Saudi National Cybersecurity Authority mark.

NCA's Critical Systems Cybersecurity Controls supplement the Essential Cybersecurity Controls for national critical systems. The publisher identifies CSCC–1:2019, organised around governance, defence, resilience, and third-party/cloud cybersecurity. See the NCA CSCC page.

Use in a programme

Determine which systems fall within the applicable critical-system scope. Document their business functions, dependencies and the consequences of disruption. Review the additional controls alongside the underlying ECC requirements.

Keep the system boundary explicit: a sector label alone does not identify every system, dependency or control that needs assessment. Assign people who can validate both operational needs and the supporting evidence.

Use in CSFaaS

The reviewed catalogue lists NCA CSCC-1:2019 - EN. Check the imported structure against the publisher's reference and the scope your organisation has adopted.

Use system records, risk demands, policies and evidence to support the assessment. A completed framework link set is a record of mapped policy coverage, not an independent finding that the critical system meets every applicable requirement.