NCA ECC Compliance, Implemented
The Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Authority set the minimum cybersecurity requirements for the entities in scope. We assess where you stand, implement the controls on your infrastructure and prepare the evidence.
The Baseline for Cybersecurity in the Kingdom
The ECC was first issued in 2018 and updated as ECC-2:2024. It is organised into four main domains: cybersecurity governance, cybersecurity defence, cybersecurity resilience, and third-party and cloud computing cybersecurity.
It applies to government entities and their companies, and to private-sector entities that own, operate or host critical national infrastructure. Each entity must comply with all the controls applicable to it, and the NCA encourages other organisations to use the controls as good practice.
We are not an audit firm. Our work is the implementation itself — the same hands-on approach behind more than 300 Aramco compliance certificates.
From Gap Assessment to Evidence
Implementation on your actual environment, documented for review.
Gap assessment
Every applicable control checked against your actual environment, with a clear list of what is missing.
Governance documents
Cybersecurity strategy, policies, procedures and roles written for your organisation, in Arabic and English.
Technical controls
Identity and access, email and network protection, backup, logging and the other defence controls implemented on your systems.
Evidence pack
Evidence collected and organised control by control, ready for self-assessment and review.
Awareness programme
The awareness and training requirement covered with a managed programme for your staff.
Staying compliant
Controls kept active through a maintenance contract, so compliance does not lapse after the project.
Our ECC Process
Scope
We agree which entities, systems and controls are in scope.
Gap assessment
We check every applicable control on your environment and report the gaps.
Remediation plan
A prioritised plan: what to fix, in which order, and who does it.
Implementation
We implement the technical controls and write the governance documents.
Evidence and follow-up
We prepare the evidence pack and support you through assessment and review.
Questions Clients Ask
You May Also Need
ISO 27001 Certification Support
An information security management system built for your size, and support through certification.
Learn more →Security Awareness Training
Managed phishing simulation and training programmes, delivered as a KnowBe4 partner.
Learn more →SACS-210 Certificate Renewal
We update your controls, rebuild the evidence report and attend the audit before your certificate expires.
Learn more →SACS-210 Certificate — Full Guide
The 33 requirements, the certification process, the audit session and validity.
Learn more →Find Out How Far You Are From ECC Compliance
Ask for a gap assessment. We tell you where you stand and what it takes.