The NCA Essential Cybersecurity Controls (ECC) require in-scope Saudi organisations to conduct periodic penetration testing (control 2-11, in domain 2 - Cybersecurity Defence). The stricter Critical Systems Cybersecurity Controls (CSCC) require testing of critical systems at least every six months. CyberFortify maps each finding to the relevant control, remediates and retests, and delivers a report the NCA assessor accepts.
// 01 What the NCA ECC is
The Essential Cybersecurity Controls issued by Saudi Arabia's National Cybersecurity Authority - the national baseline for cybersecurity. The ECC is organised into domains covering governance, defence, resilience, third-party and cloud security, structured as main controls and sub-controls.
Domain 2, Cybersecurity Defence, contains the vulnerability management and penetration testing controls (commonly referenced as 2-11), requiring periodic, planned testing with findings addressed.
The ECC sits at the centre of Saudi Arabia's cybersecurity regime under Vision 2030, and the NCA has issued complementary controls for critical systems, cloud, telework and data. For the practitioner view of the testing obligation, see our NCA ECC penetration testing requirements guide and the broader VAPT in Saudi Arabia overview.
// 02 The penetration testing controls
Periodic penetration testing
In-scope systems must undergo periodic, planned penetration testing with findings assessed and addressed. Our manual-led testing satisfies the intent.
Critical systems every 6 months
The Critical Systems Cybersecurity Controls raise the cadence for critical systems to at least twice a year.
Vulnerability management
Domain 2 also covers vulnerability management, which testing feeds - see our vulnerability assessment service.
Mapped to the control
Findings and coverage mapped to the ECC/CSCC control so the assessor sees the requirement satisfied.
// 03 Who is in scope
The ECC applies broadly to Saudi government organisations and their subsidiaries, and to private-sector organisations that own, operate or host critical national infrastructure or sensitive systems. Many other organisations adopt the ECC as the national baseline or are required to by their sector regulator - and financial entities also answer to SAMA. The CSCC applies specifically to systems classified as critical. In practice most medium and large Saudi organisations either fall directly under the ECC or align to it. Personal data adds the Saudi PDPL, and operational technology the NCA's OTCC.
The NCA assessor wants to see the penetration testing control satisfied with evidence - a documented, mapped report, not just a claim that testing happened. We design ECC and CSCC engagements to produce exactly that, at the right six-month cadence for critical systems.
CyberFortify NCA-facing reporting// 04 Cadence & timing
Under the ECC the expectation is periodic testing, justified by risk; under the CSCC it is at least every six months for critical systems, plus after significant change. Organisations run this as a recurring programme, booking ahead of each cycle so findings can be remediated and retested before reporting. A typical engagement is one to three weeks of active testing (about four to six weeks total). Map it alongside SAMA and the wider region using the GCC compliance calendar.
// 05 Frequently asked questions
Do the NCA ECC require penetration testing?
Yes. The ECC require in-scope organisations to conduct periodic penetration testing under the domain 2 (Cybersecurity Defence) controls, commonly referenced as 2-11, with testing planned, conducted and findings addressed. For critical systems, the separate CSCC require penetration testing at least once every six months.
Who must comply with the ECC?
Saudi government organisations and their subsidiaries, and private-sector organisations that own, operate or host critical national infrastructure or sensitive systems. Many others adopt it as the national baseline or are required to by their sector regulator. The CSCC applies specifically to critical systems. Most medium and large Saudi organisations fall under or align to the ECC.
What is the difference between the ECC and CSCC?
The ECC are the baseline controls requiring periodic penetration testing among many controls. The CSCC are an additional, stricter set for systems classified as critical, raising the bar - including penetration testing at least every six months rather than the ECC's periodic expectation. Organisations with critical systems must satisfy both.
How does CyberFortify map a test to the ECC?
We scope to the systems in ECC or CSCC scope and deliver a report mapping each finding and the overall coverage to the relevant control, so the NCA assessor sees the penetration testing control satisfied. Findings are remediated and retested, and reporting reflects the six-month cadence for critical systems.