Templates

NCA Compliance Checklist: ECC-2:2024 Full Guide

The NCA compliance checklist your team actually needs: ECC-2:2024 domains, NCNICC-1:2025, and what auditors look for as evidence.

Mountain landscape representing leadership perspective and vision
Written by
Trio Content Team
Published on
29 Mar 2026
Modified on
29 Mar 2026

Since December 2024, failing to meet NCA requirements carries penalties up to SAR 25 million, enforced by NCA Governor-appointed inspectors who can arrive unannounced. According to Arab News reporting on the IMD World Competitiveness Yearbook 2025, Saudi Arabia ranked #1 globally in cybersecurity, and the regulatory framework is built to keep it that way. This NCA compliance checklist is your practical response to that enforcement reality.

Two frameworks are now in effect. Government entities and critical national infrastructure (CNI) operators fall under ECC-2:2024. All non-CNI private sector organizations, regardless of size, are now covered by NCNICC-1:2025. If you manage IT or compliance at a company with as few as six employees and SAR 3 million in annual revenue, this checklist applies to you.

ECC-2:2024 restructured the original ECC-1:2018 framework into 4 domains and 110 controls, down from the previous 5 domains and 114 controls. The update also introduced a maturity-based evidence model: auditors now want proof that controls operate consistently, not just that they are documented.

This article walks through each ECC-2:2024 domain with actionable checklist items, explains what NCNICC-1:2025 requires for private sector organizations, maps exactly what auditors examine as evidence, and covers where most implementation programs stall.

TL;DR

TL;DR
  • ECC-2:2024 is the current NCA framework, 4 domains, 110 controls, replacing the 5-domain, 114-control ECC-1:2018 structure.

  • Since December 2024, non-compliance carries penalties up to SAR 25 million under the NCA Regulations 2024.

  • NCNICC-1:2025 extends mandatory compliance to all non-CNI private sector organizations, including SMBs with 6+ employees or SAR 3M+ in annual revenue.

  • MDM systems are explicitly named as a required control under ECC-2:2024 subdomain 2-6 (Mobile Devices Security).

  • ECC-2:2024 requires demonstrated operational security maturity, continuous enforcement generates continuous evidence, which is what auditors actually check.

Who the NCA Compliance Checklist Applies To

If you already know your organization falls under ECC-2:2024 or NCNICC-1:2025, skip ahead to the checklist sections below.

The most common reason organizations delay starting is scope confusion, mistakenly believing NCA compliance only applies to critical infrastructure operators. That gap formally closed with NCNICC-1:2025. The NCA compliance Saudi Arabia checklist now spans three distinct applicability tiers, each with different obligations.

Here is how scope breaks down:

  • Government entities and CNI operators, mandatory ECC-2:2024 compliance across all 4 domains and 110 controls. If you also operate OT or ICS environments, OTCC-1:2022 applies after ECC compliance is established.
  • Non-CNI private sector (Class A), 250+ employees OR SAR 200M+ annual revenue. NCNICC-1:2025 Class A obligations mirror ECC-2:2024 in depth, including a mandatory independent cybersecurity unit.
  • Non-CNI private sector (Class B), 6–249 employees OR SAR 3M–SAR 200M annual revenue. Lighter burden, but mandatory: baseline technical controls plus cybersecurity awareness training.

One important clarification: NCNICC-1:2025 is a distinct framework, not an update to ECC-2:2024. Organizations that previously achieved ECC-1:2018 or ECC-2:2024 compliance still need to assess their NCNICC-1:2025 obligations separately if they have a private sector operation alongside a government-facing one.

For a broader look at what NCA compliance means across Saudi regulatory law, the Trio blog has a dedicated reference.

Which NCA framework applies to your organization?

Government entity or CNI operator → ECC-2:2024 (4 domains, 110 controls). Add OTCC-1:2022 if you operate OT/ICS environments after establishing ECC compliance.

Private sector, 250+ employees OR SAR 200M+ annual revenue → NCNICC-1:2025 Class A. Scope mirrors ECC-2:2024; independent cybersecurity unit is mandatory.

Private sector, 6–249 employees OR SAR 3M–SAR 200M annual revenue → NCNICC-1:2025 Class B. Focus on awareness training and baseline controls: MFA, encryption, backups.

Not sure? → Begin with a gap assessment against ECC-2:2024, it covers the broadest control set, and mapping your current state against it first gives you a clear picture of what NCNICC adds.

The NCA ECC-2:2024 Compliance Checklist by Domain

The ECC-2:2024 framework replaced ECC-1:2018 with 4 domains and 110 controls, streamlined from the previous 5-domain, 114-control structure. This NCA ECC compliance checklist follows that domain architecture exactly. As an IT compliance framework, ECC-2:2024 does more than require implementation, it requires organizations to demonstrate operational maturity. Your evidence collection is as important as the controls themselves. Continuous enforcement tools generate continuous evidence, which means the compliance posture is built into day-to-day operations rather than assembled under pressure before an audit.

Domain 1, Cybersecurity Governance (10 Subdomains)

Domain 1 is the foundation every other control depends on. Control 1-4 requires named ownership for each cybersecurity role, and the absence of assigned owners is the most common reason controls remain unimplemented, address this before anything else.

  • ☐ Define a cybersecurity strategy aligned with Vision 2030 digital objectives (1-1)
  • ☐ Document, approve, and communicate cybersecurity policies and procedures across the organization (1-3)
  • ☐ Assign named ownership for each cybersecurity role and responsibility (1-4)
  • ☐ Establish a risk management methodology with a documented, maintained risk register (1-5)
  • ☐ Integrate cybersecurity review requirements into the IT project management lifecycle (1-6)
  • ☐ Verify ongoing compliance with relevant NCA standards, applicable laws, and sector regulations (1-7)
  • ☐ Schedule periodic cybersecurity reviews and independent audits, approved auditors may conduct these on NCA's behalf (1-8)
  • ☐ Embed cybersecurity requirements into HR processes, including hiring screening and offboarding access revocation (1-9)
  • ☐ Implement a continuous cybersecurity awareness and training program with measurable completion tracking (1-10)

Domain 2, Cybersecurity Defense (15 Subdomains)

Domain 2 is where most organizations concentrate their compliance effort, and where the pre-audit evidence crunch hits hardest, particularly around log management (2-12) and MDM configuration exports (2-6). Practitioners consistently prioritize Domain 2 first; the checklist items below reflect that priority order.

  • ☐ Maintain a current asset inventory across all hardware and software (2-1)
  • ☐ Implement identity and access management (IAM) with least-privilege principles (2-2)
  • ☐ Protect information systems and processing facilities with documented security baselines (2-3)
  • ☐ Implement email security controls, filtering, anti-phishing, and SPF/DKIM/DMARC configuration (2-4)
  • ☐ Manage network security including segmentation, firewall configurations, and perimeter controls (2-5)
  • Deploy a Mobile Device Management (MDM) system, explicitly listed as a required control (NCA checklist item 9; ECC-2:2024 subdomain 2-6), enforce encryption and password policies on all enrolled devices; implement remote lock and wipe for lost or stolen devices; apply scoped BYOD controls that prevent privileged access via personal devices; block devices without current security software. Organizations that already have an MDM solution deployed can evidence control 2-6 immediately. Deploying MDM to satisfy control 2-6 also automatically populates your asset inventory (2-1), satisfying two controls simultaneously. Consider using compliance automation tooling to enforce these policies continuously across all enrolled endpoints.
  • ☐ Protect data at rest and in transit using documented encryption standards (2-7)
  • ☐ Implement cryptographic key management procedures with defined ownership (2-8)
  • ☐ Establish backup and recovery procedures with documented RTO and RPO targets; test restore procedures regularly (2-9)
  • ☐ Conduct vulnerability assessments on an ongoing basis across all in-scope systems (2-10)
  • ☐ Schedule annual penetration tests for all production systems with an NCA-recognized testing firm (2-11), pen test firms in KSA book months in advance; the most common reason organizations miss this control's evidence window is scheduling delay, not technical failure. If your annual pen test report doesn't satisfy auditors, check whether the scope of systems tested matches the asset inventory, a mismatch is the most common cause of a rejected finding.
  • ☐ Implement log collection, normalization, and centralized monitoring (2-12)
  • ☐ Develop, document, and test an incident response plan with defined roles (2-13)
  • ☐ Implement physical security controls for all facilities housing IT infrastructure (2-14)
  • Secure web applications against OWASP-class vulnerabilities (2-15), new subdomain in ECC-2:2024, not present in ECC-1:2018. Organizations previously ECC-1:2018 compliant must add this subdomain to their program; it cannot be carried over from prior assessment evidence.

Domain 3, Cybersecurity Resilience (1 Subdomain)

  • ☐ Integrate cybersecurity resilience requirements into the Business Continuity Management (BCM) plan (3-1)
  • ☐ Document recovery time objectives and test failover procedures with recorded outcomes
  • ☐ Review and update the BCM plan after any material change to systems, structure, or threat environment

Domain 4, Third-Party and Cloud Computing Cybersecurity (2 Subdomains)

Third-party contract amendments routinely take longer than technical controls. International vendors unfamiliar with NCA requirements often resist contractual changes, begin vendor outreach in the earliest phase of your compliance program.

  • ☐ Assess all third-party vendors' cybersecurity posture before engagement (4-1)
  • ☐ Include cybersecurity annexes, NDAs, and secure data disposal clauses in all vendor agreements (4-1)
  • ☐ Assess cloud providers' security certifications, data handling practices, and incident response commitments (4-2)
  • ☐ Confirm cloud hosting arrangements against applicable data localization requirements under ICT Regulations, note: data localization authority was removed from ECC-2:2024 itself in the 2024 update; it is governed separately

ECC-2:2024 vs. NCNICC-1:2025: Which Controls Apply to You

Control AreaECC-2:2024 (Government / CNI)NCNICC-1:2025 Class A (Large Private Sector)NCNICC-1:2025 Class B (SME)
Cybersecurity StrategyFull (1-1)RequiredNot specified
Policies and ProceduresFull (1-3)RequiredBaseline
Risk ManagementFull (1-5)Dedicated methodology requiredNot specified
Cybersecurity Unit (Independent of IT)Defined roles requiredIndependent unit requiredNot required
Employee Awareness and TrainingFull (1-10)RequiredPrimary requirement
MFA and Access ControlsFull (2-2)RequiredRequired
MDM / Mobile Devices SecurityFull (2-6)RequiredBaseline
Third-Party / Cloud SecurityFull (Domain 4)RequiredBaseline

What NCNICC-1:2025 Adds for Private Sector Organizations

NCNICC-1:2025 is the first mandatory NCA framework designed exclusively for private sector organizations not classified as CNI. No NCA compliance requirements deadline has been publicly announced, but NCA inspectors can conduct unannounced reviews, and the SAR 25 million penalty ceiling is already in effect. The absence of a deadline is not a grace period. Executive buy-in for compliance investment stalls most often when there is no hard deadline; the penalty exposure is the business case practitioners need to escalate.

Organizations that delay NCNICC-1:2025 gap assessments face a second-order problem: when a deadline is eventually announced, they will have insufficient time to implement Domain 2 technical controls, many of which require procurement, vendor negotiation, and deployment cycles of 3–6 months.

Class A Requirements (Large Entities)

Class A applies to organizations with 250+ employees or SAR 200M+ in annual revenue. The scope effectively mirrors ECC-2:2024 in depth.

  • Establish an independent cybersecurity unit, separate from IT operations
  • Define and document a formal risk management methodology
  • Undergo regular independent cybersecurity audits
  • Implement full technical controls: access management, encryption, and documented backup procedures
  • Satisfy Domain 2 defense controls at the same level of evidence maturity expected of government entities

Class B Requirements (SMEs)

Class B applies to organizations with 6–249 employees or SAR 3M–SAR 200M in annual revenue. The burden is lighter than Class A, but the obligation is still mandatory. The primary focus is cybersecurity awareness, employee training on phishing, password security, and safe device use, alongside baseline technical controls: MFA, encryption, and tested backups.

For Class B organizations with small IT teams, NCA compliance automation tooling is the most practical path: applying baseline controls at scale without requiring a dedicated security function.

What NCA Auditors Actually Examine as Evidence

ECC-2:2024 introduced a formal maturity-based assessment model, and it changed what a successful NCA audit looks like. Auditors do not just verify that a control is documented; they check whether it operates consistently over time. The evidence collection crunch is real, and it is the most commonly cited pain point among practitioners who have been through an NCA audit cycle.

What a Strong Audit Evidence Package Includes

  • Policy documents: Dated, version-controlled, signed by the appropriate authority (Domain 1)
  • Training completion records: Dates, attendee lists, and content covered (Control 1-10)
  • Penetration test reports: Signed by an approved testing firm, scoped to all production systems (Control 2-11)
  • MDM configuration exports and device compliance reports: Showing encryption enforcement, policy assignment, and enrolled device inventory (Control 2-6), MDM solutions that generate device compliance reports on demand give auditors immediate, structured evidence for control 2-6 without manual log assembly
  • Access review logs: Periodic review of user permissions, termination of access for leavers (Control 2-2)
  • Incident response test records: Tabletop exercise documentation and response timeline logs (Control 2-13)
  • Vendor cybersecurity annexes: Signed contractual attachments for each third party (Domain 4)
  • Backup test logs: Restore test dates and outcomes (Control 2-9)

The Four Failure Points in Evidence Collection

ECC-2:2024 made evidence requirements an explicit audit criterion, this was not formally required under ECC-1:2018. Knowing where evidence packages fall short is how you prepare for the NCA audit before it arrives, not after.

  • Manual log collection from fragmented environments (AD, servers, firewalls, cloud) with no unified collection layer
  • Human error introduced during manual evidence assembly under deadline pressure
  • A gap between what the framework requires and what the organization can actually produce at assessment time
  • Log data that is not normalized, readable by IT staff but not in the structured format auditors expect

The practical answer to all four is continuous, tool-assisted enforcement. Automated compliance software that enforces controls continuously and exports standardized reports eliminates the evidence crunch by making audit readiness a steady state, not a pre-audit sprint. If auditors flag an evidence gap on a control you believe is implemented, check whether the evidence format matches ECC-2:2024 requirements, implementation and documentation are separate audit checks.

NCA Compliance and Related Obligations: PDPL, Penalties, and Other Frameworks

NCA ECC-2:2024 and PDPL, Two Frameworks, Overlapping Obligations

PDPL, administered by SDAIA, governs the collection, processing, and transfer of personal data, its grace period ended September 2024. ECC-2:2024 and PDPL address overlapping obligations, particularly around data protection, access controls, and encryption, but they operate through separate regulatory lenses with separate authorities. Compliance with NCA controls does not automatically satisfy PDPL; your organization must run both programs concurrently.

Many technical controls satisfy both frameworks simultaneously, encryption and access management are the clearest examples. A unified control inventory, where each control is tagged to both frameworks it serves, reduces duplicated effort without creating a false sense of full PDPL compliance. The practical obstacle to running both programs is the absence of a unified compliance ownership model, without a named owner for overlapping controls, the same control gets implemented twice by different teams.

The December 2024 Enforcement Framework

The December 2024 NCA Regulations established a penalty ceiling of SAR 25 million for non-compliance. NCA Governor-appointed inspectors can conduct unannounced site, system, and document reviews at any time. Key violations include operating regulated cybersecurity activities without an NCA license, making cybersecurity tools available without required licenses, and general non-compliance with NCA Standards.

No public remediation process for partial compliance has been announced. Maintaining documented progress toward full compliance, with a gap register and a roadmap, is the most defensible position if an inspection occurs before your program is complete.

Download Our Free NCA ECC Compliance Template/Checklist

Download your NCA Compliance Checklist to get a clear, practical overview of the controls and requirements set by the National Cybersecurity Authority (NCA) in Saudi Arabia. Use this resource to assess your current security posture, identify gaps, and take the next steps toward achieving and maintaining full compliance.

How Trio MDM Helps You Meet NCA ECC Compliance Requirements

ECC-2:2024 subdomain 2-6 explicitly names MDM systems as a required control. Treat MDM as a compliance tool, not just an IT tool, the device management layer is where control 2-6 evidence originates, and it feeds the asset inventory evidence for control 2-1 at the same time. Here is what Trio MDM covers across the NCA compliance checklist.

Control 2-6 (Mobile Devices Security):

  • Trio MDM enforces disk encryption and password policies across all enrolled Android, iPhone, iPad, Mac, and Windows devices, directly satisfying the ECC-2:2024 requirement that data on mobile devices be encrypted
  • Remote lock and wipe capability addresses device loss scenarios before they escalate into reportable data incidents
  • BYOD management applies scoped organizational controls that isolate corporate data and prevent privileged access via personal devices, precisely what ECC-2:2024 subdomain 2-6 requires
  • Continuous policy enforcement means device compliance status is current at all times, generating a real-time evidence trail for control 2-6 without manual intervention

Control 2-1 (Asset Management), second-order benefit:

  • Enrolling a device in Trio MDM automatically adds it to a centralized device inventory, generating audit-ready evidence for control 2-1 and control 2-6 simultaneously, one deployment action satisfies two controls

Audit Evidence (Domain 2 and broader):

  • Trio MDM generates device compliance reports and audit trails for administrative actions via Trio Device Logs, capturing actions taken within the Trio panel and actions Trio initiates on devices
  • Every activity table can be exported instantly, providing the structured evidence format auditors expect for device-related controls, no manual log assembly required
  • Automated control testing and one-click remediation keep the compliance posture current between assessment windows

Governance support (Domain 1 and Domain 2):

  • Trio MDM integrates with Azure AD (Microsoft Entra ID) and Google Workspace, supporting the IAM and access management controls required under control 2-2

Trio MDM handles the device layer of your ECC-2:2024 program. Start your free trial to see how Trio MDM maps to your ECC-2:2024 control requirements, or book a demo to walk through device compliance configuration with our team.

Ready-to-use Templates

Must-have Template Toolkit for IT Admins

Explore All
Template Toolkit

Start your free trial

No credit card required
Full access to all features

Get Ahead of the Curve

Every organization today needs a solution to automate time-consuming tasks and strengthen security. Without the right tools, manual processes drain resources and leave gaps in protection. Trio MDM is designed to solve this problem, automating key tasks, boosting security, and ensuring compliance with ease.

Don't let inefficiencies hold you back.

Every organization today needs a solution to automate time-consuming tasks and strengthen security. Without the right tools, manual processes drain resources and leave gaps in protection. Trio MDM is designed to solve this problem, automating key tasks, boosting security, and ensuring compliance with ease.

Smiling womanAbstract geometric patternAbstract geometric patternSmiling womanSmiling woman

Frequently Asked Questions (FAQ)

Not a full rebuild, but a structured gap assessment is required. The domain architecture changed from 5 to 4, controls reduced from 114 to 110, and a new subdomain, 2-15 Web Application Security, was added and has no equivalent in ECC-1:2018. You need to map your existing evidence to the updated control structure, identify what is missing, and produce evidence that meets ECC-2:2024's maturity demonstration requirements, which are more formally specified than ECC-1:2018's.

No. ECC-2:2024 is administered by NCA; PDPL is administered by SDAIA, they are separate frameworks with separate regulatory authorities. Technical controls like encryption and access management satisfy requirements under both, but a unified control inventory is the most efficient way to manage the overlap without creating a false sense of complete PDPL compliance.

No deadline has been announced as of this article's publication. NCA inspectors can conduct unannounced reviews, and the SAR 25 million penalty framework is already active under the December 2024 NCA Regulations. Begin your gap assessment now rather than waiting for a deadline announcement, Domain 2 technical controls alone require 3–6 months of procurement, deployment, and configuration work.

NCA requires that independent audits and assessments be conducted by approved cybersecurity auditors, verify that your chosen pen test vendor holds the required NCA recognition before engaging them. Beyond accreditation, pen test firms with KSA regulatory experience book months in advance; scope and schedule early to avoid missing the evidence window for control 2-11.

ECC-2:2024 control 2-6 and the NCA's Workstations, Mobile Devices and BYOD Security Policy Template apply to both. Requirements include encrypting and segregating data on BYOD devices, preventing privileged access via personal devices, and blocking devices without current security software. Corporate-owned devices allow stricter policy enforcement at the full device level; BYOD management requires a scoped approach that applies organizational controls without taking over the personal device entirely.

Related

From the blog

The related industry news, interviews, technologies, and resources.