Skip to content

Gulf — Saudi Arabia

NCA Essential Cybersecurity Controls (ECC) Assessment

Compliance assessment against the National Cybersecurity Authority's Essential Cybersecurity Controls — the baseline cyber security requirement for government entities and organisations operating critical national infrastructure in Saudi Arabia.

Who it applies to

The NCA's Essential Cybersecurity Controls set a minimum cyber security baseline in the Kingdom. Scope extends to government entities and their contractors, and to private sector organisations that own, operate or host critical national infrastructure. Many organisations discover they are in scope through a contractual requirement flowed down from a government client rather than through direct notification.

The NCA publishes several control sets beyond the ECC, addressing areas such as critical systems, cloud, telework and operational technology. Which apply to you depends on your sector and the systems you operate. Confirming applicability precisely — and the current revision of each applicable control set — is the first step of any engagement, and we do it before scoping the assessment.

Structure of the assessment

The ECC is organised into main domains covering cyber security governance, cyber security defence, cyber security resilience, third-party and cloud computing cyber security, and industrial control systems where applicable. Each domain breaks down into subdomains and individual controls.

Assessment is compliance-based rather than maturity-scored: each control is assessed as implemented, partially implemented or not implemented, with evidence. Partial implementation must be described specifically — "partially compliant" without stating which element is missing is not a usable finding.

Overlap is an opportunity

ISO 27001 SAMA CSF NCA ECC Shared evidence Assess once, reportseparately Usually the largest savingavailable on a multi-frameworkengagement.
Where several frameworks apply, collect evidence once and report separately.

What we typically find

  • Governance controls documented but without evidence of the periodic review the control requires.
  • Third-party cyber security requirements present in contracts but never monitored in operation.
  • Cloud service usage that predates the cloud control requirements and was never brought into scope.
  • Asset inventories that are incomplete, which undermines every control that depends on knowing what you have.
  • Logging deployed without the retention period or monitoring coverage the controls specify.
  • Cyber security resilience requirements treated as an IT disaster recovery matter rather than a tested capability.

How the engagement runs

  1. 1

    Applicability determination

    Establish which NCA control sets and which current revisions apply to your organisation.

  2. 2

    Scope definition

    Define the systems, sites and services in scope, including cloud and third-party hosted components.

  3. 3

    Evidence collection

    Gather documentation, configuration evidence and operational records against each control.

  4. 4

    Control assessment

    Assess each control as implemented, partially implemented or not implemented, with specifics.

  5. 5

    Gap remediation planning

    Sequence remediation by risk and by the effort required to close.

  6. 6

    Reporting

    Report in the framework's own domain structure for direct submission use.

What you receive

Applicability determination across the relevant NCA control sets
Control-by-control compliance assessment with evidence references
Specific description of what is missing for every partially implemented control
Prioritised remediation roadmap
Reporting structured to the framework domains
Reassessment of remediated controls at an agreed interval

Frequently asked questions

If you are a government entity, work as a government contractor, or own or operate critical national infrastructure in the Kingdom, you should assume it does and confirm the specifics. Many private organisations come into scope through contract terms flowed down from a public sector client. We determine applicability formally at the start of the engagement rather than assuming it.

For a financial institution that is in scope for both, yes — and it should be, because the control overlap is substantial. We map the two control sets so a single evidence collection exercise serves both assessments, then report separately in each framework's own structure.

Compliance is assessed and reported rather than certified in the way ISO 27001 is. What entities need is a defensible, evidenced compliance position they can report to the authority and to the government clients who ask for it.

Related services

Not sure this is the framework that binds you?

Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.

Request a proposal
Top