Saudi NCA ECC-2:2024 Audit
NCA ECC-2:2024 audit — baseline cybersecurity for all organisations in KSA.
Full NCA Essential Cybersecurity Controls v2 (ECC-2:2024) audit — applicability scoping, control-by-control assessment across governance, defence, resilience and third-party / cloud domains. Designed for government entities, critical national infrastructure operators and private-sector organisations in the Kingdom of Saudi Arabia.
- NCA Essential Cybersecurity Controls v2 (ECC-2:2024)
- NCA Critical Systems Cybersecurity Controls (CSCC)
- NCA Cloud Cybersecurity Controls (CCC)
- NCA Telework Cybersecurity Controls
- Saudi PDPL (Personal Data Protection Law)
- SAMA CSF overlay (financial sector)
- ISO 27001:2022 (mapped)
- NIST CSF (mapped)
What are NCA Essential Cybersecurity Controls?
Saudi Arabia's National Cybersecurity Authority Essential Cybersecurity Controls (ECC) are mandatory for government and critical-sector organizations, spanning governance, defence, resilience, and third-party domains. Macksofy runs ECC gap assessments and implementation for entities operating in Saudi Arabia.
NCA ECC-2 is leverage, not paperwork.
The National Cybersecurity Authority's Essential Cybersecurity Controls v2 (ECC-2:2024) is the baseline cybersecurity standard for any organisation operating in the Kingdom of Saudi Arabia — government, critical national infrastructure and private sector. NCA performs compliance assessments and references ECC compliance in its national cybersecurity reporting; sector regulators (SAMA, CMA, CITC, Ministry of Health) layer their own controls on top. Macksofy's NCA ECC-2 audit walks the four domains end-to-end and produces the assessment artefacts NCA samples first.
- Saudi government entities (ministries, authorities, government-owned companies)
- Critical national infrastructure operators (energy, water, transport, finance, health)
- Private-sector organisations operating in KSA (any size)
- Cloud and digital-platform providers serving KSA customers
- Suppliers and managed-service providers to NCA-regulated entities
- Multinationals with Saudi operations or KSA data-residency commitments
Aligned to the regulations that matter.
How we run a NCA ECC-2 engagement.
Interactive walkthrough — every phase clickable, every activity documented, every artefact regulator-ready.
1 · Applicability + scoping
- 01Sector classification + NCA scope test
- 02Critical-system identification (CSCC overlay)
- 03Cloud / telework overlay assessment
What your NCA ECC-2 engagement puts on the table.
- NCA ECC-2 applicability + scoping memo
- Control-by-control compliance register
- Critical-system + cloud overlay risk pack
- Incident-response + tabletop drill report
- Third-party cybersecurity review
- NCA-format submission pack
- Annual recertification plan + closure tracker
NCA ECC-2 audit + CSCC overlay on critical systems
Outcome: Closed all priority-1 gaps in one cycle; NCA assessment cleared with no follow-up actions on critical systems
ECC-2 + Cloud Cybersecurity Controls (CCC) overlay
Outcome: Cloud-overlay evidence pack accepted by two NCA-regulated customer assessments without remediation
The shape of a NCA ECC-2 engagement.
Every number below is grounded in how Macksofy actually runs the engagement — not aspirational marketing copy.
What we actually examine.
Each pillar is a distinct workstream inside the engagement — scoped, evidenced, and signed off independently before the audit pack is assembled.
- Applicability & scoping3 pts
- Governance domain3 pts
- Defence domain3 pts
- Resilience domain3 pts
- Third-party & cloud3 pts
- NCA submission pack3 pts
ECC-2 baseline applies broadly — CSCC and CCC overlays apply selectively. Clean scoping prevents over-engineering.
- Sector + criticality classification
- Critical-system + cloud-overlay scoping
- Telework-control applicability
Cybersecurity strategy, risk management and human-resources controls — the spine of ECC-2.
- Cybersecurity strategy + governance
- Cyber-risk management framework
- HR + awareness controls
Asset, identity, network and endpoint defence walked end-to-end with technical evidence.
- Asset + identity-and-access management
- Network, endpoint + email defence
- Cryptography + secure data handling
Backup, recovery, log management and incident response — the controls that decide breach outcomes.
- Backup + recovery evidence
- Event-log management + retention
- Incident-response + tabletop drill
Supplier and cloud-provider controls under ECC-2 + the CCC overlay where cloud is used.
- Third-party cybersecurity controls
- Cloud Cybersecurity Controls (CCC) overlay
- Contractual + exit-plan evidence
Artefacts assembled exactly the way NCA assessments consume them.
- Control-statement to evidence map
- Compliance-level heatmap
- Assessor Q&A walk-through
From kick-off to regulator-ready report.
The horizontal flow below shows the typical week-by-week shape of a NCA ECC-2 engagement. Click any station for detail in the methodology section above.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
NCA ECC-2 — what compliance leads ask before signing.
Dubai DESC ISR Audit
DESC ISR readiness for Dubai government entities and sector-specific operators.
Learn moreSAMA Cyber Security Framework Audit
End-to-end SAMA CSF audit — control assessment, maturity scoring, submission pack.
Learn moreADHICS Compliance Audit
Full ADHICS readiness for Abu Dhabi healthcare providers, payers and Malaffi participants.
Learn moreNCA ECC-2 evidence starts with hands-on testing.
A clean NCA ECC-2 report rests on real technical assurance. These Macksofy assessments generate the vulnerability, penetration and control-effectiveness evidence your auditor expects to see.
Penetration Testing
Find what attackers will. Before they do.
Explore serviceVulnerability Assessment & Penetration Testing (VAPT)
VAPT done properly — not a scan with a cover page.
Explore serviceWeb Application Security Testing
Test web apps the way attackers (and bug bounty hunters) do.
Explore serviceMacksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
