Penetration testing in the Saudi Essential Cybersecurity Controls lives at subdomain 2-11 "Penetration Testing", under Main Domain 2 "Cybersecurity Defense" — the same number in both ECC-1:2018 and ECC-2:2024. The control requires testing scoped to all externally provided services accessible via the Internet (infrastructure, websites, web and mobile applications, email, remote access), conducted "periodically". That word matters: the base ECC does not fix an interval, so describing it as an "annual" requirement is an interpretation, not the control text. A six-month interval applies only to critical systems under the CSCC, and an annual interval only to telework under the TCC. The ECC is mandatory for government entities, their affiliates, and private-sector owners or operators of Critical National Infrastructure; it is encouraged for everyone else. For Saudi banks, the ECC runs in parallel with SAMA, not instead of it.
// 01 Which NCA ECC control covers penetration testing?
Penetration testing is subdomain 2-11 "Penetration Testing", sitting under Main Domain 2, "Cybersecurity Defense." In the control hierarchy it falls immediately after Vulnerability Management (2-10) and before Event Logs and Monitoring Management (2-12). The number is stable: it is 2-11 in the original ECC-1:2018 and remains 2-11 in the updated ECC-2:2024.
The control's stated objective in ECC-2:2024 is "to assess and test the efficiency of the entity's cybersecurity defense capabilities through simulation of actual cyber-attack methods and technologies to discover unknown weaknesses that may lead to cyber penetration of the entity, as per the relevant legislative and regulatory requirements." The emphasis on simulating actual attack methods is deliberate — the NCA is asking for adversarial testing, not a vulnerability scan relabelled as a penetration test.
2-11-1: Cybersecurity requirements for penetration testing within the entity shall be identified, documented, and approved.
2-11-2: Cybersecurity requirements for penetration testing shall be implemented.
2-11-3: Requirements shall include, as a minimum: (2-11-3-1) scope covering all externally provided services via the Internet and their technical components — infrastructure, websites, web applications, smartphone and tablet applications, email, and remote access; and (2-11-3-2) conducting penetration tests periodically.
2-11-4: The implementation of these requirements shall be reviewed periodically.
// 02 Who must comply with the ECC?
The ECC is mandatory for a defined set and encouraged for everyone else. The mandatory population is Saudi government organizations — ministries, authorities and establishments — together with their affiliated companies and entities, and private-sector organizations that own, operate or host Critical National Infrastructure (CNI). ECC-2:2024 explicitly extends the reach of government-affiliated entities to those operating inside and outside the Kingdom. For all other organizations, the NCA "strongly encourages" adoption but does not compel it.
One nuance trips people up: within the mandatory population, not every control applies automatically. The ECC's Statement of Applicability makes control applicability depend on the technologies actually in use — the cloud subdomain applies only if you use cloud, and so on. Penetration testing under 2-11, however, applies wherever there are externally provided services to test, which is effectively every digitally active entity. Contractors are not named in a standalone clause; they are reached through the Third-Party Cybersecurity domain, which pushes ECC-equivalent obligations down the supply chain.
| Organization type | ECC status | Note |
|---|---|---|
| Government entities & affiliates | Mandatory | Including affiliated entities operating outside the Kingdom (ECC-2) |
| Private-sector CNI owners/operators/hosts | Mandatory | Energy, finance, health, telecom and other designated sectors |
| Contractors to the above | Via third-party domain | Inherited through Third-Party Cybersecurity controls, not a standalone clause |
| All other Saudi organizations | Encouraged | NCA "strongly encourages" adoption as good practice |
// 03 How often must you conduct penetration testing under the ECC?
The honest answer is the one most guides get wrong: the ECC says "periodically," and does not set a fixed interval. Sub-control 2-11-3-2 reads simply "conducting penetration tests periodically" in both ECC-1:2018 and ECC-2:2024. Vendors routinely paraphrase this as "annually" because an annual cadence is sensible practice, but it is an interpretation rather than a requirement written into the base ECC. If you are documenting compliance, quote "periodically" and then state the interval you have set and justified in your own approved requirements under 2-11-1.
Fixed intervals do exist in the Saudi framework family — but in the sector-specific control sets, not the ECC. This distinction matters for scoping and for defending your programme to an assessor.
| Control set | Applies to | Penetration testing interval |
|---|---|---|
| ECC-1:2018 / ECC-2:2024 (2-11-3-2) | General entities, external Internet services | "Periodically" — no fixed interval |
| CSCC-1:2019 (2-10-2) | Critical systems | At least every 6 months |
| TCC-1:2021 | Telework systems | At least once a year |
| OTCC-1:2022 (2-10) | Operational technology / ICS | Per the OTCC control set |
The CSCC figure is the one to remember. Its sub-control 2-10-2 states that "with reference to ECC subcontrol 2-11-3-2, penetration tests must be conducted on critical systems at least once every six months." So if any of your systems are classified as critical, the operative cadence is six-monthly, inherited from the CSCC, not the ECC.
// 04 What must an ECC penetration test cover?
Scope is defined by control 2-11-3-1: all externally provided services accessible via the Internet, and their technical components. ECC-2:2024 words this as "all externally provided services (via the Internet) and their technical components, including infrastructure, websites, web applications, smartphone and tablet applications, email, and remote access." The 2024 wording is broader than the 2018 phrase "Internet-facing services" — it captures services you provide externally even where a third party operates part of the stack.
In practice that scope statement maps onto a familiar external attack surface: public web applications and their APIs, the mobile apps that consume them, authentication and remote-access gateways, email infrastructure, and the perimeter that fronts all of it. What it does not explicitly reach in the base ECC is the internal network and internal-only systems — those are picked up by other domains and, for critical systems, by the CSCC (whose scope covers internal and external services alike). A defensible ECC test plan starts from the external estate the control names, then extends inward where your own risk assessment and any critical-system classification demand it.
// 05 What changed from ECC-1:2018 to ECC-2:2024?
ECC-2:2024 is a consolidation, not a rewrite. The structure tightened from 5 main domains, 29 subdomains and 114 controls to 4 main domains, 28 subdomains, 108 main controls and 92 sub-controls. The most visible change is the removal of the old Domain 5, "Industrial Control Systems Cybersecurity" — OT and ICS now have their own dedicated control set in the OTCC-1:2022. The four remaining domains are Governance, Cybersecurity Defense, Resilience, and Third-Party and Cloud Computing.
5 domains, 114 controls
Included a standalone Industrial Control Systems domain. Penetration testing at 2-11 with scope worded as "Internet-facing services" and "mobile apps."
4 domains, 108 controls
ICS domain removed (now OTCC). Penetration testing stays at 2-11; scope reworded to "all externally provided services (via the Internet)" and "smartphone and tablet applications"; objective references "actual cyber-attack methods."
For penetration testing specifically, the headline is continuity: the control number, the "periodically" frequency and the external-services scope are all preserved. If your programme was aligned to ECC-1's 2-11, the migration to ECC-2 is a wording refresh and a scope clarification, not a new obligation.
// 06 How does the ECC relate to CSCC, OTCC, CCC and SAMA?
The ECC is the baseline; the other NCA control sets are specialised layers on top of it, and SAMA sits alongside the whole family for the financial sector. Understanding which set governs which system is the difference between one efficient testing programme and several redundant ones.
Essential Cybersecurity Controls
The floor for all in-scope entities. External-services penetration testing, conducted periodically.
Critical Systems Cybersecurity Controls
Adds a six-monthly penetration testing interval and internal + external scope for systems classified as critical.
Operational Technology Cybersecurity Controls
Governs industrial and OT environments, which ECC-2 no longer covers directly — see our OT/ICS penetration testing service.
Cloud Cybersecurity Controls
A modular add-on. Cloud providers and tenants comply with the ECC first, then the extra CCC controls; penetration testing is inherited from ECC 2-11 rather than renumbered.
For Saudi banks, the key point is that the NCA framework and the SAMA Cyber Security Framework operate in parallel. A bank whose systems are designated Critical National Infrastructure, or which consumes cloud under the CCC, must satisfy the NCA controls and SAMA — they are not alternatives. The efficient path is to map controls once against both regulators and reuse a single evidence set. We cover the banking-sector view in the companion SAMA CSF penetration testing guide.
// 07 How is ECC compliance assessed?
Compliance is assessed through self-assessment against the published controls using the NCA's compliance tool, backed by NCA audits and assurance reviews. Entities report their implementation status and maturity level for each control, and remediate gaps within agreed timeframes; for government bodies and CNI operators, sustained non-compliance can escalate into formal directives. The ECC is positioned as the operational backbone of the Kingdom's national cybersecurity strategy under Vision 2030, which is why the assessment posture is meaningfully stricter for entities protecting government, energy, finance and health infrastructure.
For penetration testing specifically, an assessor is looking for three things: an approved set of penetration testing requirements under 2-11-1, evidence that testing was actually performed against the externally provided services in scope, and a periodic-review record under 2-11-4. A test report on its own does not demonstrate the governance the control asks for — the documented, approved requirements and the review cadence are as important as the test itself.
// 08 Frequently asked questions
Which NCA ECC control covers penetration testing?
Subdomain 2-11 "Penetration Testing," under Main Domain 2 "Cybersecurity Defense." The number is 2-11 in both ECC-1:2018 and ECC-2:2024.
How often does the ECC require penetration testing?
The control says "periodically" and does not fix an interval. A six-month interval applies to critical systems under the CSCC; an annual interval applies to telework under the TCC. Describing the base ECC as "annual" is an interpretation, not the control text.
What must the test cover?
Under 2-11-3-1, all externally provided services via the Internet and their technical components — infrastructure, websites, web applications, smartphone and tablet applications, email and remote access.
Who must comply?
Government entities and their affiliates, and private-sector owners, operators or hosts of Critical National Infrastructure. Encouraged for all other Saudi organizations.
What changed in ECC-2:2024?
Structure reduced to 4 domains and 108 controls; the Industrial Control Systems domain moved to the OTCC. Penetration testing stayed at 2-11 with reworded scope and objective, and the "periodically" frequency was retained.
Does an ECC test satisfy SAMA?
No. The NCA ECC and SAMA Cyber Security Framework run in parallel. Banks classified as CNI, or using cloud under the CCC, are subject to both. Map once, reuse the evidence.
// 09 Sources
- NCA Essential Cybersecurity Controls, ECC-1:2018 — subdomain 2-11 "Penetration Testing" (control text quoted verbatim). National Cybersecurity Authority.
- NCA Essential Cybersecurity Controls, ECC-2:2024 — subdomain 2-11; structure of 4 domains / 28 subdomains / 108 main controls.
- NCA Critical Systems Cybersecurity Controls, CSCC-1:2019 — control 2-10-2 (six-monthly testing of critical systems).
- NCA Operational Technology Cybersecurity Controls, OTCC-1:2022 — control 2-10 Penetration Testing.
- NCA Cloud Cybersecurity Controls (CCC-1:2020) and Telework Cybersecurity Controls (TCC-1:2021).
- Saudi Central Bank (SAMA) Cyber Security Framework — for the parallel financial-sector obligation.
Control references reflect the NCA control documents published on nca.gov.sa. Confirm the current control text for your entity classification before relying on it for a compliance submission.