NCA ECC Compliance Checklist: 20 Controls to Check First

A practical NCA ECC compliance checklist: governance, asset and access management, patching, logging, backup, incident response, third parties and cloud.

· Thoughts House

Key takeaways

  • This checklist turns the NCA Essential Cybersecurity Controls (ECC 2-2024) into 20 practical checks you can review with your IT team.
  • It follows the ECC domains: governance, defense, resilience, third-party and cloud security, and industrial control systems where relevant.
  • Organizations using cloud, critical systems or operational technology should also review the NCA's related control sets, such as the CCC, CSCC and OTCC.

Our guide to the NCA Essential Cybersecurity Controls explains what the ECC are and who they apply to. This article is the hands-on companion: a checklist you can go through with your IT team to see where you stand. Use the official ECC document as the final reference.

Governance

  • 1. A cybersecurity strategy and policies are approved by management.
  • 2. Cybersecurity roles are defined, with a responsible person or function.
  • 3. Cybersecurity risks are assessed and reviewed regularly.
  • 4. Cybersecurity requirements are included in IT projects and changes.
  • 5. Staff receive regular security awareness training.

Defense

  • 6. An up-to-date inventory of hardware, software and information assets exists.
  • 7. Access follows least privilege, with multi-factor authentication for remote and privileged access.
  • 8. Leavers' and unused accounts are removed promptly.
  • 9. Systems and network devices are hardened and patched on a schedule.
  • 10. Endpoint protection (ideally EDR) runs on all laptops, desktops and servers.
  • 11. Email is protected against phishing, spoofing and malicious attachments.
  • 12. The network is segmented and protected by firewalls with reviewed rules.
  • 13. Sensitive data is classified and encrypted where required.
  • 14. Backups are made, protected from ransomware and restore-tested.
  • 15. Vulnerability scans run regularly and findings are fixed.
  • 16. Security logs are collected centrally and monitored.
  • 17. An incident response plan exists and has been tested.

Resilience

  • 18. Cybersecurity is part of business continuity and disaster recovery plans.

Third parties and cloud

  • 19. Contracts with suppliers and service providers include cybersecurity requirements.
  • 20. Cloud services are assessed for security and data hosting location before use.

If your organization uses industrial control systems or operational technology, the ECC add requirements for those environments, and the OTCC go further.

How to use the checklist

Mark each item as in place, partial or missing, and note the evidence (a policy, a report, a screenshot). Then rank the gaps by risk. Missing MFA, unpatched systems and untested backups are usually the first items to fix.

How Thoughts House can help

We help organizations across Saudi Arabia run ECC gap assessments and implement the technical controls: firewalls, EDR, email security, MFA, central logging and protected backups, with documentation you can use as evidence.

Frequently asked questions

Is this checklist enough to prove ECC compliance?

No. It is a starting point to find gaps quickly. Compliance is measured against the full official ECC document and, for regulated entities, through the NCA's assessment process.

What other NCA control sets might apply?

Depending on your environment, the NCA also publishes control sets such as the Cloud Cybersecurity Controls (CCC), Critical Systems Cybersecurity Controls (CSCC) and Operational Technology Cybersecurity Controls (OTCC). Check the NCA website for the ones that apply to you.

Which ECC controls should we fix first?

Usually multi-factor authentication, patching, endpoint protection, backups protected from ransomware and central logging, because they reduce the most common attack paths.

Get In Touch

Get In Touch

Ready to secure and optimize your IT infrastructure? Let's start a conversation.

We use your details only to reply to your enquiry. See our Privacy Policy.