Saudi National Cybersecurity Authority mark.

NCA's OTCC–1:2022 extends ECC for operational technology and industrial control systems. It sets cybersecurity requirements intended to protect these systems against threats with potentially significant operational consequences. See the NCA OTCC publication page.

Use in a programme

Define the industrial processes, control systems, dependencies and responsible operators within scope. Coordinate cybersecurity decisions with safety, availability, engineering and change-management requirements.

Assess the controls in the actual operating environment. A measure suitable for an ordinary office system may require a different implementation or maintenance approach in an industrial setting.

Use in CSFaaS

The reviewed library lists NCA OTCC-1:2022 - EN. Verify the source and structure before beginning the assessment. Document the relevant systems and dependencies, assign owners and connect policies and evidence to the assessed requirements.

Review operational evidence and specialist findings alongside the framework scores. An internal implementation label does not replace technical validation in the OT environment.