NCA ECC and Saudi Cyber Security Compliance Training

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

Our NCA ECC training prepares Saudi organisations to implement and evidence the National Cybersecurity Authority’s Essential Cybersecurity Controls, along with the NCA’s cloud, data, operational technology and private sector controls and the Personal Data Protection Law (PDPL). SSC delivers practical courses for government entities, critical national infrastructure operators, cloud providers and private companies, live online or on-site in the Kingdom.

Saudi professionals at laptops in a modern Riyadh training room with skyscrapers at dusk, representing NCA ECC training in Saudi Arabia
Saudi Arabia’s cyber security controls are mandatory for many entities and evidence is expected on request.

NCA ECC training and related courses

CourseTypical durationBest for
NCA ECC-2:2024 practitioner3 daysCybersecurity departments of government, CNI and affiliated entities
NCA Cloud Cybersecurity Controls (CCC)2 daysCloud service providers and cloud tenants
NCA OTCC for industrial environments2 daysOperators of industrial control systems in the Kingdom
NCA controls for non-CNI private sector entities1 dayPrivate companies preparing for the NCNICC
Saudi PDPL practitioner2 daysData protection officers, legal, privacy and IT teams
NCA compliance internal auditor3 daysInternal audit and second-line teams assessing NCA compliance

NCA Essential Cybersecurity Controls (ECC-2:2024)

The Essential Cybersecurity Controls are Saudi Arabia’s national minimum baseline, issued by the NCA. ECC-2:2024 replaced ECC-1:2018 and is organised into four domains, Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party and Cloud Computing Cybersecurity, with 28 subdomains, 108 main controls and 92 subcontrols. It applies to government entities and their affiliated companies, and to private entities that own, operate or host critical national infrastructure. Compliance must be continuous and evidenced.

NCA ECC-2:2024 practitioner

Typical duration: 3 days. Who it is for: cybersecurity, IT and risk teams responsible for ECC compliance.

  • The structure of ECC-2:2024 and what changed from ECC-1:2018
  • The governance domain: strategy, cybersecurity department, policies, roles, risk management and compliance reviews
  • Defense controls for assets, identity and access, systems, networks, mobile devices, data, cryptography, backup, vulnerabilities, penetration testing, logging, incidents and physical security
  • Third-party and cloud controls, and cybersecurity in business continuity
  • Building an evidence pack and a remediation plan the NCA can review

You will be able to: assess your entity against ECC-2:2024 and lead the work to close gaps.

Cloud, data and OT controls

Team reviewing cloud security architecture on a large screen with cloud and server icons, representing NCA Cloud Cybersecurity Controls training
Cloud providers and tenants each carry their own NCA control obligations.
  • Cloud Cybersecurity Controls (CCC-2:2024): separate control sets for cloud service providers and for cloud service tenants, built on the ECC, with data classification levels that drive which controls apply.
  • Operational Technology Cybersecurity Controls (OTCC): controls for industrial control systems, which build on ECC compliance and suit energy, utilities, petrochemical and manufacturing operators.
  • Data Cybersecurity Controls (DCC) and Critical Systems Cybersecurity Controls (CSCC): additional NCA controls for classified data and for systems designated as critical, covered on request.
  • Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC): adopted by the NCA in December 2025 for private companies that are not critical infrastructure, with requirements that depend on company size.

Saudi Personal Data Protection Law (PDPL)

Data protection officer at a laptop with a shield and document icon, desert city skyline at sunset, representing Saudi PDPL training
The PDPL applies to organisations inside and outside the Kingdom that process Saudi residents’ personal data.

The PDPL is supervised by the Saudi Data and Artificial Intelligence Authority (SDAIA) and applies to any organisation processing the personal data of individuals in Saudi Arabia, including organisations outside the Kingdom. Our PDPL course covers lawful bases for processing, records of processing activities, data subject rights and response deadlines, cross-border transfer controls, and the 72-hour breach notification process.

Financial institutions can also add a module on the Saudi Central Bank (SAMA) cyber security framework, and ICT providers a module on the Communications, Space and Technology Commission (CST) Cybersecurity Regulatory Framework.

How the NCA and PDPL training is delivered

  • Live online. Instructor-led virtual classes over Microsoft Teams or Zoom, with breakout exercises, shared workbooks and the option to split longer courses into half-day sessions across a week or two.
  • On-site at your premises. Private training for your team at your office, delivered by a consultant who can use your own policies, systems and examples in the exercises.
  • Private and tailored. Every course can be run for a single organisation, with case studies drawn from your sector and the depth adjusted to your team’s experience.

For Gulf clients, sessions can be supported with bilingual English and Arabic materials on request.

What participants receive

  • A course workbook and the slides used in class
  • Reusable templates and checklists, such as audit checklists, risk registers and report formats, depending on the course
  • A case study pack and practice questions
  • A certificate of completion from Security Solution Consultants

Certificates and accredited exams

Every participant who completes a course receives a certificate of completion from Security Solution Consultants. Lead Auditor and Lead Implementer courses can include an accredited certification exam through our accredited training partner, for standards where the partner offers one. Your quote confirms the exam body, exam format and certificate for each course, so there are no surprises on the day.

Why train with SSC

  • Taught by practitioners. Our trainers are working consultants and auditors who implement and assess NCA controls and build NCA compliance modules into GRCLens, so examples come from real engagements rather than slides.
  • We hold ourselves to the same standard. SSC is certified to ISO/IEC 27001 and follows a Secure by Design approach. See our Trust Centre.
  • Hands-on with real tools. Exercises can use GRCLens, the GRC platform built by SSC, so participants practise with risk registers, control libraries and evidence the way they will at work.
  • Training that connects to delivery. If your team needs help after the course, the same people can support implementation, internal audits and certification readiness.

Related: the GRCLens NCA ECC module, CCC, PDPL and the Saudi Arabia framework pack. See all training courses.

Frequently asked questions

The second edition of Saudi Arabia's Essential Cybersecurity Controls, issued by the National Cybersecurity Authority. It has four domains, 28 subdomains, 108 main controls and 92 subcontrols, and replaced ECC-1:2018.

Government entities and their affiliated companies inside and outside the Kingdom, and private entities that own, operate or host critical national infrastructure. Other private companies are covered by the NCA's non-CNI controls.

Yes. The CCC course covers both the cloud service provider and the cloud service tenant control sets, and how data classification decides which controls apply.

Yes. It applies to the processing of personal data of individuals in Saudi Arabia, including by organisations based abroad.

Sessions are delivered in English and can be supported with bilingual English and Arabic materials on request.

Plan NCA and PDPL training for your team

Tell us how many people need training, which courses interest you, and whether you prefer live online or on-site delivery. We will come back with a tailored proposal and quote.

Prefer email? Write to info@secsolutionshub.com