
HIPAA compliance and cell phones is possible, but SMS, unmanaged BYOD, and unencrypted devices create real exposure most teams overlook.
The NCA compliance checklist your team actually needs: ECC-2:2024 domains, NCNICC-1:2025, and what auditors look for as evidence.
Since December 2024, failing to meet NCA requirements carries penalties up to SAR 25 million, enforced by NCA Governor-appointed inspectors who can arrive unannounced. According to Arab News reporting on the IMD World Competitiveness Yearbook 2025, Saudi Arabia ranked #1 globally in cybersecurity, and the regulatory framework is built to keep it that way. This NCA compliance checklist is your practical response to that enforcement reality.
Two frameworks are now in effect. Government entities and critical national infrastructure (CNI) operators fall under ECC-2:2024. All non-CNI private sector organizations, regardless of size, are now covered by NCNICC-1:2025. If you manage IT or compliance at a company with as few as six employees and SAR 3 million in annual revenue, this checklist applies to you.
ECC-2:2024 restructured the original ECC-1:2018 framework into 4 domains and 110 controls, down from the previous 5 domains and 114 controls. The update also introduced a maturity-based evidence model: auditors now want proof that controls operate consistently, not just that they are documented.
This article walks through each ECC-2:2024 domain with actionable checklist items, explains what NCNICC-1:2025 requires for private sector organizations, maps exactly what auditors examine as evidence, and covers where most implementation programs stall.
ECC-2:2024 is the current NCA framework, 4 domains, 110 controls, replacing the 5-domain, 114-control ECC-1:2018 structure.
Since December 2024, non-compliance carries penalties up to SAR 25 million under the NCA Regulations 2024.
NCNICC-1:2025 extends mandatory compliance to all non-CNI private sector organizations, including SMBs with 6+ employees or SAR 3M+ in annual revenue.
MDM systems are explicitly named as a required control under ECC-2:2024 subdomain 2-6 (Mobile Devices Security).
ECC-2:2024 requires demonstrated operational security maturity, continuous enforcement generates continuous evidence, which is what auditors actually check.
If you already know your organization falls under ECC-2:2024 or NCNICC-1:2025, skip ahead to the checklist sections below.
The most common reason organizations delay starting is scope confusion, mistakenly believing NCA compliance only applies to critical infrastructure operators. That gap formally closed with NCNICC-1:2025. The NCA compliance Saudi Arabia checklist now spans three distinct applicability tiers, each with different obligations.
Here is how scope breaks down:
One important clarification: NCNICC-1:2025 is a distinct framework, not an update to ECC-2:2024. Organizations that previously achieved ECC-1:2018 or ECC-2:2024 compliance still need to assess their NCNICC-1:2025 obligations separately if they have a private sector operation alongside a government-facing one.
For a broader look at what NCA compliance means across Saudi regulatory law, the Trio blog has a dedicated reference.
Which NCA framework applies to your organization?
Government entity or CNI operator → ECC-2:2024 (4 domains, 110 controls). Add OTCC-1:2022 if you operate OT/ICS environments after establishing ECC compliance.
Private sector, 250+ employees OR SAR 200M+ annual revenue → NCNICC-1:2025 Class A. Scope mirrors ECC-2:2024; independent cybersecurity unit is mandatory.
Private sector, 6–249 employees OR SAR 3M–SAR 200M annual revenue → NCNICC-1:2025 Class B. Focus on awareness training and baseline controls: MFA, encryption, backups.
Not sure? → Begin with a gap assessment against ECC-2:2024, it covers the broadest control set, and mapping your current state against it first gives you a clear picture of what NCNICC adds.
The ECC-2:2024 framework replaced ECC-1:2018 with 4 domains and 110 controls, streamlined from the previous 5-domain, 114-control structure. This NCA ECC compliance checklist follows that domain architecture exactly. As an IT compliance framework, ECC-2:2024 does more than require implementation, it requires organizations to demonstrate operational maturity. Your evidence collection is as important as the controls themselves. Continuous enforcement tools generate continuous evidence, which means the compliance posture is built into day-to-day operations rather than assembled under pressure before an audit.
Domain 1 is the foundation every other control depends on. Control 1-4 requires named ownership for each cybersecurity role, and the absence of assigned owners is the most common reason controls remain unimplemented, address this before anything else.
Domain 2 is where most organizations concentrate their compliance effort, and where the pre-audit evidence crunch hits hardest, particularly around log management (2-12) and MDM configuration exports (2-6). Practitioners consistently prioritize Domain 2 first; the checklist items below reflect that priority order.
Third-party contract amendments routinely take longer than technical controls. International vendors unfamiliar with NCA requirements often resist contractual changes, begin vendor outreach in the earliest phase of your compliance program.
NCNICC-1:2025 is the first mandatory NCA framework designed exclusively for private sector organizations not classified as CNI. No NCA compliance requirements deadline has been publicly announced, but NCA inspectors can conduct unannounced reviews, and the SAR 25 million penalty ceiling is already in effect. The absence of a deadline is not a grace period. Executive buy-in for compliance investment stalls most often when there is no hard deadline; the penalty exposure is the business case practitioners need to escalate.
Organizations that delay NCNICC-1:2025 gap assessments face a second-order problem: when a deadline is eventually announced, they will have insufficient time to implement Domain 2 technical controls, many of which require procurement, vendor negotiation, and deployment cycles of 3–6 months.
Class A applies to organizations with 250+ employees or SAR 200M+ in annual revenue. The scope effectively mirrors ECC-2:2024 in depth.
Class B applies to organizations with 6–249 employees or SAR 3M–SAR 200M in annual revenue. The burden is lighter than Class A, but the obligation is still mandatory. The primary focus is cybersecurity awareness, employee training on phishing, password security, and safe device use, alongside baseline technical controls: MFA, encryption, and tested backups.
For Class B organizations with small IT teams, NCA compliance automation tooling is the most practical path: applying baseline controls at scale without requiring a dedicated security function.
ECC-2:2024 introduced a formal maturity-based assessment model, and it changed what a successful NCA audit looks like. Auditors do not just verify that a control is documented; they check whether it operates consistently over time. The evidence collection crunch is real, and it is the most commonly cited pain point among practitioners who have been through an NCA audit cycle.
ECC-2:2024 made evidence requirements an explicit audit criterion, this was not formally required under ECC-1:2018. Knowing where evidence packages fall short is how you prepare for the NCA audit before it arrives, not after.
The practical answer to all four is continuous, tool-assisted enforcement. Automated compliance software that enforces controls continuously and exports standardized reports eliminates the evidence crunch by making audit readiness a steady state, not a pre-audit sprint. If auditors flag an evidence gap on a control you believe is implemented, check whether the evidence format matches ECC-2:2024 requirements, implementation and documentation are separate audit checks.
PDPL, administered by SDAIA, governs the collection, processing, and transfer of personal data, its grace period ended September 2024. ECC-2:2024 and PDPL address overlapping obligations, particularly around data protection, access controls, and encryption, but they operate through separate regulatory lenses with separate authorities. Compliance with NCA controls does not automatically satisfy PDPL; your organization must run both programs concurrently.
Many technical controls satisfy both frameworks simultaneously, encryption and access management are the clearest examples. A unified control inventory, where each control is tagged to both frameworks it serves, reduces duplicated effort without creating a false sense of full PDPL compliance. The practical obstacle to running both programs is the absence of a unified compliance ownership model, without a named owner for overlapping controls, the same control gets implemented twice by different teams.
The December 2024 NCA Regulations established a penalty ceiling of SAR 25 million for non-compliance. NCA Governor-appointed inspectors can conduct unannounced site, system, and document reviews at any time. Key violations include operating regulated cybersecurity activities without an NCA license, making cybersecurity tools available without required licenses, and general non-compliance with NCA Standards.
No public remediation process for partial compliance has been announced. Maintaining documented progress toward full compliance, with a gap register and a roadmap, is the most defensible position if an inspection occurs before your program is complete.
Download your NCA Compliance Checklist to get a clear, practical overview of the controls and requirements set by the National Cybersecurity Authority (NCA) in Saudi Arabia. Use this resource to assess your current security posture, identify gaps, and take the next steps toward achieving and maintaining full compliance.
ECC-2:2024 subdomain 2-6 explicitly names MDM systems as a required control. Treat MDM as a compliance tool, not just an IT tool, the device management layer is where control 2-6 evidence originates, and it feeds the asset inventory evidence for control 2-1 at the same time. Here is what Trio MDM covers across the NCA compliance checklist.
Control 2-6 (Mobile Devices Security):
Control 2-1 (Asset Management), second-order benefit:
Audit Evidence (Domain 2 and broader):
Governance support (Domain 1 and Domain 2):
Trio MDM handles the device layer of your ECC-2:2024 program. Start your free trial to see how Trio MDM maps to your ECC-2:2024 control requirements, or book a demo to walk through device compliance configuration with our team.
Every organization today needs a solution to automate time-consuming tasks and strengthen security. Without the right tools, manual processes drain resources and leave gaps in protection. Trio MDM is designed to solve this problem, automating key tasks, boosting security, and ensuring compliance with ease.
Every organization today needs a solution to automate time-consuming tasks and strengthen security. Without the right tools, manual processes drain resources and leave gaps in protection. Trio MDM is designed to solve this problem, automating key tasks, boosting security, and ensuring compliance with ease.





Related
The related industry news, interviews, technologies, and resources.

HIPAA compliance and cell phones is possible, but SMS, unmanaged BYOD, and unencrypted devices create real exposure most teams overlook.

Saudi private sector organizations now face mandatory NCA compliance, this guide shows which ECC-2:2024 controls to automate first and how.

Explore top NIST compliance automation tools and strategies. Save time, reduce risk, and simplify compliance management with this practical IT guide.

NIST compliance checklist with a free template. Learn how to meet NIST cybersecurity requirements and streamline your compliance process.

Discover automated PCI DSS compliance tools - what they do, key features, and how to choose the right solution for your business needs.

Learn what ISO 27001 compliance automation actually covers, what it cannot replace, and step-by-step guidance for successful implementation.

Explore HIPAA compliance automation capabilities, limitations, and implementation steps. Learn what you can automate and what needs human oversight.

Learn how to achieve ISO 27001 compliance for small businesses with practical steps, real cost breakdowns, and tips to get certified on a tight budget.