NCA ECC and CSCC Compliance

Ensure your cybersecurity controls meet the Saudi National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) and Critical Systems Cybersecurity Controls (CSCC) requirements. Validate the effectiveness of your security posture against real attacks to stay compliant, protect critical systems, and produce audit-ready evidence year-round.

 

What Is Essential Cybersecurity Controls (ECC)?

Essential Cybersecurity Controls (ECC) is the NCA baseline. It defines the minimum set of cybersecurity controls that in-scope organizations must implement.

Its domains span network and email security, vulnerability management, penetration testing, event logging and monitoring, web application security, and cloud computing.

What Is Critical Systems Cybersecurity Controls (CSCC)?

Critical Systems Cybersecurity Controls (CSCC) builds on top of the ECC and applies to organizations that operate critical systems. CSCC is an extension of the ECC, and an organization cannot be fully compliant with the CSCC unless it is also compliant with the ECC.

The CSCC makes review cycles stricter, with configuration and firewall reviews every six months, vulnerability assessments every month, and penetration tests at least twice a year.

Stay NCA-compliant and prove control effectiveness with autonomous validation

Why It Matters

Why NCA Compliance Is Important

NCA compliance requires more than meeting a regulatory checklist. Organizations operating in the Kingdom of Saudi Arabia work within one of the most structured cybersecurity regulatory environments in the region, and they must demonstrate that the controls protecting their digital and critical infrastructure actually work as systems and threats change.

The challenge is that NCA frameworks repeat the same instruction across control after control: review the requirements periodically. A point-in-time review reflects the state of a control only on the day it was tested. It says nothing about the days in between, while configurations drift and adversary techniques keep evolving. This requirement for ongoing control assurance makes security validation a core component of NCA compliance.

Here is how a validation-led approach to NCA compliance helps organizations achieve their goals:

Proves that security controls block and detect current attacks, not just that they exist on paper.
Keeps compliance evidence current rather than tied to a single annual assessment.
Strengthens the resilience of the Kingdom's critical systems against advanced, nation-state-level threats.
Builds defensible, audit-ready evidence for auditors, the cybersecurity steering committee, and the Authorizing Official.

What NCA Compliance Requires

NCA compliance is governed by two related frameworks, ECC and CSCC. The following shows which controls in these frameworks Picus helps with.

Framework

ECC

Essential Cybersecurity Controls

Domain 1 — Cybersecurity Governance

  • 1-8 Periodical Cybersecurity Review and Audit

Domain 2 — Cybersecurity Defense

  • 2-3 Information System and Information Processing Facilities Protection
  • 2-4 Email Protection
  • 2-5 Networks Security Management
  • 2-7 Data and Information Protection
  • 2-10 Vulnerabilities Management
  • 2-11 Penetration Testing
  • 2-15 Web Application Security
  • 2-12 Cybersecurity Event Logs and Monitoring Management

Domain 4 — Third-Party and Cloud Computing Cybersecurity

  • 4-2 Cloud Computing and Hosting Cybersecurity
Framework

CSCC

Critical Systems Cybersecurity Controls

Domain 1 — Cybersecurity Governance

  • 1-4 Periodical Cybersecurity Review and Audit

Domain 2 — Cybersecurity Defense

  • 2-3 Systems and Information Processing Facilities Protection
  • 2-4 Network Security Management
  • 2-9 Vulnerabilities Management
  • 2-10 Penetration Testing
  • 2-12 Web Application Security
  • 2-11 Cybersecurity Event Logs and Monitoring Management
mid-strip-gray-mobile mid-strip-gray

Benefits of Security Validation for NCA Compliance

Picus Platform helps Saudi organizations test the effectiveness of the controls the NCA requires, supporting regulatory compliance while reducing the risk of breaches, data tampering, and disruption to critical systems.

Strengthen Critical System Resilience

Validate security controls that protect critical infrastructure and sensitive systems from unauthorized access, misuse, and exploitation that could lead to service disruption or data loss.

Make "Review Periodically" Sustainable

Automate testing on a daily, monthly, or six-monthly schedule so the recurring review obligations across the ECC and CSCC become sustainable, producing scored, time-stamped evidence that stays current between assessments.

Prioritize Real, Exploitable Risk

Replace thousands of theoretical scanner findings with a single Picus Score that blends CVSS, EPSS, KEV data, validated control effectiveness, and asset criticality, focusing remediation on the vulnerabilities that are genuinely exploitable in your environment.

Shorten Detection and Response Gaps

Validate that SIEM, EDR, XDR, and SOAR controls capture logs and alert on the latest adversary behavior, flagging missing or obsolete rules and measuring the delay between event and alert to reduce false positives and attacker dwell time.

Requirements

NCA Controls Supported by Picus Security

Below is a list of the NCA controls supported by Picus, highlighting where it contributes to securing critical systems and supporting compliance efforts.

ECC 1-8 / CSCC 1-4 Periodical Cybersecurity Review & Audit
ECC 2-3 / CSCC 2-3 Systems & Information Processing Facilities Protection
ECC 2-4 Email Protection
ECC 2-5 / CSCC 2-4 Networks Security Management
ECC 2-7 Data & Information Protection
ECC 2-10 / CSCC 2-9 Vulnerabilities Management
ECC 2-11 / CSCC 2-10 Penetration Testing
ECC 2-15 / CSCC 2-12 Web Application Security
ECC 2-12 / CSCC 2-11 Cybersecurity Event Logs & Monitoring Management
ECC 4-2 Cloud Computing & Hosting Cybersecurity
PRACTICAL GUIDE

A Practical Guide to NCA ECC and CSCC Compliance Using Picus

NCA compliance does not stop at documentation. This guide walks through how Saudi organizations can validate every control against real attack behavior, satisfy the periodic-review obligations of ECC and CSCC, and produce audit-ready evidence in real-time throughout the year.

VALIDATED & COMPLIANT
mid-strip-gray-mobile mid-strip-gray
mid-strip-gray-mobile mid-strip-gray

gartner-logo-2025 1 (1)

Customer's Choice

2026 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation

mid-strip-gray-mobile mid-strip-gray
mid-strip-gray-mobile mid-strip-gray

G2-winter-badge-standart-size

BAS Category Leader

Ranked #1 by Users on G2

What Our Customers Say

resources

Picus for Compliance

Pattern-mobile Pattern(1)

See the
Picus Security Validation Platform

Request a Demo

Submit a request and we'll share answers to your top security validation and exposure management questions.

Get Threat-ready

Simulate real-world cyber threats in minutes and see a holistic view of your security effectiveness.

Frequently Asked Questions

NCA compliance means meeting the cybersecurity requirements set by the Saudi National Cybersecurity Authority (NCA), the body responsible for setting and enforcing the controls that protect the Kingdom's digital and critical infrastructure. The two frameworks that matter most are the Essential Cybersecurity Controls (ECC) and the Critical Systems Cybersecurity Controls (CSCC).

ECC applies to in-scope organizations across the Saudi government, critical infrastructure, and other sensitive sectors. CSCC applies specifically to organizations that operate critical systems, such as energy generation, water treatment, and other essential services. An organization cannot be fully compliant with the CSCC unless it is also compliant with the ECC.

ECC is the NCA baseline that defines the minimum set of cybersecurity controls every in-scope organization must implement. CSCC is an extension of the ECC for critical systems that adds tighter controls and shorter review cadences, including firewall and configuration reviews every six months, monthly vulnerability assessments, and penetration tests at least twice a year.

NCA frameworks require controls across network and email security, vulnerability management, penetration testing, event logging and monitoring, web application security, and cloud computing. A consistent requirement runs through both frameworks: each control must be reviewed periodically to confirm it remains effective as systems and threats change.

It means controls cannot be validated once and assumed to be effective. NCA frameworks require organizations to retest controls on a defined schedule because configurations drift and attacker techniques evolve. Security validation automates this testing so the review becomes continuous and the supporting evidence stays current.

Security validation runs scheduled simulations to see whether security controls actually block and detect real attacks. It turns periodic, assumption-based compliance into continuous, evidence-based assurance, producing scored, time-stamped reports that satisfy the expectations of auditors, the cybersecurity steering committee, and the Authorizing Official, not just at assessment time, but continuously.

The Picus Platform maps attack paths, simulates real-world threats, and proves exploitability across your stack. It validates control effectiveness, prioritizes exploitable exposures, and returns vendor-specific & vendor-neutral mitigation guidance. Every threat is mapped to MITRE ATT&CK, and new threats are added on an ongoing basis, which makes the NCA periodic-review obligations sustainable and audit-ready.