Saudi NCA ECC penetration testing requirements — controls 2-10 and 2-11 and the CSCC frequencies for critical systems
Short definition
A control-by-control guide to vulnerability management and penetration testing in the Saudi NCA Essential Cybersecurity Controls (ECC-2:2024) and the Critical Systems Cybersecurity Controls: who must comply, how often, and what to document.
Why this matters now
The NCA has updated the Essential Cybersecurity Controls to ECC-2:2024, and entities in scope must ensure ongoing and continuous compliance, which the NCA assesses through self-assessments, its compliance tool and field audits. The ECC itself only says that penetration tests must be periodic. For systems an organization identifies as critical, the CSCC turns that into hard numbers: vulnerability assessments at least monthly and penetration tests at least every six months.
Key points
- ▸ECC scope: government agencies and their affiliated companies and entities, inside and outside the Kingdom, and private sector entities that own, operate or host Critical National Infrastructure.
- ▸ECC 2-10-3: periodic vulnerability assessment, severity classification, risk-based remediation, patches verified in a non-production environment, and subscriptions to trusted vulnerability sources.
- ▸ECC 2-11-3: penetration testing covers at least all externally provided services and their technical components, and tests are conducted periodically.
- ▸CSCC for critical systems: vulnerability assessment at least monthly, penetration tests at least every six months by a qualified team, covering all internal and external services.
- ▸ECC 1-8: implementation is reviewed and audited independently, by parties other than the cybersecurity department, in line with Generally Accepted Auditing Standards.
- ▸The Arabic text of the ECC is the binding version; the English text is a translation.
Who must comply
The National Cybersecurity Authority (NCA) sets the Essential Cybersecurity Controls (ECC) as the minimum cybersecurity requirements for national entities. The current version is ECC-2:2024, which updates ECC-1:2018. According to its scope, the controls apply to:
- Government agencies in the Kingdom of Saudi Arabia, including ministries, authorities and establishments, and their affiliated companies and entities, inside and outside the Kingdom.
- Private sector entities owning, operating or hosting Critical National Infrastructure (CNI).
The NCA strongly encourages all other entities in the Kingdom to use the controls as best practice. Each entity must comply with all controls applicable to it; some depend on the technology used, for example the cloud computing controls apply to entities using or planning to use cloud services.
Compliance is continuous, not a one-off certification. Under Article 10(3) of the NCA's Statute and High Order No. 57231, entities in scope must take all necessary measures to ensure ongoing and continuous compliance, and the NCA evaluates it through self-assessment, periodic reports from its compliance tool and field audit visits. The document states that the Arabic version is binding for all matters of meaning and interpretation.
Vulnerability management: control 2-10
Subdomain 2-10 aims to ensure timely detection and effective remediation of technical vulnerabilities, to prevent or minimize the probability of their exploitation.
- 2-10-1: cybersecurity requirements for technical vulnerability management are identified, documented and approved.
- 2-10-2: those requirements are implemented.
- 2-10-3 sets the minimum content:
- 2.10.3.1: periodic vulnerability assessment and detection.
- 2.10.3.2: classification of vulnerabilities by severity.
- 2.10.3.3: remediation based on that classification and the associated cyber risks.
- 2.10.3.4: patch management, with the integrity and effectiveness of updates and fixes verified in a non-production environment before they are applied.
- 2.10.3.5: communication and subscription with trusted sources for new vulnerabilities.
- 2-10-4: the implementation of these requirements is reviewed periodically.
Vulnerability assessment also appears earlier, in project and change management: 1-6-2 requires, at a minimum, vulnerability assessment and remediation, and a review of secure configuration, hardening and update packages, before projects and changes go live.
Penetration testing: control 2-11
Subdomain 2-11 has a clear objective: to assess and test the efficiency of the entity's cybersecurity defense capabilities through simulation of actual cyber-attack methods and technologies, to discover unknown weaknesses that may lead to a breach.
- 2-11-1: cybersecurity requirements for penetration testing are identified, documented and approved.
- 2-11-2: those requirements are implemented.
- 2-11-3 sets the minimum content:
- 2.11.3.1: the scope includes all externally provided services (via the Internet) and their technical components, including infrastructure, websites, web applications, smartphone and tablet applications, email and remote access.
- 2.11.3.2: penetration tests are conducted periodically.
- 2-11-4: the implementation of these requirements is reviewed periodically.
Two things stand out. The minimum scope is the external attack surface, listed in detail; internal systems are not part of the ECC minimum, although the objective of discovering weaknesses that may lead to a breach is hard to meet without them. And the ECC does not set the period: that is what the CSCC adds for critical systems.
Critical systems: the CSCC numbers
The Critical Systems Cybersecurity Controls (CSCC-1:2019) extend the ECC for national critical systems. They apply to systems that the organizations owning or operating them deem critical, whether government organizations in the Kingdom or abroad, or subsidiaries of government or private organizations. A critical system is one whose failure, unauthorized change, unauthorized access, or compromise of its data could harm the organization's services or cause economic, financial, security or social impact at national level. The identification criteria include negative impact on national security, significant financial losses (more than 0.01% of GDP), impact on services used by more than 5% of the population, loss of lives, disclosure of data classified Top Secret or Secret, and impact on vital sectors.
For those systems the CSCC sets fixed intervals:
- 2-9-1-1: trusted methods and tools for vulnerability assessments.
- 2-9-1-2: vulnerabilities assessed and remediated on critical systems' technical components at least once every month for external and internet-connected critical systems, and at least once every three months for internal critical systems.
- 2-9-1-3: critical vulnerabilities remediated immediately, in line with approved change management.
- 2-9-2: with reference to ECC 2-10-3-1, vulnerability assessments on critical systems' technical components at least once every month.
- 2-10-1-1: the penetration testing scope covers all of the critical systems' technical components and all internal and external services.
- 2-10-1-2: penetration tests conducted by a qualified team.
- 2-10-2: with reference to ECC 2-11-3-2, penetration tests on critical systems at least once every six months.
- 1-4-1 and 1-4-2: the cybersecurity function reviews CSCC implementation at least once a year, and independent parties within the organization, outside the cybersecurity function, review it at least once every three years.
The CSCC refers to ECC subcontrols 2-10-3-1 and 2-11-3-2, which keep the same numbering in ECC-2:2024.
What is explicit and what is left to you
Written in the controls:
- ECC: documented and approved requirements for vulnerability management and penetration testing, implemented and reviewed periodically; periodic vulnerability assessment with severity-based remediation; penetration tests of all externally provided services, periodically; vulnerability assessment before projects and changes go live; independent review and audit of the controls.
- CSCC, for critical systems: monthly vulnerability assessment, monthly or quarterly remediation depending on exposure, immediate remediation of critical vulnerabilities, penetration tests of all internal and external services at least every six months by a qualified team.
Not written in these texts:
- A fixed period for penetration tests of systems that are not critical. “Periodically” is the interval you set, document, approve and can defend.
- An obligation to use an external or accredited tester. The ECC is silent on who tests; the CSCC asks for a qualified team. The independence requirement in ECC 1-8 applies to the review and audit of the controls, not to each test.
- Red teaming as a control. Subdomain 2-11 describes simulation of real attack methods, which is the definition of a penetration test, not a separate adversary exercise.
Sector regulators can add their own requirements on top of the ECC, so check the instruments that apply to your sector as well.
Designing the testing programme
- Decide which systems are critical using the CSCC criteria, and document the decision. Everything else in the programme depends on this list.
- Inventory the externally provided services named in 2.11.3.1: infrastructure, websites, web applications, mobile applications, email and remote access. That is the minimum penetration testing scope for every system in scope of the ECC.
- Write the requirements down and get them approved (2-10-1 and 2-11-1), including the periods you chose for non-critical systems and why.
- Run the CSCC cadence on critical systems: monthly vulnerability assessment, monthly or quarterly remediation, and a penetration test at least every six months that covers internal as well as external services.
- Test before go-live: vulnerability assessment and remediation for every project and change (1-6-2), and patches verified in a non-production environment (2.10.3.4).
- Review periodically (2-10-4, 2-11-4) and arrange the independent review and audit under 1-8, with results presented as 1-8-3 requires.
The evidence to keep
- The approved requirements documents for vulnerability management and penetration testing (2-10-1, 2-11-1).
- The list of critical systems and the criteria applied, plus the inventory of externally provided services.
- Vulnerability assessment records with severity classification, remediation decisions based on risk, and dates that show the monthly cadence for critical systems.
- Patch records showing verification in a non-production environment before deployment.
- Penetration test reports with scope, date and team, showing coverage of every externally provided service and, for critical systems, all internal and external services at least every six months.
- Pre-go-live assessments for projects and changes.
- Periodic reviews and the independent audit results presented to the cybersecurity supervisory committee and the Authorized Official, with scope, observations, recommendations, corrective actions and remediation plans (1-8-3).
How continuous autonomous pentesting on an on-premise appliance helps
An autonomous AI red team for networks and infrastructure does not approve your requirements, is not the independent review of ECC 1-8, and does not decide by itself whether your testers are the qualified team the CSCC asks for. It makes the cadence the controls require easier to sustain, on infrastructure you control. For the category, see automated penetration testing.
- Monthly and six-monthly without gaps. Scheduled black-box campaigns against externally provided services and gray-box campaigns with standard-user access inside the network, run to the CSCC intervals and after changes, so the monthly assessment and the six-monthly test do not depend on a single engagement slot.
- Severity from proof. Findings say whether they were proven exploitable in your environment, which is the input the risk-based remediation in 2.10.3.3 needs, and each fix can be re-tested with the same proof.
- Human approval of risky steps. Five autonomy levels define what waits for an operator, and exploit proofs of concept can be held for review. See human in the loop.
- Framework mapping and records. Saudi NCA is one of the 34 frameworks the engine maps findings to, with exportable compliance reports; tying reports to 2-10, 2-11 and the CSCC controls stays in your documentation. Every attack attempt is an Ed25519-signed entry in a SHA-256 hash chain per campaign, verifiable offline.
- Data stays in the Kingdom. The models run on the appliance with no external AI service, and no customer data leaves it; in air-gapped mode it also stops downloads from public sources. See on-premise AI red team and the on-premise pentest platform buyer's guide.
Sources
- NCA: Essential Cybersecurity Controls page (nca.gov.sa)
- NCA Essential Cybersecurity Controls ECC-2:2024, English version, scope, 1-6, 1-8, 2-10 and 2-11 (PDF, nca.gov.sa)
- NCA: Critical Systems Cybersecurity Controls page (nca.gov.sa)
- NCA Critical Systems Cybersecurity Controls CSCC-1:2019, scope, criteria, 1-4, 2-9 and 2-10 (PDF, nca.gov.sa)
Goes deeper
- Worldwide guide: pentest requirements by regulation →
- Automated penetration testing explained →
- Industry: public administration →
- Industry: defense and air-gapped environments →
- Black-box vs gray-box penetration testing →
- Buyer's guide: on-premise pentest platforms →
- On-premise AI red team on private AI →
- Book a 30-minute readiness call →
Want this against your environment?
Book a 30-minute scoping call — we will map this directly to your current compliance scope and threat profile.