ManySignal

Compliance — NCA ECC-2:2024

NCA ECC-2:2024 — evidence for every domain of the updated Essential Cybersecurity Controls

Automated coverage across Governance, Defence, Resilience, Third-Party & Cloud, and Industrial Control Systems — with bilingual assessor packages for KSA government and CNI submissions.

5

ECC-2:2024 domains with primary or supporting coverage

ECC-2

Aligned with the 2024 revision, not the 2018 baseline

OT + IT

ICS coverage for CNI operators in Domain 5

AR + EN

Bilingual assessor evidence for NCA submissions

Domain coverage

ECC-2:2024 coverage across the five-domain model

The 2024 revision of the Essential Cybersecurity Controls elevates third-party and cloud cybersecurity into a dedicated domain, promotes ICS to a top-level domain, and strengthens monitoring expectations. ManySignal delivers the operational and third-party evidence — with the governance and resilience artefacts assessors expect to be data-driven.

Domain 1 — Cybersecurity Governance

Policy attestation, role assignment, awareness records, and cyber-risk register evidence aligned with ECC-2:2024 Domain 1 — sourced from platform activity rather than one-off attestation.

Domain 2 — Cybersecurity Defence

Asset management, identity and access, information protection, cryptography, vulnerability management, event log correlation, and incident response — the operational spine of ECC-2:2024 Domain 2 delivered as an agentic SOC.

Domain 3 — Cybersecurity Resilience

Cybersecurity aspects of business continuity — backup integrity monitoring, ransomware recovery instrumentation, and BC test evidence — mapped to Domain 3 sub-controls.

Domain 4 — Third-Party & Cloud Cybersecurity

The new-and-strengthened ECC-2:2024 domain covering third-party assurance, cloud tenancy controls, and outsourced-service monitoring — with continuous telemetry rather than annual questionnaires.

Domain 5 — Industrial Control Systems

OT and ICS monitoring with unidirectional collection, protocol-aware detection, and IT/OT boundary control evidence aligned with ECC-2:2024 Domain 5 for CNI operators.

NCA submission-ready evidence

Assessor artefacts, control mapping, and maturity scoring generate in the NCA-expected structure — with bilingual descriptions for entities submitting through the Haseen portal.

ECC-1:2018 vs ECC-2:2024 — key deltas

ECC-1:2018 baseline ECC-2:2024 revision
ECC-1:2018 — Third-party controls scattered across defence and resilience domains ECC-2:2024 — Dedicated Third-Party and Cloud Cybersecurity domain with expanded sub-controls
ECC-1:2018 — ICS treated as an appendix or optional set for CNI operators ECC-2:2024 — Industrial Control Systems as its own top-level domain with unified sub-controls
ECC-1:2018 — Cryptography requirements referenced NCA cryptographic standard baseline ECC-2:2024 — Updated cryptography requirements aligned with current NCA cryptographic guidance
ECC-1:2018 — Cloud coverage limited to references in third-party and defence controls ECC-2:2024 — Explicit cloud-tenancy, data-residency, and shared-responsibility sub-controls
ECC-1:2018 — Event logging and monitoring at Domain 2 baseline ECC-2:2024 — Strengthened event correlation, retention, and 24x7 monitoring expectations
ECC-1:2018 — Vulnerability management as periodic scan cadence ECC-2:2024 — Risk-based and continuous vulnerability posture management

ECC-2:2024 domain reference

  • Domain 1 — Cybersecurity Governance: strategy, roles, risk, awareness, audit
  • Domain 2 — Cybersecurity Defence: asset, identity, access, crypto, vuln, monitoring, IR
  • Domain 3 — Cybersecurity Resilience: cyber aspects of business continuity
  • Domain 4 — Third-Party and Cloud: vendor assurance, cloud tenancy, outsourced services
  • Domain 5 — Industrial Control Systems: OT, ICS, IT/OT boundary for CNI
  • Mandatory for government entities and CNI operators in KSA
  • Enforced by the National Cybersecurity Authority through supervisory review
  • Assessment via the NCA Haseen portal for in-scope entities

NCA ECC-2:2024 — buyer questions

What is the NCA ECC-2:2024?

ECC-2:2024 is the second revision of the Essential Cybersecurity Controls issued by the National Cybersecurity Authority (NCA) of the Kingdom of Saudi Arabia, replacing ECC-1:2018. It is mandatory for government entities, semi-government entities, and Critical National Infrastructure operators in KSA. The revision strengthens third-party and cloud cybersecurity, introduces Industrial Control Systems as a top-level domain, and updates cryptographic and monitoring requirements to reflect current NCA guidance.

Which entities must comply with NCA ECC-2:2024?

Government and semi-government entities in KSA, and organisations designated as Critical National Infrastructure by the NCA. Private-sector entities may also adopt ECC as good practice or where required by sector regulators. SAMA-regulated financial institutions follow the SAMA Cyber Security Framework instead — though NCA ECC alignment is common where entities operate in both scopes.

What are the five domains of ECC-2:2024?

Domain 1 — Cybersecurity Governance (strategy, policies, roles, risk management, awareness, audit). Domain 2 — Cybersecurity Defence (asset management, identity, access control, cryptography, vulnerability management, event monitoring, incident response). Domain 3 — Cybersecurity Resilience (cyber aspects of business continuity). Domain 4 — Third-Party and Cloud Cybersecurity (vendor assurance, cloud tenancy, outsourced services). Domain 5 — Industrial Control Systems Cybersecurity (OT and ICS controls for CNI operators).

What changed between ECC-1:2018 and ECC-2:2024?

The most material changes are the elevation of Third-Party and Cloud Cybersecurity into a dedicated domain (previously scattered across defence and outsourcing controls), the promotion of Industrial Control Systems from an appendix to a full domain with unified sub-controls, updated cryptographic requirements aligned with current NCA cryptographic guidance, strengthened event correlation and retention expectations, and a shift from periodic-scan vulnerability management toward continuous risk-based posture. Governance controls are largely stable but with sharper evidence expectations.

How does ManySignal accelerate ECC-2:2024 compliance?

ManySignal delivers the operational spine of Domain 2 (Defence) — event correlation, incident response, vulnerability posture, cryptographic monitoring — plus Domain 4 (Third-Party and Cloud) monitoring evidence from telemetry rather than questionnaires. Domain 3 (Resilience) is supported through backup and ransomware recovery instrumentation. Domain 5 (ICS) is covered where OT telemetry is integrated. Domain 1 (Governance) is supported through activity-based attestation records. Evidence exports render in the NCA-expected structure with bilingual descriptions.

Prepare your NCA ECC-2:2024 submission with continuous evidence

Book a working session with our KSA compliance team to walk through your current ECC posture, the 2024 revision deltas, and the ManySignal evidence package that supports your NCA submission.