TrustPoint

NCA Essential Cybersecurity Controls

The baseline cybersecurity control set issued by the National Cybersecurity Authority in Saudi Arabia, and one of the two framework packs that ship in the TrustPoint core library.

Publisher
National Cybersecurity Authority, Saudi Arabia
Version
ECC-1:2018
Country
Saudi Arabia
Availability
Included in the platform

What the ECC is

The Essential Cybersecurity Controls are a baseline control set published by the National Cybersecurity Authority (NCA) of the Kingdom of Saudi Arabia. They set a minimum standard of cybersecurity practice rather than an aspirational maturity target, which is why they read as concrete and operational rather than principles-based.

The control set is organised hierarchically. Top-level domains cover the broad areas of a cybersecurity programme, each domain breaks into subdomains, and each subdomain carries the individual controls an organization is assessed against. Controls are referenced by a dotted numeric path, which is why you will see references written in the form of a domain, subdomain and control number.

The NCA has also published sector-specific and subject-specific control sets alongside the ECC. Where those apply to you, they sit on top of the essential baseline rather than replacing it.

Who it applies to

The ECC is directed at government entities in the Kingdom and at organizations operating critical national infrastructure, along with their contractors and service providers. Many private-sector organizations adopt it voluntarily, either because a government customer expects it or because it is the clearest baseline available in the region.

If you supply services into a Saudi government entity or a critical infrastructure operator, expect the control set to reach you contractually even where it does not reach you by regulation. Confirm your specific obligation with the NCA or with your own legal counsel rather than inferring it from a vendor page.

What compliance actually requires

In operational terms, an ECC programme asks you to do four things and prove each of them. Define the scope you are assessing. Determine, control by control, whether the required practice is implemented. Hold evidence that it is implemented, dated and attributable. And show that gaps are being closed on a plan with owners rather than noted and forgotten.

The proving is where most programmes struggle. A control marked implemented with nothing attached to it is an assertion. The same control with a dated configuration export, an approval record and a named owner is a finding you can defend, and it is the difference between a smooth assessment and a long one.

The second recurring difficulty is scope. A control assessed against "the organization" rarely survives scrutiny, because the answer is different for the core banking estate than it is for a marketing website. Assessing against a defined perimeter is what makes the answer meaningful.

How TrustPoint supports it

The ECC pack ships in the core library, so it is available without a Marketplace download and works the same way on an air-gapped installation as it does in SaaS.

You attach the framework to a perimeter defined in Governance, then work the assessment requirement by requirement, recording status, score, notes and evidence on each one. Evidence is held once in the managed evidence store and reused wherever it applies, so a quarterly access review is uploaded once rather than four times.

Maturity is reported as a perimeters-by-frameworks heatmap, and every gap the assessment produces becomes a work item on a kanban roadmap with an owner, exportable to CSV or Excel for the people who will not log in.

Where continuous control monitoring is configured, control evidence refreshes itself from the security tools you already run, and each automated evidence item carries the provenance an auditor will ask for: which connector, which collection run, what time.

Reporting is audience-tuned. The board template, the manager template, the technical template and the regulator template read from the same assessment, so the version the board sees and the version the assessor sees cannot drift apart.

What it maps to, and what that saves

The NCA ECC to ISO/IEC 27001:2022 mapping set ships in the core library. Where a control you have assessed under the ECC has mapped ISO 27001 controls, the engine surfaces them as suggestions, shows each recorded relationship (equal, subset, superset, intersecting or related) with a strength score, and waits for a person to accept it.

That last part matters more than the automation. An assessor who is told that an ISO control passed because an ECC control passed will ask who decided the two were the same. Because the relationship is recorded and the acceptance is attributable, the answer is a person and a date rather than a shrug.

For organizations running the ECC alongside ISO 27001 and a financial-sector framework, the overlap is substantial, and answering the shared requirements once is usually the single largest efficiency available in the programme.

Common questions

Does TrustPoint ship the ECC control set itself?

The ECC framework pack is in the core library, so the structure and references are there when you activate it against a perimeter. Always work from the authoritative text published by the NCA as the definitive source for control wording.

Can we run the ECC on an air-gapped installation?

Yes. The pack is in the core library rather than behind a Marketplace download, and where you later need updated content, air-gapped sites install it by signed manual upload. Continuous control monitoring connectors also run inside the platform on your own network, so nothing about the assessment requires outbound connectivity.

How does the ECC relate to ISO 27001?

They overlap substantially but are not interchangeable. ISO 27001 certifies a management system; the ECC prescribes a baseline of practice. The mapping set in the core library links ECC controls to ISO 27001 Annex A controls and records each relationship, so the difference stays visible.

What happens when the NCA revises the control set?

Frameworks in TrustPoint are versioned. When a new version of a framework is added to the library, a guided upgrade previews what was renamed, merged, split, introduced or retired, carries existing assessments forward, and can be rolled back within 24 hours.

Is TrustPoint certified or endorsed by the NCA?

No, and we would not claim it. TrustPoint is software that helps you run an assessment against the control set and hold the evidence for it. Certification and endorsement are matters for the authority, not for a vendor.

Commonly mapped to

See TrustPoint assessed against NCA ECC.

A 45-minute working session focused on the frameworks and requirements that matter to your organization.