Frequently Asked Questions
Find answers to your questions about cybersecurity and the CISO Consulting platform
NCA & Government 13
The NCA Essential Cybersecurity Controls (ECC) is a mandatory framework issued by the National Cybersecurity Authority of Saudi Arabia. It applies to all Saudi government entities, state-owned enterprises, and critical national infrastructure organizations. It contains 114 controls across 5 domains.
The NCA ECC covers: (1) Cybersecurity Governance — policies, roles, and strategy; (2) Cybersecurity Defense — technical controls for endpoints, servers, applications, and networks; (3) Cybersecurity Resilience — business continuity, incident response, and disaster recovery; (4) Third-Party & Cloud Cybersecurity — supplier management and cloud usage controls; (5) Industrial Control Systems — cybersecurity for OT/ICS environments.
The NCA Essential Cybersecurity Controls (ECC) place specific obligations on Saudi organizations regarding cryptography, addressed primarily under ECC Domain 2-14 (Cryptography and Encryption). Organizations must establish and enforce a documented cryptography policy that governs the use, management, and retirement of cryptographic keys and algorithms across all information systems. Approved cryptographic standards must align with internationally recognized frameworks such as NIST SP 800-57 and FIPS 140-2 (or FIPS 140-3 for newer deployments). This means deploying only vetted algorithms: AES-256 for symmetric encryption, RSA-2048 or ECDSA P-256 for asymmetric operations, and SHA-256 or higher for hashing. Weak or deprecated algorithms such as MD5, SHA-1, DES, and 3DES must be eliminated from all production systems. From a SAMA CSF perspective, Control 3.2.1 reinforces encryption mandates for data at rest and in transit across banking systems, payment channels, and customer-facing applications. Key management is a critical operational area: organizations must implement a formal Key Management Lifecycle covering key generation, distribution, storage, rotation, and destruction. Hardware Security Modules (HSMs) are strongly recommended — and in many cases expected by regulators — for protecting cryptographic keys used in payment processing and PKI environments. Public Key Infrastructure (PKI) should be managed with a clearly defined Certificate Lifecycle Management process, including automated alerting for certificate expiry to prevent outages. Practical steps include conducting a cryptographic asset discovery exercise to identify all certificates, keys, and encryption implementations across the environment, followed by a gap assessment against ECC and SAMA requirements. Organizations should also integrate certificate management tools such as Venafi or Keyfactor and schedule annual cryptographic reviews to ensure ongoing compliance as standards evolve.
NCA ECC-2 Article 3-8 (Cybersecurity Incident Management) sets explicit obligations for how Saudi organizations must detect, manage, and report cybersecurity incidents. For financial institutions, SAMA CSF Control Domain 3.6 adds additional sector-specific layers.
Reporting Timelines: Under NCA ECC, significant cybersecurity incidents must be reported to the National Cybersecurity Authority within 24 hours of detection. SAMA requires banks to additionally notify SAMA's Cybersecurity Division within the same window for incidents impacting financial services, customer data, or operational continuity.
Incident Classification: Establish a formal severity taxonomy (P1–P4) aligned to NCA ECC definitions. P1 incidents (full system compromise, ransomware, data breach affecting customer PII) trigger immediate escalation to executive leadership and regulators. PDPL Article 39 also mandates notification to SDAIA within 72 hours for breaches involving personal data.
IR Plan Components: Your Incident Response Plan must include: defined roles and responsibilities (RACI matrix), pre-approved communication templates for regulators and customers, evidence preservation procedures aligned to forensic best practices, and post-incident review (PIR) requirements. NCA expects IR plans to be tested via tabletop exercises at minimum annually.
Practical Guidance: Integrate your SIEM and SOAR platform to automate initial triage and alert escalation. Pre-register your institution on the NCA's National Cybersecurity Operations Center (NCOC) reporting portal. Maintain an up-to-date incident log with timestamps, containment actions, and regulatory notifications as permanent audit evidence. SAMA examiners routinely request IR documentation during on-site reviews.
The NCA Essential Cybersecurity Controls (ECC) — specifically ECC-2: 2-3 on Cybersecurity Operations — mandate that Saudi organizations operating critical national infrastructure, including banks and financial institutions, establish and operate a Security Operations Center (SOC) capable of continuous threat detection, monitoring, and response.
Key NCA ECC SOC Requirements:
1. 24/7 Monitoring Coverage: The SOC must provide round-the-clock monitoring of all critical systems, networks, and endpoints. This applies equally to in-house and outsourced managed SOC models.
2. SIEM Integration: A Security Information and Event Management (SIEM) platform must be deployed to aggregate, correlate, and analyze security events. Log retention must meet NCA requirements — typically 12 months online with extended archival.
3. Threat Intelligence Integration: Per NCA ECC, the SOC must consume and act on threat intelligence feeds, including those from CERT-SA, to detect emerging Saudi-specific threats such as targeted phishing campaigns and ransomware affecting Gulf financial entities.
4. Incident Detection & Escalation SLAs: Define Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) metrics. SAMA CSF additionally expects these KPIs to be reported to senior management periodically.
5. Integration with SAMA CSF Domain 3.4: SOC workflows must feed directly into the institution's Incident Response Plan, triggering regulatory notification processes when thresholds are breached.
6. SOC Maturity Assessment: NCA recommends periodic SOC maturity assessments against the SOC-CMM or equivalent model. Financial institutions should target at least Level 3 maturity.
Insourced vs. Outsourced SOC: Both models are acceptable under NCA ECC, provided the outsourced provider operates within Saudi Arabia and complies with data residency requirements under PDPL Article 29.
Our platform supports SOC teams with compliance dashboards, automated alert mapping to NCA ECC controls, and readiness assessments for SOC maturity uplift.
Vulnerability management is one of the most operationally intensive — yet most scrutinized — controls in Saudi financial regulation. Both NCA ECC (Article 2-7: Vulnerability Management) and SAMA CSF Control 3.3.5 set clear expectations for a continuous, risk-based vulnerability management lifecycle.
Building a Compliant Vulnerability Management Program:
- Asset Discovery & Coverage: You cannot protect what you don't know exists. Maintain a continuously updated asset inventory covering all IT, OT, cloud, and third-party-connected systems. This directly supports NCA ECC asset management requirements.
- Scanning Frequency: Internal vulnerability scans should run at minimum monthly; critical internet-facing assets and systems processing customer data require weekly or continuous scanning. New systems must be scanned before production deployment.
- Severity-Based Remediation SLAs: Establish documented SLAs aligned with risk classification:
- Critical (CVSS 9.0+): Remediate within 15 days
- High (CVSS 7.0–8.9): Remediate within 30 days
- Medium: 90 days
- Low: Next scheduled maintenance cycle
- Risk Acceptance Process: Where immediate remediation is not feasible, implement a formal risk acceptance and compensating controls process with CISO sign-off and documented review timelines.
- Patch Management Integration: Vulnerability management must feed directly into your patch management workflow. SAMA CSF expects evidence of patch tracking and exception management.
- Threat Intelligence Integration: Prioritize remediation based on active exploitation in the wild — CISA KEV catalog and Saudi-specific threat intelligence feeds are valuable inputs.
- Reporting to Senior Management: Produce monthly vulnerability posture reports for IT leadership and quarterly summaries for CISO and board-level reporting.
Ensure your GRC platform can auto-generate vulnerability aging reports and exception registers for SAMA regulatory submissions.
NCA uses a structured Cybersecurity Maturity Assessment (CMA) process. Entities submit self-assessments which are verified through NCA's review cycle. NCA may conduct on-site inspections, request evidence, and publish compliance ratings. Non-compliant entities receive remediation plans with deadlines.
NCA ECC (Essential Cybersecurity Controls) applies broadly to all government entities and is the baseline standard. NCA CSCC (Critical Sector Cybersecurity Controls) is a more stringent framework for critical national infrastructure sectors such as energy, water, telecommunications, and financial services. CSCC builds upon ECC with additional sector-specific requirements.
The NCA Essential Cybersecurity Controls (ECC-1:2018) includes specific provisions under Domain 4 (Cybersecurity Resilience) and Domain 2 (Cybersecurity Defense) that apply to organizations operating OT/ICS environments, such as utilities, critical infrastructure operators, and increasingly, large financial institutions with data center OT components.
Network Segmentation (ECC Control 2-8): OT and IT networks must be strictly segregated using firewalls, data diodes, or demilitarized zones (DMZ). Direct connectivity between corporate IT and OT environments is prohibited. Any integration points must go through validated, one-way data transfer mechanisms.
Asset Management (ECC Control 2-1): All OT/ICS assets must be inventoried and classified. Legacy systems that cannot be patched must be documented with compensating controls — air-gapping, application whitelisting, and enhanced monitoring are commonly accepted compensating measures.
Remote Access Controls: Remote access to OT environments must be tightly controlled, session-based, and require MFA. Permanent remote access connections to OT systems are generally prohibited without documented risk acceptance.
Vulnerability Management: Given that many ICS components run proprietary or legacy operating systems with infrequent patch cycles, organizations must implement a tailored OT vulnerability management program with vendor coordination. Virtual patching via industrial intrusion prevention systems (IPS) is an acceptable interim control.
Monitoring and Incident Detection: Passive network monitoring tools (e.g., Claroty, Dragos, Nozomi Networks) must be deployed to detect anomalies without disrupting OT operations. Active scanning is generally avoided due to risk of system disruption.
Practical Recommendation: Commission an OT-specific cybersecurity assessment using IEC 62443 as a complementary framework alongside NCA ECC, and map your findings into your GRC platform to track remediation progress and demonstrate compliance during NCA assessments.
The NCA Essential Cybersecurity Controls (ECC-1:2018) — specifically under Domain 2-7 (Cybersecurity Resilience) — mandate that organizations establish a formal, documented Cybersecurity Incident Response (IR) capability. For Saudi financial institutions, this overlaps with SAMA CSF Domain 5 (Cybersecurity Resilience) and must also align with reporting obligations to SAMA and NCA's national CERT (CERT-SA).
Core IR Program Components Required:
- Incident Response Policy & Plan: Define roles, responsibilities, escalation paths, and communication protocols. The plan must be approved by senior leadership and reviewed at least annually.
- Incident Classification Framework (ECC Art. 2-7-1): Categorize incidents by severity (P1–P4) to trigger proportionate responses. Cyber incidents affecting critical financial infrastructure may require escalation to CERT-SA.
- Detection & Analysis Capabilities: Deploy a Security Operations Center (SOC) or equivalent with 24/7 monitoring, SIEM integration, and threat intelligence feeds tailored to the Saudi financial sector's threat landscape.
- Containment, Eradication & Recovery: Document playbooks for common attack scenarios (ransomware, DDoS, insider threats, BEC fraud) specific to banking environments.
- Regulatory Reporting Obligations: SAMA requires notification of significant cyber incidents within defined timeframes. Coordinate with your Legal and Compliance teams to ensure timely, accurate disclosures.
- Post-Incident Reviews (PIR): Conduct structured lessons-learned sessions after every significant incident, and feed findings back into your risk register and control improvements.
Pro Tip: Conduct tabletop exercises at least twice per year simulating scenarios such as core banking system compromise or payment fraud, and document outcomes for SAMA and NCA audit evidence.
The NCA Essential Cybersecurity Controls (ECC-1:2018) dedicates a substantial section to Identity and Access Management (IAM) under Control Domain 2-4, outlining mandatory requirements for any entity falling under NCA's scope — including government agencies, critical national infrastructure operators, and state-affiliated organizations.
Core ECC IAM Requirements:
- ECC Control 2-4-1: Establish a formal IAM policy covering user lifecycle management — from provisioning to deprovisioning — with documented approval workflows.
- ECC Control 2-4-2: Enforce the principle of least privilege (PoLP) and role-based access control (RBAC) across all systems and applications.
- ECC Control 2-4-3: Mandate multi-factor authentication (MFA) for all privileged accounts, remote access sessions, and systems handling sensitive national data.
- ECC Control 2-4-4: Conduct quarterly access reviews and immediately revoke access upon role changes or employment termination.
Implementation Guidance:
- Deploy a centralized Identity Provider (IdP) — such as Microsoft Entra ID or a FIDO2-compliant solution — integrated with all critical systems.
- Implement Privileged Access Management (PAM) tools to monitor, record, and control privileged sessions.
- Establish a joiners-movers-leavers (JML) process with automated deprovisioning tied to HR systems.
- Maintain detailed access logs for a minimum of 12 months, aligned with NCA log retention requirements.
- For cloud environments, apply IAM controls consistent with NCA Cloud Cybersecurity Controls (CCC-1:2020).
Regular IAM audits should be documented and presented to the cybersecurity steering committee as evidence of ongoing compliance.
The NCA Essential Cybersecurity Controls (ECC) place cybersecurity governance at the foundation of organizational security maturity. Understanding and implementing these governance requirements is a starting point for any Saudi organization subject to NCA oversight.
NCA ECC Governance Requirements (Domain 1): ECC Domain 1 — Cybersecurity Governance — requires organizations to establish a formal cybersecurity governance framework that includes:
- A documented Cybersecurity Strategy aligned to business objectives (ECC Control 1-1).
- A dedicated Cybersecurity Function with defined roles and reporting lines, ideally reporting to C-suite or board level (ECC Control 1-2).
- A Cybersecurity Policy Framework covering all critical security domains (ECC Control 1-3).
- Cybersecurity roles and responsibilities formally defined and communicated across the organization (ECC Control 1-4).
- Board and senior management engagement in cybersecurity oversight and risk acceptance.
Building a Compliant Governance Structure:
- Appoint a CISO or equivalent: Designate a senior cybersecurity leader with direct access to executive management and the board.
- Establish a Cybersecurity Committee: A cross-functional committee (IT, Legal, Risk, Compliance, Business) that reviews cybersecurity risks and approves policies.
- Develop a Cybersecurity Policy Suite: Draft and approve policies covering access control, incident management, asset management, and acceptable use — mapped to ECC controls.
- Define a Cybersecurity Strategy: A 3–5 year roadmap aligned to NCA ECC maturity levels and business risk appetite.
- Conduct Annual Governance Reviews: Regularly assess governance effectiveness through internal audits and self-assessments using the NCA ECC assessment template.
- Integrate with ISO 27001: ISO 27001 Clause 5 (Leadership) and Clause 6 (Planning) closely mirror ECC Domain 1 requirements, enabling a unified governance approach.
Organizations that align their governance structures early reduce remediation effort during NCA compliance assessments and build a sustainable security culture from the top down.
The NCA Essential Cybersecurity Controls (ECC) explicitly addresses human-layer security through ECC Control 2-7 (Cybersecurity Awareness and Training), requiring Saudi organizations — including banks, fintechs, and government-linked entities — to implement a formal, ongoing security awareness program.
NCA ECC Mandatory Elements:
- Documented security awareness policy and annual training plan
- Role-based training tailored to job functions (e.g., developers, finance staff, executives)
- Phishing simulation exercises conducted regularly
- Awareness for third-party staff with access to organizational systems
- Metrics to measure program effectiveness
SAMA CSF Alignment: SAMA CSF Control 3.3.4 similarly requires awareness programs covering social engineering, password hygiene, data handling, and incident reporting procedures.
Building an Effective Program — Practical Steps:
- Baseline Assessment: Conduct a phishing simulation before launching the program to establish a click-rate baseline. Industry benchmarks suggest >30% click rates are common without training.
- Tiered Content: Develop role-specific modules — general staff receive phishing/password training, IT staff receive secure coding and access management content, and executives receive targeted social engineering and fraud awareness modules.
- Arabic-Language Content: Saudi regulators expect culturally relevant, Arabic-language training materials. Generic English-only platforms often fail to achieve the required engagement levels.
- Frequency: NCA ECC and best practices recommend at least annual formal training, monthly micro-learning, and quarterly phishing simulations.
- Documentation: Maintain training completion records, simulation results, and improvement metrics as audit evidence for NCA and SAMA reviews.
A GRC platform with integrated LMS capabilities can automate scheduling, track completions, generate compliance reports, and feed awareness metrics into your overall risk posture dashboard.
No matching questions found.
Didn't find what you're looking for?
✉️ Contact Us