NCA ECC and CSCC Compliance
Ensure your cybersecurity controls meet the Saudi National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) and Critical Systems Cybersecurity Controls (CSCC) requirements. Validate the effectiveness of your security posture against real attacks to stay compliant, protect critical systems, and produce audit-ready evidence year-round.
What Is Essential Cybersecurity Controls (ECC)?
Essential Cybersecurity Controls (ECC) is the NCA baseline. It defines the minimum set of cybersecurity controls that in-scope organizations must implement.
Its domains span network and email security, vulnerability management, penetration testing, event logging and monitoring, web application security, and cloud computing.
What Is Critical Systems Cybersecurity Controls (CSCC)?
Critical Systems Cybersecurity Controls (CSCC) builds on top of the ECC and applies to organizations that operate critical systems. CSCC is an extension of the ECC, and an organization cannot be fully compliant with the CSCC unless it is also compliant with the ECC.
The CSCC makes review cycles stricter, with configuration and firewall reviews every six months, vulnerability assessments every month, and penetration tests at least twice a year.
Stay NCA-compliant and prove control effectiveness with autonomous validation
Why NCA Compliance Is Important
NCA compliance requires more than meeting a regulatory checklist. Organizations operating in the Kingdom of Saudi Arabia work within one of the most structured cybersecurity regulatory environments in the region, and they must demonstrate that the controls protecting their digital and critical infrastructure actually work as systems and threats change.
The challenge is that NCA frameworks repeat the same instruction across control after control: review the requirements periodically. A point-in-time review reflects the state of a control only on the day it was tested. It says nothing about the days in between, while configurations drift and adversary techniques keep evolving. This requirement for ongoing control assurance makes security validation a core component of NCA compliance.
Here is how a validation-led approach to NCA compliance helps organizations achieve their goals:
ECC
Essential Cybersecurity Controls
Domain 1 — Cybersecurity Governance
- 1-8 Periodical Cybersecurity Review and Audit
Domain 2 — Cybersecurity Defense
- 2-3 Information System and Information Processing Facilities Protection
- 2-4 Email Protection
- 2-5 Networks Security Management
- 2-7 Data and Information Protection
- 2-10 Vulnerabilities Management
- 2-11 Penetration Testing
- 2-15 Web Application Security
- 2-12 Cybersecurity Event Logs and Monitoring Management
Domain 4 — Third-Party and Cloud Computing Cybersecurity
- 4-2 Cloud Computing and Hosting Cybersecurity
CSCC
Critical Systems Cybersecurity Controls
Domain 1 — Cybersecurity Governance
- 1-4 Periodical Cybersecurity Review and Audit
Domain 2 — Cybersecurity Defense
- 2-3 Systems and Information Processing Facilities Protection
- 2-4 Network Security Management
- 2-9 Vulnerabilities Management
- 2-10 Penetration Testing
- 2-12 Web Application Security
- 2-11 Cybersecurity Event Logs and Monitoring Management
Benefits of Security Validation for NCA Compliance
Picus Platform helps Saudi organizations test the effectiveness of the controls the NCA requires, supporting regulatory compliance while reducing the risk of breaches, data tampering, and disruption to critical systems.
Validate security controls that protect critical infrastructure and sensitive systems from unauthorized access, misuse, and exploitation that could lead to service disruption or data loss.
Automate testing on a daily, monthly, or six-monthly schedule so the recurring review obligations across the ECC and CSCC become sustainable, producing scored, time-stamped evidence that stays current between assessments.
Replace thousands of theoretical scanner findings with a single Picus Score that blends CVSS, EPSS, KEV data, validated control effectiveness, and asset criticality, focusing remediation on the vulnerabilities that are genuinely exploitable in your environment.
Validate that SIEM, EDR, XDR, and SOAR controls capture logs and alert on the latest adversary behavior, flagging missing or obsolete rules and measuring the delay between event and alert to reduce false positives and attacker dwell time.
NCA Controls Supported by Picus Security
Below is a list of the NCA controls supported by Picus, highlighting where it contributes to securing critical systems and supporting compliance efforts.
A Practical Guide to NCA ECC and CSCC Compliance Using Picus
NCA compliance does not stop at documentation. This guide walks through how Saudi organizations can validate every control against real attack behavior, satisfy the periodic-review obligations of ECC and CSCC, and produce audit-ready evidence in real-time throughout the year.
Customer's Choice
2026 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation
What Our Customers Say
Picus is very good attack simulation tool in overall. It shows all security vulnerabilities and guides..
Sr. Information Security & Risk Officer
The implementation was very fast, the platform is easy to integrate and results quite intuitive to be analyzed.
CIO
A very successful platform where we can test the accuracy of our security investments and see their scores.
Manager, IT Security and Risk Management
Picus is one of the best BAS solution on the market today. The threat database it is constantly updated..
ICT Security Engineer
There is a very nice team from which I can get quick support. The application provides us with great convenience and confidence in our work.
Information Security Specialist
With the help of this product we can perform continuosly endpoint attack via latest tactics and techniques which are used by threat actors..
Manager, IT Security and Risk Management
.. It is possible to customise the campaign or schedule the assessment periodically, to test protection measure implemented on network, endpoint and email.
ICT Security Engineer
Picus is such a great product for organizations that are looking to have constant checks and validation on their security posture in the organization.
Cybersecuirty Pre-sales Engineer
Picus is a real safety measurement tool. Ever since we took Picus into our inventory, Security has helped significantly to increase our maturity level.
Cyber Defense Senior Specialist
It strengthened our security perspective and allowed us to follow trend attacks. We can test zeroday malicious threats very early because Picus could add them their attack database quickly.
Security Specialist
Picus for Compliance
See the
Picus Security Validation Platform
Request a Demo
Submit a request and we'll share answers to your top security validation and exposure management questions.
Get Threat-ready
Simulate real-world cyber threats in minutes and see a holistic view of your security effectiveness.
Frequently Asked Questions
NCA compliance means meeting the cybersecurity requirements set by the Saudi National Cybersecurity Authority (NCA), the body responsible for setting and enforcing the controls that protect the Kingdom's digital and critical infrastructure. The two frameworks that matter most are the Essential Cybersecurity Controls (ECC) and the Critical Systems Cybersecurity Controls (CSCC).
ECC applies to in-scope organizations across the Saudi government, critical infrastructure, and other sensitive sectors. CSCC applies specifically to organizations that operate critical systems, such as energy generation, water treatment, and other essential services. An organization cannot be fully compliant with the CSCC unless it is also compliant with the ECC.
ECC is the NCA baseline that defines the minimum set of cybersecurity controls every in-scope organization must implement. CSCC is an extension of the ECC for critical systems that adds tighter controls and shorter review cadences, including firewall and configuration reviews every six months, monthly vulnerability assessments, and penetration tests at least twice a year.
NCA frameworks require controls across network and email security, vulnerability management, penetration testing, event logging and monitoring, web application security, and cloud computing. A consistent requirement runs through both frameworks: each control must be reviewed periodically to confirm it remains effective as systems and threats change.
It means controls cannot be validated once and assumed to be effective. NCA frameworks require organizations to retest controls on a defined schedule because configurations drift and attacker techniques evolve. Security validation automates this testing so the review becomes continuous and the supporting evidence stays current.
Security validation runs scheduled simulations to see whether security controls actually block and detect real attacks. It turns periodic, assumption-based compliance into continuous, evidence-based assurance, producing scored, time-stamped reports that satisfy the expectations of auditors, the cybersecurity steering committee, and the Authorizing Official, not just at assessment time, but continuously.
The Picus Platform maps attack paths, simulates real-world threats, and proves exploitability across your stack. It validates control effectiveness, prioritizes exploitable exposures, and returns vendor-specific & vendor-neutral mitigation guidance. Every threat is mapped to MITRE ATT&CK, and new threats are added on an ongoing basis, which makes the NCA periodic-review obligations sustainable and audit-ready.
.png?width=161&height=136&name=gartner-logo-2025%201%20(1).png)
