NCA ECC Compliance Platform

NCA ECC compliance, structured and continuous

Operationalize the National Cybersecurity Authority Essential Cybersecurity Controls with pre-loaded domains, evidence collection, and NCA-ready compliance reporting.

Compliance postureLive
Control coverage
94%
Open risks
7
Evidence items
1,284
Audit findings
2
Implemented94%
In progress58%
Evidence freshness82%
  • ECC coverage and maturity across domains
  • Open risks and corrective actions by owner
  • Incident timelines with NCA notification status
01The problem

The NCA ECC challenge

The NCA expects government and critical entities to demonstrate continuous adherence to ECC, with related controls such as CSCC and DCC layered on top, plus mandatory incident reporting.

  • Multiple ECC domains with hundreds of controls and sub-controls
  • Overlapping requirements with CSCC, DCC, and sector regulations
  • Annual compliance evaluations with NCA
  • Incident reporting within strict NCA timelines
  • Third-party and cloud governance under NCA controls
  • Maturity expectations beyond minimum compliance
02The approach

A national-grade ECC operating model

Waaqi pre-loads NCA ECC and related controls so your program is structured, continuously evidenced, and NCA-ready.

01

NCA-native library

ECC, CSCC, and DCC controls preloaded with implementation guidance.

02

Continuous compliance

Evidence and maturity update as controls run, not once a year.

03

NCA-ready packages

Generate compliance evaluations, incident reports, and audit packages on demand.

03Capabilities

What you get inside Waaqi

Every module works from one control library, one evidence store, and one risk register.

Full ECC Library

All ECC domains and sub-controls preloaded with guidance and evidence prompts.

Risk Management

Risk register tailored to national and critical infrastructure context, linked to ECC.

Maturity Tracking

Track current and target maturity across ECC domains with roadmap planning.

Internal Audit

Plan and run NCA-aligned internal audits with findings, CAPA, and reviews.

Policy Automation

Auto-generate cybersecurity policies aligned to ECC and related NCA frameworks.

Incident Management

Workflow for NCA incident reporting with timelines and post-incident reviews.

Third-Party Governance

Vendor and cloud risk aligned to NCA cloud cybersecurity controls.

Multi-Framework Mapping

Reuse ECC controls for ISO 27001, NIST CSF, SAMA CSF, and KSA PDPL.

04Workflow

From control definition to audit-ready evidence

Each step is owned, dated, and traceable, so nothing depends on a spreadsheet or a single person.

  1. Step 1

    Set scope

    Define entity scope, applicable ECC tiers, and related NCA frameworks.

  2. Step 2

    Assign owners

    Route controls to business, IT, and security owners with SLAs.

  3. Step 3

    Collect evidence

    Connectors and tasks keep evidence current across systems and vendors.

  4. Step 4

    Report to NCA

    Generate compliance evaluations, incident notifications, and audit packages.

05Audit readiness

NCA evaluations, on demand

Provide NCA reviewers a complete, structured package with evidence for every ECC sub-control and related framework.

  • Compliance evaluation exports with supporting evidence
  • Maturity rationale and history per domain
  • Incident register with NCA notifications
  • Third-party and cloud assurance records
  • Internal audit findings and CAPA progress
06For leadership

Board level answers without a fire drill

Boards, CISOs, and risk committees get the same numbers the compliance team works from.

National security alignment

Demonstrate cybersecurity maturity expected of strategic and critical entities.

Lower regulatory exposure

Provable continuous compliance reduces NCA enforcement risk.

Resilience by design

ECC operated as a living program improves real resilience, not just paper compliance.

07FAQ

Questions we get asked

What is NCA ECC?

NCA ECC, the Essential Cybersecurity Controls, is the mandatory baseline cybersecurity framework issued by the National Cybersecurity Authority of the Kingdom of Saudi Arabia. It defines the minimum cybersecurity controls every in-scope national organization must implement, monitor, and demonstrate.

Who must comply with NCA ECC in Saudi Arabia?

All Saudi government entities, their subsidiaries, organizations operating critical national infrastructure (CNI), and any entity processing sensitive national information must comply with NCA ECC. Private-sector organizations bidding on government contracts are increasingly required to demonstrate ECC alignment as well.

What is the difference between ECC, CSCC, and DCC?

ECC is the baseline framework for all in-scope entities. CSCC (Critical Systems Cybersecurity Controls) adds requirements for systems classified as critical. DCC (Data Cybersecurity Controls) focuses on protecting data across its lifecycle. Waaqi maps controls across ECC, CSCC, and DCC so a single program satisfies all three.

How is NCA ECC structured?

ECC is organized into five main domains: Cybersecurity Governance, Cybersecurity Defence, Cybersecurity Resilience, Third-Party and Cloud Computing Cybersecurity, and Industrial Control Systems Cybersecurity. Each domain contains main controls and sub-controls with implementation guidance.

How does the NCA audit ECC compliance?

The NCA conducts compliance assessments and requires regular self-assessments through its compliance tooling. Entities must demonstrate evidence for every applicable control and report incidents within prescribed timelines. Waaqi keeps the evidence current and the maturity scoring up to date.

What is the relationship between NCA ECC and SAMA CSF?

NCA ECC is the national baseline; SAMA CSF is the sector-specific framework for the Saudi financial sector. Financial institutions typically need both, plus PCI DSS for payments. Waaqi's cross-mapping engine ensures a single control implementation satisfies ECC, SAMA CSF, ISO 27001, and PCI DSS where they overlap.

Does NCA ECC apply to cloud and third-party services?

Yes. ECC has a dedicated domain for third-party and cloud cybersecurity, and the Cloud Cybersecurity Controls (CCC) extend these requirements. Waaqi tracks cloud providers, third-party attestations, and data residency commitments alongside internal controls.

How does Waaqi help with NCA ECC compliance?

Waaqi pre-loads the full NCA ECC control library plus CSCC, DCC, and CCC overlays, assigns owners, automates evidence collection and maturity scoring, and generates NCA-ready compliance and incident reports, making ECC a continuous program rather than a periodic exercise.

NCA ECC compliance: the Saudi cybersecurity baseline

The Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Authority (NCA) of Saudi Arabia define the minimum mandatory cybersecurity baseline for every in-scope national organization. They are non-negotiable for government entities, critical national infrastructure operators, and a growing list of private-sector organizations engaged in regulated activities or government contracting.

ECC is structured around five domains, Cybersecurity Governance, Cybersecurity Defence, Cybersecurity Resilience, Third-Party and Cloud Computing Cybersecurity, and Industrial Control Systems Cybersecurity, and is reinforced by complementary frameworks: CSCC for critical systems, DCC for data, CCC for cloud, and OTCC for operational technology. Together they form the most prescriptive national cybersecurity regime in the GCC.

Compliance is verified through the NCA's compliance tool, periodic self-assessments, on-site reviews, and incident reporting. Falling short carries regulatory, contractual, and reputational consequences, particularly for Vision 2030 programs and government suppliers.

Operationalizing NCA ECC, CSCC, DCC, and CCC with Waaqi

Most Saudi organizations don't face only ECC. Critical systems trigger CSCC. Sensitive datasets bring DCC into scope. Cloud adoption activates CCC. OT environments add OTCC. Maintaining each as a separate spreadsheet program is unsustainable. Waaqi consolidates all NCA frameworks into a single, navigable control library with cross-mapped requirements and unified evidence.

Each control is assigned an owner with a service-level commitment, evidence is collected through integrations or recurring tasks, and the maturity model defined by the NCA is updated continuously rather than reconstructed before an audit. Risk treatment, exception management, and management reviews are first-class workflows tied directly to the affected controls.

Incident response follows NCA-aligned timelines, with classification, regulator notification templates, evidence capture, and post-incident learning baked in, so reporting obligations are met without scrambling across teams.

NCA ECC alongside SAMA CSF, ISO 27001, and PCI DSS

Saudi financial institutions typically need NCA ECC, SAMA CSF, PCI DSS for payments, and often ISO 27001 for international stakeholders. Healthcare, energy, telecoms, and government suppliers face similar combinations. Waaqi maps NCA ECC to SAMA CSF, ISO 27001 Annex A, NIST CSF, PCI DSS, and KSA PDPL, so a single implementation of each control satisfies every framework it overlaps with.

This unified model dramatically reduces effort, eliminates contradictory evidence, and lets CISOs report cybersecurity posture across regimes with one dashboard rather than several disconnected reports.

NCA audits, maturity scoring, and continuous evidence

NCA audits and self-assessments expect not just policy documents but live evidence: configurations, logs, attestations, training records, vendor reviews, exception approvals, and incident artifacts. Waaqi continuously gathers and freshness-stamps this evidence, scores maturity against the NCA model, and produces audit packages on demand.

The auditor workspace gives the NCA assessor a scoped, read-only view of controls, evidence, risk treatment, and incidents, making the audit shorter, less disruptive, and dramatically more likely to pass on the first attempt.

Operationalize NCA ECC

See how Waaqi runs ECC, CSCC, and DCC as one continuous program.