Framework B.10 · Saudi NCA

NCA ECC - Essential Cybersecurity Controls and penetration testing.

Saudi Arabia's National Cybersecurity Authority (NCA) Essential Cybersecurity Controls require periodic penetration testing under domain 2, with the Critical Systems Controls (CSCC) raising that to every six months. CyberFortify's network and web application testing produces evidence mapped to the exact ECC and CSCC control.

Maintainer: National Cybersecurity Authority (KSA) Version: ECC (with CSCC for critical systems) Pen testing: Control 2-11
2-11
Pen testing control
Periodic
ECC baseline
6 months
CSCC critical systems
Mapped
Report to control
NCA ECC: Domain 2 Cybersecurity Defence · Control 2-11 Penetration Testing · Periodic Testing · CSCC 6-month for Critical Systems · Remediate & Retest · Report Mapped to Control NCA ECC: Domain 2 Cybersecurity Defence · Control 2-11 Penetration Testing · Periodic Testing · CSCC 6-month for Critical Systems · Remediate & Retest · Report Mapped to Control
// Executive summary

The NCA Essential Cybersecurity Controls (ECC) require in-scope Saudi organisations to conduct periodic penetration testing (control 2-11, in domain 2 - Cybersecurity Defence). The stricter Critical Systems Cybersecurity Controls (CSCC) require testing of critical systems at least every six months. CyberFortify maps each finding to the relevant control, remediates and retests, and delivers a report the NCA assessor accepts.

// 01 What the NCA ECC is

// DefinitionNCA ECC

The Essential Cybersecurity Controls issued by Saudi Arabia's National Cybersecurity Authority - the national baseline for cybersecurity. The ECC is organised into domains covering governance, defence, resilience, third-party and cloud security, structured as main controls and sub-controls.

Domain 2, Cybersecurity Defence, contains the vulnerability management and penetration testing controls (commonly referenced as 2-11), requiring periodic, planned testing with findings addressed.

The ECC sits at the centre of Saudi Arabia's cybersecurity regime under Vision 2030, and the NCA has issued complementary controls for critical systems, cloud, telework and data. For the practitioner view of the testing obligation, see our NCA ECC penetration testing requirements guide and the broader VAPT in Saudi Arabia overview.

// 02 The penetration testing controls

2-11ECC

Periodic penetration testing

In-scope systems must undergo periodic, planned penetration testing with findings assessed and addressed. Our manual-led testing satisfies the intent.

CSCC6-month

Critical systems every 6 months

The Critical Systems Cybersecurity Controls raise the cadence for critical systems to at least twice a year.

2-xVuln mgmt

Vulnerability management

Domain 2 also covers vulnerability management, which testing feeds - see our vulnerability assessment service.

ReportMapping

Mapped to the control

Findings and coverage mapped to the ECC/CSCC control so the assessor sees the requirement satisfied.

// 03 Who is in scope

The ECC applies broadly to Saudi government organisations and their subsidiaries, and to private-sector organisations that own, operate or host critical national infrastructure or sensitive systems. Many other organisations adopt the ECC as the national baseline or are required to by their sector regulator - and financial entities also answer to SAMA. The CSCC applies specifically to systems classified as critical. In practice most medium and large Saudi organisations either fall directly under the ECC or align to it. Personal data adds the Saudi PDPL, and operational technology the NCA's OTCC.

The NCA assessor wants to see the penetration testing control satisfied with evidence - a documented, mapped report, not just a claim that testing happened. We design ECC and CSCC engagements to produce exactly that, at the right six-month cadence for critical systems.

CyberFortify NCA-facing reporting

// 04 Cadence & timing

Under the ECC the expectation is periodic testing, justified by risk; under the CSCC it is at least every six months for critical systems, plus after significant change. Organisations run this as a recurring programme, booking ahead of each cycle so findings can be remediated and retested before reporting. A typical engagement is one to three weeks of active testing (about four to six weeks total). Map it alongside SAMA and the wider region using the GCC compliance calendar.

// 05 Frequently asked questions

Do the NCA ECC require penetration testing?

Yes. The ECC require in-scope organisations to conduct periodic penetration testing under the domain 2 (Cybersecurity Defence) controls, commonly referenced as 2-11, with testing planned, conducted and findings addressed. For critical systems, the separate CSCC require penetration testing at least once every six months.

Who must comply with the ECC?

Saudi government organisations and their subsidiaries, and private-sector organisations that own, operate or host critical national infrastructure or sensitive systems. Many others adopt it as the national baseline or are required to by their sector regulator. The CSCC applies specifically to critical systems. Most medium and large Saudi organisations fall under or align to the ECC.

What is the difference between the ECC and CSCC?

The ECC are the baseline controls requiring periodic penetration testing among many controls. The CSCC are an additional, stricter set for systems classified as critical, raising the bar - including penetration testing at least every six months rather than the ECC's periodic expectation. Organisations with critical systems must satisfy both.

How does CyberFortify map a test to the ECC?

We scope to the systems in ECC or CSCC scope and deliver a report mapping each finding and the overall coverage to the relevant control, so the NCA assessor sees the penetration testing control satisfied. Findings are remediated and retested, and reporting reflects the six-month cadence for critical systems.

Ready for an NCA ECC-aligned engagement?

Schedule a 30-minute scoping call. We'll scope your ECC or CSCC systems, map the report to the exact control, and deliver on the right cadence - accepted first time.

Schedule scoping call → Back to CyberFortify home →