ECC-2 vs NCNICC-1 vs CCC-2: Which NCA Framework Applies?

Start with the short answer.
If you are a Saudi government entity, or a private company that owns, operates or hosts Critical National Infrastructure (CNI), ECC-2:2024 applies to you.
If you are a private-sector company that is not CNI and you meet the size thresholds, NCNICC-1:2025 is your mandatory baseline. Below those thresholds, adoption is encouraged but not mandated.
If you use or provide cloud services, CCC-2:2024 may apply on top but the test is not simply "do you touch cloud." Provider scope and tenant scope are determined differently, and most scoping errors we see happen here.
These frameworks are not a menu. Scope follows from what your institution is and what it operates, and a large share of organisations in the Kingdom are in scope of two at once.
The scoping test
Question 1: Are you a government entity, or a company owned or controlled by government? → ECC-2:2024. Note that ECC-2 explicitly extends to government entities established outside the Kingdom, along with their affiliated companies and sub-entities. Overseas incorporation is not a carve out.
Question 2: Do you own, operate or host Critical National Infrastructure? → ECC-2:2024, plus CSCC-1:2019 (Critical Systems Cybersecurity Controls) where systems are designated critical.
Question 3: Do you operate OT or ICS environments? → OTCC-1:2022 (Operational Technology Cybersecurity Controls), applied after ECC compliance is established. The old ECC Domain 5 was removed precisely because OT moved here.
Question 4: Neither government nor CNI, but a private-sector entity operating in the Kingdom? → NCNICC-1:2025, subject to the size thresholds below.
Question 5: the cloud question, asked separately. See the CCC section. The answer depends on whether you are a tenant or a provider, and for providers it depends on who your customers are.
ECC-2:2024: the national baseline
The Essential Cybersecurity Controls are the NCA's flagship mandatory framework. ECC-2:2024 replaced ECC-1:2018 in October 2024, restructuring the framework into:
- 4 main domains
- 28 subdomains
- 108 main controls
- 92 sub-controls
The four domains are Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party and Cloud Computing Cybersecurity.
For comparison, ECC-1:2018 ran to 5 main domains, 29 subdomains and 114 controls. The consolidation reduced the count and merged overlapping requirements. It did not relax them.
What changed in the 2024 revision
The Industrial Control Systems domain was removed. OT environments are now addressed through OTCC-1:2022 rather than inside the ECC.
Data-localisation responsibility shifted to the National Data Management Office (NDMO), with CCC-2:2024 updated accordingly. Several areas left the ECC because another national authority now owns them a pattern worth watching, because it means "not in the ECC" no longer means "not regulated."
The Saudization requirement was widened. Under ECC-2:2024, cybersecurity roles must be filled by qualified Saudi nationals not only senior positions, as under the previous version.
That last change is the one foreign-owned entities in the Kingdom most often discover late, usually during a gap assessment rather than during hiring. It is a recruitment lead-time problem disguised as a compliance finding, and lead time is the one thing a remediation plan cannot buy back.
Who it does not bind
If you are a private company with no CNI designation, the ECC does not bind you directly. The NCA encourages adoption as good practice, and Saudi enterprise buyers increasingly demand it in procurement but your binding obligation comes from NCNICC.
NCNICC-1:2025: the private-sector baseline
NCNICC-1:2025 (Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities) is the most consequential recent development for ordinary Saudi businesses. Published in January 2026, it extends binding NCA obligations beyond government and CNI to the wider private sector for the first time.
The framework contains:
- 65 main controls
- across 22 sub-components
- within 3 main components Cybersecurity Governance, Cybersecurity Defense, and Third-Party and Cloud Computing Cybersecurity
- underpinned by 47 sub controls
Class A vs Class B: how to place yourself
Large entities fall into Class A if they have 250 employees or more, or annual revenue above SAR 200 million. Class A entities must implement all 65 main controls, with no exceptions.
Small and medium entities fall into Class B if they have between 6 and 249 employees, or annual revenue between SAR 3 million and SAR 200 million. Class B entities are mandated to implement 26 main controls, concentrated in the Cybersecurity Defense component, while the remaining 39 controls are recommended rather than mandatory.
Entities falling below the Class B thresholds are currently outside mandatory scope, though the NCA encourages voluntary adoption.
Why this table is not the end of the exercise. The thresholds look like a headcount check. In practice, classification is where scoping engagements spend their time, because:
- The tests are disjunctive. A 40 person company with SAR 250m in revenue is Class A.
- Group structures with multiple commercial registrations can produce different classifications per entity, and mixed groups should expect Class A obligations at parent level.
- Headcount and revenue move. A classification that was correct at budget approval may not be correct at assessment.
- Contractors, seconded staff and part-time headcount need a consistent counting basis before the test means anything.
Get the classification wrong upward and you fund 39 controls you did not owe. Get it wrong downward and you fail assessment on 39 controls you did.
Treat Class B as sequencing, not exemption
The 39 "recommended" controls are not optional in any durable sense. Regulator expectation rises with organisational maturity, and recommended controls have a habit of appearing as findings in post incident review at which point the distinction between mandatory and recommended offers very little protection.
CCC-2:2024: the cloud overlay
The Cloud Cybersecurity Controls are a modular extension to the ECC rather than a standalone framework. CCC-2:2024 superseded CCC-1:2020.
The structure:
- 4 main domains, 24 subdomains
- CSP (Cloud Service Provider): 37 main controls, 94 sub-controls
- CST (Cloud Service Tenant): 18 main controls, 26 sub-controls
Scope is determined differently for tenants and providers
This is the single most common scoping error we correct, and it is worth stating precisely.
Tenants (CST). In scope are government agencies in the Kingdom — including ministries, authorities, establishments and their companies and sub-entities, inside or outside the Kingdom — together with private-sector entities owning, operating or hosting CNI, where any of them currently use or plan to use cloud services. In short: CST scope tracks ECC scope.
Providers (CSP). Scope does not follow from your own regulatory status. It follows from who your customers are. A provider serving in-scope CSTs is in scope. A provider serving only individuals, or only private-sector entities that do not own, operate or host CNI, and that does not serve in-scope CSTs, falls outside mandatory scope with the NCA encouraging voluntary adoption.
The practical consequence: a Saudi SaaS company with a purely non-CNI private-sector client base is not automatically inside CCC. Guides that reduce the cloud question to "do you provide cloud services?" will hand that company a 37-control programme it does not owe.
Equally, note that the NCA addresses providers both within and outside ECC scope. Being outside the ECC does not place a provider outside the CCC if its customer base brings it in.
Reading the control identifiers
Every control is assigned to one role, encoded in the identifier:
1-3-P-1-1 is a provider control and 1-3-T-1-1 is the tenant equivalent. Confirm which side of the relationship you are assessing before scoping this single question decides most of the workload.
Applicable controls also scale across four cloud cybersecurity levels, driven by data classification and service criticality. Not every control applies at every level.
On data residency: the 2024 revision changed the position on strict in-Kingdom residency, and localisation responsibility now sits with the NDMO. Verify the current text against both authorities before making architecture decisions. This is not a question to settle from a summary including this one.
Three scoping mistakes we see repeatedly
1. Assuming NCA means government only. Defensible before NCNICC-1:2025. Now the fastest route to an unbudgeted compliance programme.
2. Running two isolated gap assessments. Institutions subject to both ECC-2:2024 and NCNICC-1:2025 — or ECC and CCC — should run one unified assessment. The frameworks share substantial control overlap, particularly across governance and third-party domains. Duplicate audit cycles waste budget and produce inconsistent evidence for controls that are substantially the same.
3. Scoping CCC without deciding your role. Many organisations are tenant and provider at once consuming SaaS while hosting a service for clients. Where both apply, both tracks apply, and they are assessed separately.
How compliance is assessed
Scope determines cost, but assessment determines exposure. The NCA evaluates through entity self-assessment, periodic reporting via its compliance tooling, and field audit visits, and it holds enforcement powers including remediation orders and, in regulated sectors, licence conditions.
Penalty exposure varies by framework, sector and the nature of the finding. Confirm your specific exposure with Saudi-qualified counsel rather than from any summary including this one.
Confirm your scope before you budget
Scoping determines the size of your programme, the evidence assessors will demand, and whether your board is funding the right controls. The three questions that most often change a budget by an order of magnitude:
- Are you Class A or Class B under NCNICC and does that hold at parent level across every commercial registration?
- On the cloud side, are you tenant, provider, or both and if provider, does your client base actually bring you into scope?
- Where do ECC, NCNICC and CCC overlap, so one body of evidence serves all three?
B&P GRC runs framework scoping and entity classification as a fixed scope engagement: we confirm which NCA frameworks bind your institution, classify you under NCNICC across your full group structure, map control overlap into a single evidence set, and hand you a prioritised control inventory with owners assigned.


