Gulf — Saudi Arabia
NCA Essential Cybersecurity Controls (ECC) Assessment
Compliance assessment against the National Cybersecurity Authority's Essential Cybersecurity Controls — the baseline cyber security requirement for government entities and organisations operating critical national infrastructure in Saudi Arabia.
Who it applies to
The NCA's Essential Cybersecurity Controls set a minimum cyber security baseline in the Kingdom. Scope extends to government entities and their contractors, and to private sector organisations that own, operate or host critical national infrastructure. Many organisations discover they are in scope through a contractual requirement flowed down from a government client rather than through direct notification.
The NCA publishes several control sets beyond the ECC, addressing areas such as critical systems, cloud, telework and operational technology. Which apply to you depends on your sector and the systems you operate. Confirming applicability precisely — and the current revision of each applicable control set — is the first step of any engagement, and we do it before scoping the assessment.
Structure of the assessment
The ECC is organised into main domains covering cyber security governance, cyber security defence, cyber security resilience, third-party and cloud computing cyber security, and industrial control systems where applicable. Each domain breaks down into subdomains and individual controls.
Assessment is compliance-based rather than maturity-scored: each control is assessed as implemented, partially implemented or not implemented, with evidence. Partial implementation must be described specifically — "partially compliant" without stating which element is missing is not a usable finding.
Overlap is an opportunity
What we typically find
- Governance controls documented but without evidence of the periodic review the control requires.
- Third-party cyber security requirements present in contracts but never monitored in operation.
- Cloud service usage that predates the cloud control requirements and was never brought into scope.
- Asset inventories that are incomplete, which undermines every control that depends on knowing what you have.
- Logging deployed without the retention period or monitoring coverage the controls specify.
- Cyber security resilience requirements treated as an IT disaster recovery matter rather than a tested capability.
How the engagement runs
-
1
Applicability determination
Establish which NCA control sets and which current revisions apply to your organisation.
-
2
Scope definition
Define the systems, sites and services in scope, including cloud and third-party hosted components.
-
3
Evidence collection
Gather documentation, configuration evidence and operational records against each control.
-
4
Control assessment
Assess each control as implemented, partially implemented or not implemented, with specifics.
-
5
Gap remediation planning
Sequence remediation by risk and by the effort required to close.
-
6
Reporting
Report in the framework's own domain structure for direct submission use.
What you receive
Frequently asked questions
Related services
Not sure this is the framework that binds you?
Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.
Request a proposal