CompliverseAI
National cyber · Saudi Arabia

NCA ECC

NCA Essential Cybersecurity Controls

The National Cybersecurity Authority's baseline controls for protecting Saudi Arabia's information and technology assets, structured into five domains.

5
domains
29
subdomains
Mandatory
for CNI
NCA ECC
Cybersecurity governance
Cybersecurity defence
Cybersecurity resilience
Third-party & cloud
ICS cybersecurity
ECC domains

Why it matters

Mandatory for government bodies and critical national infrastructure in the Kingdom, with subdomains that map cleanly to ISO 27001.

Who it's for

Government organisations, critical national infrastructure and the entities that operate on their behalf.

The journey

How you get to NCA ECC

  1. 1ScopeAssets in the KSA
  2. 2Gap assessmentAgainst the ECC
  3. 3RemediateClose the gaps
  4. 4ImplementAll five domains
  5. 5Compliance reviewEvaluate posture
  6. 6MaintainContinuous compliance
On Compliverse

NCA ECC, worked in the platform

NCA ECC · Assessment
Statement-level status
64% ready
Control areaAI evidence
Cybersecurity governanceCybersecurity policy
Cybersecurity defenceSuggested
Cybersecurity resilienceCreate
Third-party & cloudSuggested

AI recommends evidence for 3 open controls, and flags what is still missing.

Create from standard template
PolicyAssessmentCharter
+Cybersecurity policy+Asset register+Compliance report

Get the evidence you need

The AI recommends which evidence answers each NCA ECC control, ready to confirm.

See what's missing

Gaps and missing artifacts surface on their own, not the week of the audit.

Create from templates

Spin up policies, assessments and charters from standard templates, then tailor them to your scope.

Collected once, reused

One artifact satisfies this framework and every other it maps to.

Get NCA ECC-ready on your own stack.

Demos are scoped to your frameworks. Pick a slot and we'll run NCA ECC live.