What is NCA ECC?
The Saudi National Cybersecurity Authority's Essential Cybersecurity Controls — a 114-control mandatory baseline for in-scope organisations in the Kingdom.
Also known as
NCA ECC — explained.
ECC (Essential Cybersecurity Controls) is the Saudi National Cybersecurity Authority's (NCA) mandatory cybersecurity baseline for in-scope organisations operating in Saudi Arabia. The current version (ECC-2) defines 114 controls across five domains: governance, cybersecurity defence, cybersecurity resilience, third-party cybersecurity, and industrial control systems. Scope includes government entities, critical national infrastructure operators (energy, water, banking, telecoms, transport, healthcare), and their suppliers / contractors. Implementation is mandatory; compliance is verified by NCA assessment. Alongside ECC, NCA publishes the CCC (Critical Systems Cybersecurity Controls) for higher-criticality systems and the OTCC (Operational Technology Cybersecurity Controls) for industrial control. For Zeour deployments in KSA the practical implication is: align to ECC-2 controls, document supplier cybersecurity posture, treat NCA assessment readiness as a baseline deliverable. This is one of several KSA-specific frameworks vendors operating in the Kingdom need to know — alongside PDPL on the data-protection side and SAMA-IT on the banking side.
Zeour solutions that operate on this layer.
Verticals where nca ecc is operationally critical.
Blog posts that go deeper on nca ecc.
Adjacent definitions to read next.
PDPL
Compliance & DataPersonal Data Protection Law — the data-protection regime in Saudi Arabia (and equivalents in the UAE and several Gulf states).
ISO 27001
Compliance & DataThe international standard for Information Security Management Systems (ISMS) — a certifiable framework for managing information-security risk.
Sovereign Deployment
Sovereign DeploymentSoftware that runs entirely inside the operator's perimeter — their hardware, their network, their backups, their keys — with no third-party dependency for continued operation.
NIS2
Compliance & DataThe EU's expanded cybersecurity directive (replacing NIS1) — mandates risk-management, incident reporting, and supply-chain security for thousands of in-scope entities.
CCPA / CPRA
Compliance & DataCalifornia's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.
Cyber Essentials
Compliance & DataThe UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.
Data Subject Access Request (DSAR)
Compliance & DataThe data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.
Explicit Consent
Compliance & DataConsent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.
Talk to a Zeour engineer.
A 30-minute scoping call to walk your operational profile against where nca ecc actually sits in your stack, then a fixed-fee Discovery price by the end of the call.