
Yes. Under Penetration Testing, the framework states that penetration tests should be conducted periodically and that scope should include externally provided services and their technical components.
Why does the Defense domain usually take so much assessment effort?
Defense often requires the broadest evidence set because it spans operational and technical controls across assets, access, infrastructure, applications, monitoring, incident response, resilience-supporting safeguards, and physical environments.
What does the Cybersecurity Resilience domain include?
In assessment terms, the Resilience domain covers the cybersecurity aspects of business continuity management and how the organization supports continuity and recovery during cyber disruption.
What is the objective of the Cybersecurity Resilience BCM subdomain?
The objective is to ensure the inclusion of cybersecurity resilience requirements in the entity’s business continuity management and to remediate and minimize the impacts of disruptions on critical e-services and information processing systems and facilities caused by cyber risks.
Does ECC require cybersecurity requirements for business continuity management to be documented and approved?
Yes. The framework states that cybersecurity requirements for business continuity management within the entity shall be identified, documented, and approved.
What minimum items does ECC include for cybersecurity resilience in BCM?
The framework lists, at minimum, ensuring continuity of cybersecurity systems and procedures, developing plans for response to cybersecurity incidents that may affect business continuity, and developing disaster recovery plans.
Does ECC require resilience controls to be periodically reviewed?
Yes. The framework states that cybersecurity requirements for business continuity management within the entity shall be periodically reviewed.
Does ECC connect cyber incidents to business continuity planning?
Yes. The framework explicitly requires plans for response to cybersecurity incidents that may affect business continuity, which connects operational cyber events directly to continuity management.
Does ECC require disaster recovery planning as part of resilience?
Yes. Disaster recovery plans are listed as one of the minimum cybersecurity requirements for business continuity management within the Resilience domain.
Why is resilience different from general technical defense controls?
Defense focuses on preventing, detecting, and managing threats across operational controls, while Resilience focuses on continuity, response, and recovery when disruption still occurs.
What usually gets reviewed in resilience evidence?
Typical resilience evidence includes continuity-related cybersecurity requirements, incident response alignment, recovery planning, governance approvals, review cycles, and the extent to which continuity arrangements are actually maintained and usable.
Why do organizations sometimes underestimate the resilience domain?
Because it is smaller in structure than the Defense domain, organizations sometimes assume it is lighter. In practice, it can be important because it connects cyber disruption to critical service continuity, recovery readiness, and executive exposure.
What is the objective of Third-Party Cybersecurity under ECC?
The objective is to ensure protection of the entity’s assets against third-party cybersecurity risks, including information technology outsourcing, cybersecurity outsourcing, and managed services, in line with the entity’s policies and relevant legislative and regulatory requirements.
What does ECC require in third-party contracts and agreements?
The framework states that cybersecurity requirements for contracts and agreements with third parties shall be identified, documented, and approved, and that contracts affecting the entity’s data or services shall include at minimum non-disclosure clauses, secure removal of the entity’s data upon service end, communication procedures in case of cybersecurity incidents, and obligations to apply the entity’s cybersecurity requirements and relevant legislative and regulatory requirements.
What is the objective of Cloud Computing and Hosting Cybersecurity?
The objective is to ensure proper and efficient remediation of cyber risks and implementation of cybersecurity requirements for cloud computing and hosting, and to ensure protection of the entity’s information and technology assets on cloud services hosted, processed, or managed by third parties.
Does NCA require ongoing and continuous ECC compliance?
Yes. The document states that all entities within the scope of the controls shall take all necessary measures to ensure ongoing and continuous compliance with the controls.
How does NCA evaluate ECC compliance?
The framework states that NCA may evaluate ECC compliance through multiple means, including self-assessment, periodic reports through the compliance tool, and field auditing visits.
What is the ECC 2:2024 Assessment and Compliance Tool?
The document says NCA will issue a tool, ECC 2:2024 Assessment and Compliance Tool, to organize the process of assessment and measurement of compliance by entities in applying the ECC.
Does ECC require cybersecurity requirements for third-party agreements to be documented and approved?
Yes. The framework explicitly states that cybersecurity requirements for the entity’s contracts and agreements with third parties shall be identified, documented, and approved.
Does ECC require incident communication procedures with third parties?
Yes. The framework requires contracts affecting the entity’s data or services to include communication procedures in case of cybersecurity incidents.
Does ECC require managed cybersecurity service centers with remote access to be located in Saudi Arabia?
Yes. Under Third-Party Cybersecurity, the framework states that cybersecurity managed service centers for monitoring and operations which use remote access shall be fully located in the Kingdom of Saudi Arabia.
Does ECC require separation of our environment from other customers in cloud services?
Yes. Under Cloud Computing and Hosting Cybersecurity, the framework requires separation of the entity’s environment, especially virtual servers, from environments of other entities within the cloud service provider.
Start the Conversation

Ready to narrow ECC applicability, scope, and the right next steps?

Scroll to Top