Compliance — NCA ECC-2:2024
NCA ECC-2:2024 — evidence for every domain of the updated Essential Cybersecurity Controls
Automated coverage across Governance, Defence, Resilience, Third-Party & Cloud, and Industrial Control Systems — with bilingual assessor packages for KSA government and CNI submissions.
5
ECC-2:2024 domains with primary or supporting coverage
ECC-2
Aligned with the 2024 revision, not the 2018 baseline
OT + IT
ICS coverage for CNI operators in Domain 5
AR + EN
Bilingual assessor evidence for NCA submissions
ECC-2:2024 coverage across the five-domain model
The 2024 revision of the Essential Cybersecurity Controls elevates third-party and cloud cybersecurity into a dedicated domain, promotes ICS to a top-level domain, and strengthens monitoring expectations. ManySignal delivers the operational and third-party evidence — with the governance and resilience artefacts assessors expect to be data-driven.
Domain 1 — Cybersecurity Governance
Policy attestation, role assignment, awareness records, and cyber-risk register evidence aligned with ECC-2:2024 Domain 1 — sourced from platform activity rather than one-off attestation.
Domain 2 — Cybersecurity Defence
Asset management, identity and access, information protection, cryptography, vulnerability management, event log correlation, and incident response — the operational spine of ECC-2:2024 Domain 2 delivered as an agentic SOC.
Domain 3 — Cybersecurity Resilience
Cybersecurity aspects of business continuity — backup integrity monitoring, ransomware recovery instrumentation, and BC test evidence — mapped to Domain 3 sub-controls.
Domain 4 — Third-Party & Cloud Cybersecurity
The new-and-strengthened ECC-2:2024 domain covering third-party assurance, cloud tenancy controls, and outsourced-service monitoring — with continuous telemetry rather than annual questionnaires.
Domain 5 — Industrial Control Systems
OT and ICS monitoring with unidirectional collection, protocol-aware detection, and IT/OT boundary control evidence aligned with ECC-2:2024 Domain 5 for CNI operators.
NCA submission-ready evidence
Assessor artefacts, control mapping, and maturity scoring generate in the NCA-expected structure — with bilingual descriptions for entities submitting through the Haseen portal.
ECC-1:2018 vs ECC-2:2024 — key deltas
| ECC-1:2018 baseline | ECC-2:2024 revision |
|---|---|
| ECC-1:2018 — Third-party controls scattered across defence and resilience domains | ECC-2:2024 — Dedicated Third-Party and Cloud Cybersecurity domain with expanded sub-controls |
| ECC-1:2018 — ICS treated as an appendix or optional set for CNI operators | ECC-2:2024 — Industrial Control Systems as its own top-level domain with unified sub-controls |
| ECC-1:2018 — Cryptography requirements referenced NCA cryptographic standard baseline | ECC-2:2024 — Updated cryptography requirements aligned with current NCA cryptographic guidance |
| ECC-1:2018 — Cloud coverage limited to references in third-party and defence controls | ECC-2:2024 — Explicit cloud-tenancy, data-residency, and shared-responsibility sub-controls |
| ECC-1:2018 — Event logging and monitoring at Domain 2 baseline | ECC-2:2024 — Strengthened event correlation, retention, and 24x7 monitoring expectations |
| ECC-1:2018 — Vulnerability management as periodic scan cadence | ECC-2:2024 — Risk-based and continuous vulnerability posture management |
ECC-2:2024 domain reference
- Domain 1 — Cybersecurity Governance: strategy, roles, risk, awareness, audit
- Domain 2 — Cybersecurity Defence: asset, identity, access, crypto, vuln, monitoring, IR
- Domain 3 — Cybersecurity Resilience: cyber aspects of business continuity
- Domain 4 — Third-Party and Cloud: vendor assurance, cloud tenancy, outsourced services
- Domain 5 — Industrial Control Systems: OT, ICS, IT/OT boundary for CNI
- Mandatory for government entities and CNI operators in KSA
- Enforced by the National Cybersecurity Authority through supervisory review
- Assessment via the NCA Haseen portal for in-scope entities
NCA ECC-2:2024 — buyer questions
What is the NCA ECC-2:2024?
ECC-2:2024 is the second revision of the Essential Cybersecurity Controls issued by the National Cybersecurity Authority (NCA) of the Kingdom of Saudi Arabia, replacing ECC-1:2018. It is mandatory for government entities, semi-government entities, and Critical National Infrastructure operators in KSA. The revision strengthens third-party and cloud cybersecurity, introduces Industrial Control Systems as a top-level domain, and updates cryptographic and monitoring requirements to reflect current NCA guidance.
Which entities must comply with NCA ECC-2:2024?
Government and semi-government entities in KSA, and organisations designated as Critical National Infrastructure by the NCA. Private-sector entities may also adopt ECC as good practice or where required by sector regulators. SAMA-regulated financial institutions follow the SAMA Cyber Security Framework instead — though NCA ECC alignment is common where entities operate in both scopes.
What are the five domains of ECC-2:2024?
Domain 1 — Cybersecurity Governance (strategy, policies, roles, risk management, awareness, audit). Domain 2 — Cybersecurity Defence (asset management, identity, access control, cryptography, vulnerability management, event monitoring, incident response). Domain 3 — Cybersecurity Resilience (cyber aspects of business continuity). Domain 4 — Third-Party and Cloud Cybersecurity (vendor assurance, cloud tenancy, outsourced services). Domain 5 — Industrial Control Systems Cybersecurity (OT and ICS controls for CNI operators).
What changed between ECC-1:2018 and ECC-2:2024?
The most material changes are the elevation of Third-Party and Cloud Cybersecurity into a dedicated domain (previously scattered across defence and outsourcing controls), the promotion of Industrial Control Systems from an appendix to a full domain with unified sub-controls, updated cryptographic requirements aligned with current NCA cryptographic guidance, strengthened event correlation and retention expectations, and a shift from periodic-scan vulnerability management toward continuous risk-based posture. Governance controls are largely stable but with sharper evidence expectations.
How does ManySignal accelerate ECC-2:2024 compliance?
ManySignal delivers the operational spine of Domain 2 (Defence) — event correlation, incident response, vulnerability posture, cryptographic monitoring — plus Domain 4 (Third-Party and Cloud) monitoring evidence from telemetry rather than questionnaires. Domain 3 (Resilience) is supported through backup and ransomware recovery instrumentation. Domain 5 (ICS) is covered where OT telemetry is integrated. Domain 1 (Governance) is supported through activity-based attestation records. Evidence exports render in the NCA-expected structure with bilingual descriptions.
Prepare your NCA ECC-2:2024 submission with continuous evidence
Book a working session with our KSA compliance team to walk through your current ECC posture, the 2024 revision deltas, and the ManySignal evidence package that supports your NCA submission.