Skip to content
Live12+ production solutions40+ clients deployeddirect + partner
Glossary · Compliance & Data

What is NCA ECC?

The Saudi National Cybersecurity Authority's Essential Cybersecurity Controls — a 114-control mandatory baseline for in-scope organisations in the Kingdom.

Also known as

saudi nca eccessential cybersecurity controlsksa ecc
Definition

NCA ECC — explained.

ECC (Essential Cybersecurity Controls) is the Saudi National Cybersecurity Authority's (NCA) mandatory cybersecurity baseline for in-scope organisations operating in Saudi Arabia. The current version (ECC-2) defines 114 controls across five domains: governance, cybersecurity defence, cybersecurity resilience, third-party cybersecurity, and industrial control systems. Scope includes government entities, critical national infrastructure operators (energy, water, banking, telecoms, transport, healthcare), and their suppliers / contractors. Implementation is mandatory; compliance is verified by NCA assessment. Alongside ECC, NCA publishes the CCC (Critical Systems Cybersecurity Controls) for higher-criticality systems and the OTCC (Operational Technology Cybersecurity Controls) for industrial control. For Zeour deployments in KSA the practical implication is: align to ECC-2 controls, document supplier cybersecurity posture, treat NCA assessment readiness as a baseline deliverable. This is one of several KSA-specific frameworks vendors operating in the Kingdom need to know — alongside PDPL on the data-protection side and SAMA-IT on the banking side.

Solutions where nca ecc applies

Zeour solutions that operate on this layer.

Enterprise Dev

enterprise · development · services

Zeour Enterprise Development — we design, build, and operate corporate-grade software for organizations that take their software seriously. Custom web platforms, mobile apps, kiosk fleets, embedded/hardware-coupled systems, real-time services, AI-augmented workflows, system integrations (CRM / ERP / HRIS / payment gateways / BI / national health systems / lab analyzers / payment terminals / card readers / GPIO barriers), legacy modernization, cloud migration, on-premise deployments, DevOps + CI/CD, security hardening, and 24/7 support. Every other solution on this site — MediCare Clinic Management, Smart Parking, GLARUS Queue Management, Wayfinding, Digital Signage, Visitor Management, Online Appointment, Self-Service Kiosks, Customer Feedback — is something our team designed, built, and operates today. The same team is available for your bespoke engagement.

See the solution

DT Consultation

digital · transformation · consultation

Zeour Digital Transformation Consultation helps companies digitalise their services and operations through three pillars: process automation (workflow engines, RPA, integration platforms that retire repetitive manual work), self-service technologies (customer + employee portals, kiosks, mobile apps, WhatsApp / SMS / IVR channels), and sovereign on-premises AI (open-weight large language models, vision models, voice models, RAG pipelines, and AI-augmented workflows that run entirely on the operator's own hardware — patient data, customer data, and classified material never leave the perimeter). The service stack is the full path from problem to outcome: consulting (digital-maturity assessment, transformation roadmap, business-case modelling, vendor selection), implementation (the build itself, often delivered in partnership with our Enterprise Development team), AI model deployment (open-weight LLMs, fine-tuning, embedding pipelines, on-prem inference infrastructure, GPU sizing), customisation (tailoring deployed AI and automation to your specific operations — prompts, RAG corpora, workflow templates), and training (role-based curricula for executives, operators, and end users, with operations playbooks, runbooks, and train-the-trainer programmes that make your team self-sufficient). The same team that ships our production AI assistant in MediCare (7-mode OpenAI Responses API, evidence-based prompts, audit-logged interactions) is what you engage.

See the solution

MediCare Clinic

medicare · clinic · management · system

Zeour MediCare — the multilingual on-premise clinic and EMR management system for small-to-mid healthcare practices. Covers patients (records, allergies, conditions, medications, body diagrams), appointments + visits with SOAP notes, prescriptions with drug-interaction checks, lab orders + samples + results, billing + payments + invoicing, inventory, expenses, referrals, medical certificates, refill requests, patient communications, telemedicine (WebRTC), an AI clinical assistant (OpenAI-powered with 7 modes), a patient self-service portal, and a full role-based access model across Admin, Doctor, Reception, and Lab Tech roles. Engineered multilingual — (with full RTL) as the production baseline, extensible to any locale — and runs locally on a single server.

See the solution

Smart Parking

smart · parking · management · system

Zeour Smart Parking — a complete on-premise smart parking platform: RFID card lifecycle (issue, top-up, transfer, lost replacement, card-tap exit), staff card-management console, admin operations center with pricing profiles per car size, no-login customer self-service portal, real-time monitoring (live activity, transactions, alerts), an Android kiosk fleet that drives RFID card readers and barrier gates directly with a hardware watchdog, and offline-validated sovereign licensing that ties each deployment to the operator's own server. Single-tenant deployment on the operator's own infrastructure; ships engineered multilingual with full RTL as a production baseline — configurable for any locale and currency per engagement.

See the solution
Related terms

Adjacent definitions to read next.

PDPL

Compliance & Data

Personal Data Protection Law — the data-protection regime in Saudi Arabia (and equivalents in the UAE and several Gulf states).

ISO 27001

Compliance & Data

The international standard for Information Security Management Systems (ISMS) — a certifiable framework for managing information-security risk.

Sovereign Deployment

Sovereign Deployment

Software that runs entirely inside the operator's perimeter — their hardware, their network, their backups, their keys — with no third-party dependency for continued operation.

NIS2

Compliance & Data

The EU's expanded cybersecurity directive (replacing NIS1) — mandates risk-management, incident reporting, and supply-chain security for thousands of in-scope entities.

CCPA / CPRA

Compliance & Data

California's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.

Cyber Essentials

Compliance & Data

The UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.

Data Subject Access Request (DSAR)

Compliance & Data

The data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.

Explicit Consent

Compliance & Data

Consent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.

Want to discuss nca ecc for your operation?

Talk to a Zeour engineer.

A 30-minute scoping call to walk your operational profile against where nca ecc actually sits in your stack, then a fixed-fee Discovery price by the end of the call.