Saudi National Cybersecurity Authority mark.

The Essential Cybersecurity Controls are NCA's foundational cybersecurity requirements for entities within their defined scope. NCA identifies ECC 2-2024 as the updated reference for protecting information and technology assets. See the NCA ECC publication page.

Use in a programme

Confirm the organisation's applicable scope and edition, then assess the requirements and any relevant NCA extensions. Assign owners, identify gaps and retain evidence that supports the recorded implementation state.

Cloud, critical systems, data, operational technology and other specialist controls may extend the baseline for particular activities. Review their relationship to ECC before treating any one catalogue as the complete requirement set.

Use in CSFaaS

The reviewed library still labels its entry NCA ECC-1:2018 - EN. It must not be described as the updated 2024 edition. Compare the required baseline with the available reference and resolve the difference before a formal assessment.

Record the edition in the framework's description and keep additions or transition work traceable. Use policy links and evidence to organise the assessment, and use the publisher's authoritative materials to validate its scope.