M ManySignal

Compliance — NCA ECC (Saudi Arabia)

Saudi NCA Essential Cybersecurity Controls — ECC-1-4-3 through ECC-2-6

The National Cybersecurity Authority's ECC is mandatory for Saudi government entities and critical infrastructure operators. ManySignal maps to NCA ECC's Security Operations, Incident Management, and Audit domains — with in-Kingdom data residency options and Arabic-language compliance documentation.

NCA ECC domain coverage

ECC-1-4-2 — Identity and Access Management

Access control monitoring, privileged access anomaly detection, and deprovisioning verification

ECC-1-4-3 — Cybersecurity Operations

24x7 SOC monitoring, automated threat detection, and incident response evidence

ECC-1-4-4 — Incident Management

Automated incident classification, evidence collection, and NCA notification workflow

ECC-2-6 — Audit Logs and Monitoring

Centralised log collection, tamper-evident storage, and continuous automated log review

ECC-3-1 — Third-Party Cybersecurity

Vendor and supplier access monitoring — anomalous third-party credential usage detection

ECC-3-3 — Information Asset Management

Asset discovery and classification evidence via entity graph

NCA ECC compliance — common questions

What is the NCA Essential Cybersecurity Controls (ECC) framework?

The Saudi National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC-1:2018, updated 2020) is mandatory for all government entities, critical national infrastructure operators, and regulated private sector organisations in Saudi Arabia. The ECC comprises 5 main domains, 29 cybersecurity controls, and 114 cybersecurity sub-controls. Compliance is assessed by NCA-authorised assessors.

Which ECC domains does ManySignal address most directly?

ManySignal primarily addresses ECC Domain 1 (Cybersecurity Governance), Domain 4 (Cybersecurity Defence), and Domain 5 (Cybersecurity Resilience). Within Domain 4, ManySignal covers: ECC-1-4-3 (Security Operations), ECC-1-4-4 (Incident Management), ECC-2-6 (Audit and Logging), and ECC-1-4-2 (Identity and Access Management monitoring). Evidence packages are formatted for NCA assessment.

Does ManySignal support in-Kingdom data residency for Saudi NCA compliance?

Yes. ManySignal supports in-Kingdom deployment for organisations with NCA data localisation requirements — via stc cloud, Alibaba Cloud KSA, or customer-owned data centre infrastructure. For organisations where AWS Bahrain is acceptable, ManySignal's ME-SOUTH-1 deployment provides the lowest-latency cloud option. NCA assessors have accepted both deployment models.

How does ManySignal support SAMA CSF alongside NCA ECC for Saudi financial institutions?

Saudi financial institutions regulated by SAMA must comply with both SAMA CSF and NCA ECC — which have overlapping but distinct requirements. ManySignal's compliance mapping covers both frameworks simultaneously, with evidence export providing separate SAMA-formatted and NCA-formatted compliance evidence from the same monitoring data. See /compliance/sama-csf for the SAMA-specific mapping.

Does ManySignal provide Arabic-language compliance documentation for NCA assessments?

Yes. ManySignal's compliance evidence packages and incident reports can be generated in Arabic for NCA assessment submissions. Our KSA team — based in Riyadh — provides Arabic-language support throughout the NCA compliance process, including assessor engagement support and evidence preparation.

Deploy NCA ECC-compliant monitoring in KSA

Talk to our Riyadh team about in-Kingdom data deployment, NCA assessor-ready evidence packaging, and Arabic-language compliance documentation.