NCA ECC vs SACS-210: What is the Difference?
If you run a business in Saudi Arabia and have started researching cybersecurity compliance, you’ve likely run into two acronyms that sound similar in purpose. They come from entirely different authorities: the National Cybersecurity Authority’s Essential Cybersecurity Controls (NCA ECC), and Saudi Aramco’s SACS-002 vendor certification standard. Confusing the two — or assuming compliance with one automatically satisfies the other — is one of the most common and costly mistakes Saudi businesses make when scoping a compliance project.

Two Different Authorities, Two Different Purposes
**NCA ECC** is issued by the National Cybersecurity Authority https://nca.gov.sa, Saudi Arabia’s national regulator for cybersecurity. The ECC framework is a national-level baseline of cybersecurity requirements. It applies broadly across government entities and their supply chains, as well as organizations operating critical national infrastructure. It is a national regulatory standard, not tied to any single client relationship.
**SACS-002** is issued by Saudi Aramco specifically, as part of its third-party vendor cybersecurity requirements — the technical standard underlying the CCC (Cybersecurity Compliance Certification) program. Unlike NCA ECC, SACS-002 is not a national regulation; it is a contractual requirement Aramco places on the vendors, contractors, and service providers it does business with. If you don’t do business with Aramco, SACS-002 does not independently apply to you. If you do, it applies regardless of your organization’s size or the value of the specific contract in question.

Why This Distinction Actually Matters
The practical consequence: satisfying one framework does not automatically satisfy the other, even though there’s meaningful overlap in the security domains both care about. Access control, network security, endpoint protection, incident response, and data protection appear in some form in both.
A business that has only ever pursued NCA ECC alignment (perhaps because it works with a government entity) cannot assume it is CCC-ready for an Aramco vendor relationship. A dedicated gap assessment against SACS-002’s specific requirements is still needed. The reverse is equally true: CCC certification does not automatically demonstrate NCA ECC alignment if your organization separately needs to satisfy that national framework for a different client or regulatory relationship.
Where the Two Frameworks Overlap
Despite coming from different authorities, both frameworks converge on a similar set of foundational security domains, because both are ultimately drawing on the same broader body of cybersecurity practice:
– **Governance and risk management** — documented policies, defined ownership of security responsibilities, and a risk assessment process
– **Access control** — including multi-factor authentication and the principle of least privilege
– **Network security** — firewalls, segmentation, and monitoring
– **Endpoint protection** — antivirus/EDR and patch management
– **Data protection and backup** — encryption, retention, and recovery capability
– **Incident response** — a documented plan, not just an informal understanding of “what we’d do”
– **Security awareness training** — for staff, not just technical controls
Because of this overlap, an organization that builds its security program around either framework is doing most of the foundational work needed for the other. But “most” is not “all” — the specific evidence, documentation format, and audit process differ meaningfully between an NCA ECC self-assessment or regulatory review and an Aramco-managed CCC audit.

The Audit Process Differs Significantly
This is where organizations most often get surprised. NCA ECC compliance is typically demonstrated through self-assessment against the published control set, sometimes validated by an accredited third party depending on the entity’s classification and sector. The Aramco CCC process, by contrast, is a formal, Aramco-managed vendor certification. Evidence is compiled and submitted through Aramco’s CCC portal, and the assessment itself is conducted by Aramco-authorized audit firms — not by the vendor’s own security consultancy. That consultancy’s role is to prepare the client’s environment, documentation, and evidence package ahead of the independent audit, not to conduct the certification decision itself.
Understanding this division of responsibility matters when you’re evaluating any consultancy’s role in your CCC journey: a consultant helps you get ready and pass the audit; the certification decision itself sits with Aramco and its authorized auditors.

Which One Applies to You?
– **Only pursuing government or critical-infrastructure-adjacent business** → NCA ECC alignment is likely your primary requirement.
– **Doing business with Saudi Aramco as a vendor, contractor, or service provider, regardless of contract size** → SACS-002 / CCC certification is a contractual requirement, not optional.
– **Both** → common for larger Saudi contractors and service providers operating across multiple client relationships, in which case a security program should be built against the combined, stricter requirements of both frameworks rather than treating them as interchangeable.

Building a Security Program That Serves Both
The most efficient approach for an organization that may need to satisfy either or both frameworks over time isn’t to build two parallel compliance programs. It’s to build one genuinely strong security foundation across the overlapping domains above, then map that foundation against whichever specific framework’s evidence and documentation requirements the current engagement demands. Done this way, most of the technical and procedural work carries over between frameworks; only the specific evidence packaging, audit process, and a handful of framework-specific requirements need dedicated attention each time.

—
*SirajTech supports Saudi organizations pursuing NCA ECC alignment, Aramco CCC (SACS-002/SACS-210) certification, or both — building a single security foundation and mapping it to whichever framework your client or regulatory relationship requires.* (contact)