M ManySignal

Guide · ManySignal

Saudi NCA ECC Implementation Guide

Saudi Arabia's National Cybersecurity Authority Essential Cybersecurity Controls (NCA ECC) are mandatory for government entities and critical infrastructure operators in the Kingdom. The ECC 1-1:2020 framework includes specific controls for cybersecurity event logging, monitoring, and incident management. This guide covers the ECC controls relevant to security operations and ManySignal's alignment to them.

MH Marcus Hale — Head of Detection Engineering
13 min read Published Jul 16, 2026 Download PDF
01

NCA ECC framework overview

The ECC 1-1:2020 framework comprises five domains: Cybersecurity Governance, Cybersecurity Risk Management, Cybersecurity Operations, Third-Party Cybersecurity, and Industrial Control Systems. Domain 3 (Cybersecurity Operations) contains the controls most relevant to security monitoring: 3-1 (Asset Management), 3-3 (Identity and Access Management), and 3-5 (Cybersecurity Monitoring and Operations).

The NCA conducts compliance assessments of covered entities and publishes sector-specific guidance. Entities found non-compliant with ECC can face regulatory action. Compliance assessments typically include evidence review and technical testing — the same artefacts that satisfy other frameworks (SOC 2, ISO 27001) provide a strong foundation for NCA ECC evidence.

02

ECC 3-5: Cybersecurity Monitoring and Operations

ECC 3-5 requires: a security operations capability to monitor cybersecurity events, logging of all significant cybersecurity events, analysis of logs for anomalous activity, incident response procedures, and regular testing of the monitoring capability. These five requirements map directly to ManySignal capabilities.

The framework distinguishes between monitoring (continuous) and analysis (event-triggered). Both are required. ManySignal's detect agent provides continuous monitoring; the triage and investigate agents provide analysis. The combination satisfies the ECC 3-5 requirement for both monitoring and analytical response.

03

Log collection and retention for ECC

ECC 3-5 requires logging of all significant cybersecurity events. 'Significant' is not defined prescriptively — use the NIST SP 800-92 log management guidance as a reference: at minimum, authentication events, privilege use, account management, policy changes, and system events for all in-scope systems.

Retention requirements are not specified in the ECC itself but are subject to Saudi Arabia's Personal Data Protection Law (PDPL) and sector-specific regulations. For government entities, a common requirement is 5 years for security event logs. Configure ManySignal retention accordingly and confirm with your NCA liaison.

  • All in-scope systems have active log ingestion in ManySignal
  • Authentication, privilege, account management, policy, and system events captured
  • Retention policy reviewed against PDPL and sector-specific requirements
  • Monitoring capability tested quarterly (tabletop or controlled incident simulation)
  • Incident response procedure references ECC 3-5 requirements explicitly
04

Identity and Access Management controls (ECC 3-3)

ECC 3-3 includes MFA requirements for remote access and privileged accounts, privileged access management controls, and user activity monitoring for privileged users. ManySignal satisfies the monitoring requirement: privileged identity activity is modelled in the entity graph with elevated anomaly sensitivity, and all privileged actions are logged on the immutable case timeline.

For Saudi government entities, the ECC also requires compliance with NCA's Identity and Access Management Framework (IAM 1-1). This framework mandates IdP integration and access review processes that align naturally with ManySignal's entity graph population from IdP sources.

05

Evidence for NCA compliance assessments

NCA compliance assessments are evidence-based. Prepare: the monitoring capability design document (what sources are ingested, what is detected, how incidents are managed), the detection catalogue (active detections mapped to ECC controls), the incident log (cases from the past 12 months), and the periodic testing records (tabletop or simulation results).

Demonstrate the monitoring capability live during the assessment if requested: show a ManySignal case from detection through triage to verdict, and show the weekly metrics report. Live demonstration of a functioning capability is more persuasive than documentation alone.

Key takeaways

  • ECC Domain 3 (Cybersecurity Operations) is the primary domain relevant to security monitoring.
  • ECC 3-5 requires both continuous monitoring and analytical response — detect agent plus triage/investigate agents.
  • Retain logs per PDPL and sector requirements; confirm retention period with your NCA liaison.
  • ECC 3-3 privileged account monitoring is satisfied by elevated anomaly sensitivity in the entity graph.
  • Prepare: design document, detection catalogue, incident log, and periodic testing records for assessments.
  • Live capability demonstration during NCA assessments is more persuasive than documentation alone.

Further reading

Frequently asked questions

What is Saudi NCA ECC Implementation Guide in an agentic SOC?

Saudi NCA ECC Implementation Guide is part of ManySignal's agentic SOC and MDR platform, where AI agents detect, triage, investigate, and respond to threats with human-governed autonomy.

How does ManySignal handle saudi nca ecc implementation guide?

ManySignal grounds saudi nca ecc implementation guide in a temporal entity graph and behavioural baselines, so every verdict is backed by auditable evidence rather than opaque scores.

Can ManySignal replace my SOAR or MDR for saudi nca ecc implementation guide?

Yes. ManySignal combines detection, triage, investigation, response, and reporting in one platform, and can operate as your MDR or augment an existing SOC team.

How is autonomy governed?

Through an autonomy ladder: recommend-only, approve-gated, and autonomous modes per action class, with dry-run previews, blast-radius limits, and a one-click tenant kill switch.

How fast is time to value?

Declarative connectors and shipped detections typically produce AI agent verdicts on live alerts within days, not quarters — no parsing projects or playbook-building phase.

Is ManySignal available as a managed service?

Yes. Consume ManySignal as MDR with 24/7 coverage and monthly reporting, run it as your in-house agentic SOC, or use it as the platform behind your own MDR practice.

How does ManySignal license the platform?

Pricing scales with protected assets and autonomy tier, not per-GB ingestion or per-alert volume. Starter, Growth, and Enterprise plans are available; MDR providers receive volume discounts for multi-tenant deployments.

Where does our data reside?

By default in AWS us-east-1. Enterprise tenants can pin data to specific AWS regions, deploy self-hosted on their own Kubernetes cluster, or use customer-managed encryption keys (CMK) to retain cryptographic control.

What does the evidence trail contain?

Each verdict stores the full question set, per-question agent answers, confidence weights, source event references, entity graph snapshots, and operator attestation — preserved immutably for the retention period chosen at contract time.

How does ManySignal handle a false-positive alert?

The triage agent auto-closes findings it assesses as false positives with a documented rationale — which rule fired, why the evidence fails to support escalation, and the entity baseline that informed the decision. Auto-closure rates typically reach 85–95% within 90 days as baselines mature.

Continue reading

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.