ECC-2, Two Years In: What the First Assessment Cycle Exposed

The NCA published ECC-2 in October 2024, superseding ECC-1:2018. Two years and an assessment cycle in, the change list is settled. The question now is which changes have practical effect. If you spent six years building toward ECC-1 you're not starting over, but the gap between the two editions is where assessments are now won and lost.

Here are the five changes that matter most for Saudi entities in ECC scope, and the one most organizations are still getting wrong.

1. Control count: 114 → 108

ECC-2 consolidates and tightens. Of ECC-1's 114 main controls, 108 remain in ECC-2 in substance. Five moved to other instruments (four ICS controls to OTCC, and the data-ownership and privacy minimums toward the SDAIA/NDMO track), and control 1-7-1 was deleted outright, its obligation now embedded in every control's legislative-requirements phrasing. The rest have been clarified to remove overlap with other NCA standards (CCC, CSCC, DCC, TCC, OTCC). If your existing control matrix maps every control 1:1 to ECC-1, you'll need to re-map. Most of the changes are housekeeping; the consolidation is mostly welcome.

2. Saudization expanded to all cybersecurity roles

ECC-1's control 1-2-2 already required the cybersecurity function head plus supervisory and critical positions to be full-time Saudi professionals. ECC-2 keeps the same control number and widens it. Under ECC-2, this applies to every cybersecurity role: SOC analysts, GRC specialists, security architects, the lot. For entities that have been relying on expatriate consultants or contractors to fill day-to-day positions, this is the biggest operational change in the release. It rewrites the staffing model.

I'd start by mapping which positions you currently have that ECC-2 now requires to be Saudi-occupied, and whether you have the pipeline to fill them. A common pattern across the market: organizations that had foreign senior analysts but Saudi managers are now inverted, the seniors stay, the day-to-day analyst seats become the recruitment problem.

3. Data localization moved out of ECC

ECC-1 had explicit in-country hosting language. ECC-2 removes the general data-hosting control but keeps one localization rule: control 4-1-3-2 still requires cybersecurity managed-service centers that monitor and operate with remote access to sit fully inside Saudi Arabia, which matters if you are evaluating an offshore SOC or MSSP. Beyond that, removal doesn't mean data localization is now optional. It means the authoritative source for data localization is now the National Data Management Office (NDMO) at SDAIA, not ECC. If a vendor is telling you "ECC-2 removed the hosting requirement, we can move you to a foreign region," they're reading one document and ignoring the one that actually governs your data. Check the NDMO regulations for your data classification before any cross-border move.

4. Scope extended to Saudi government presence outside the Kingdom

ECC-2 explicitly covers Saudi government entities established inside and outside KSA. Diplomatic missions, foreign offices, and entities wholly and directly owned by covered government agencies are the safe reading. The text sets no ownership threshold, so do not assume every portfolio company with some Saudi state investment is automatically in scope; confirm whether the entity is actually affiliated with a covered agency. If you support a KSA government entity operating abroad, your ECC obligation just expanded.

5. Tighter integration with other NCA standards

ECC-2 now directs you to specific NCA standards (CSCC for critical systems, CCC for cloud, DCC for data cybersecurity, OTCC for operational technology) instead of restating those rules inside ECC. The benefit: less duplication, fewer interpretive disagreements between an ECC assessor and a CCC assessor on the same control. The cost: you need to read the dependent standards as a set, not as an ECC-only exercise.

The first ninety days of an ECC-2 program

If you completed an ECC-1 assessment within the last two years, here's the order I'd suggest:

  1. Map your existing 114-control matrix to the new 108. Most controls survive in substance; some merge and some are reworded. Note which of your existing evidence packs you can carry forward.
  2. Audit your cybersecurity staffing roster against the expanded Saudization rule. Identify the seats you'll need to refill and the timeline.
  3. Re-read the NDMO data residency rules for your classification tier. Document the lawful basis for any data that lives outside KSA today.
  4. Re-check the boundary between ECC-2 and CCC if you're in scope of both. Where ECC used to cover something CCC now governs, your evidence needs to move with the rule.
  5. Plan the next assessment against ECC-2, not ECC-1. Auditors will not be sympathetic to "we built this against the old version."

If you completed nothing under ECC-1, the practical advice is unchanged: foundation first. Asset inventory. Ownership. Then build the policy and control stack around the new 108 with the framework consolidation in mind from day one.

ECC-2 tightens rather than rewrites. The organizations that handled ECC-1 well will find it manageable; the ones that treated ECC-1 as a paperwork exercise will discover that consolidating overlap exposes the gaps the duplication was hiding.