Resources - Blog

NCA Essential Cybersecurity Controls: An Identity Guide for Saudi Arabia

The Kernel Editorial Team
August 17, 2026

The Essential CybersecurityControls, published by Saudi Arabia's National Cybersecurity Authority (NCA),set a mandatory minimum cybersecurity baseline for government entities, their supply chains, and critical private sector organisations in the Kingdom. The current version, ECC-2:2024, is structured around four domains, 28 subdomains, and 108 main controls, with 92 further sub controls beneath them.

What changed from ECC-1

The original ECC, published in2018, was organised around five domains. ECC-2:2024 restructured the frame work into four, with a significantly expanded set of controls underneath. Organisations that achieved compliance under the earlier version cannot assume that work still covers them; the control set and its structure genuinely changed.

One of the more consequential2026 developments is a Saudization requirement within the updated framework:cybersecurity positions within in-scope organisations must now be filled by full-time, qualified Saudi nationals. For organisations already stretched thin on cybersecurity headcount, this raises the practical importance of tools and platforms that reduce the operational burden on the security team that remains, rather than assuming an ever-growing specialist headcount is available to absorb it.

Who has to comply

The ECC baseline is mandatory for government entities and their supply chains, alongside critical private sector organisations. In practice, that reaches well beyond government agencies themselves: any private organisation supplying or supporting government systems is likely in scope, whether or not it thinks of itself as a critical infrastructure provider.

What the controls actually cover

The four domains span both governance and technical territory: cybersecurity strategy and how it is documented and approved at leadership level, the establishment of a proper cybersecurity management function within the organisation, and the operational and technical controls that follow from both. It is not a framework that can be satisfied with a single technical purchase; it expects strategy, governance, and technical controls to align.

A meaningful share of the technical controls land in identity and access territory: who can authenticate into which systems, how privileged access is controlled and audited, and how certificate-based and hardware-backed authentication methods are deployed where the risk warrants it. This is where most organisations preparing for an ECC assessment find the real gap between documented policy and what is actually enforced day to day.

Where organisations typically fall short

Two patterns come up repeatedly.First, privileged and administrative access frequently lacks the session-level audit trail an assessor expects to see, particularly where third party contractors or outsourced IT teams are involved. Second, authentication methodsthat were adequate five years ago, passwords with SMS codes, no longer hold up against the credential-based attacks now common across the region, and assessors are increasingly aware of that gap.

How The Kernel supports NCA-aligned deployments

The Kernel supports Saudi organisations with regional identity and compliance expertise. CyberHeed maps evidence to NCA ECC and other supported frameworks, while Pointsharp providesMFA, certificate-based authentication and identity governance for the mix of cloud and legacy systems many enterprises operate.

This work sits within TheKernel's broader Identity Management and Strong Authentication capability, alongside the compliance mapping the team already applies to NESA and SAMA engagements across the region.

Not sure how your current setup measures up against ECC-2:2024?

Talk to our team | Explore our vendor portfolio

Want these in your inbox?

We publish practical, vendor-neutral writing on identity, authentication, and security operations in the region. No spam, no hard sell.

First name
Last name
Email
Thank you for subscribe.
Oops! Something went wrong while submitting the form.