Saudi Arabia7 min read

External Attack Surface Management in Saudi Arabia: ECC-2, NCNICC and Aramco SACS

Saudi Arabia has the most detailed vulnerability management control set in the region. It also has the most widely misquoted one, and a brand new instrument that almost nobody outside the Kingdom has read because it was published in Arabic only.

ECC-2:2024 is current, and it does not say what you have been told

The National Cybersecurity Authority's Essential Cybersecurity Controls were reissued as ECC-2:2024, explicitly superseding ECC-1:2018. The structure is 4 domains, 28 subdomains, 108 main controls and 92 subcontrols. There is no transition deadline, because the obligation is framed as ongoing and continuous compliance. Scope now covers government affiliates inside and outside the Kingdom, plus private entities owning, operating or hosting critical national infrastructure.

Control 2-11-3-1 is the one that matters most for attack surface work. It requires the scope of penetration testing to include "all externally provided services (via the Internet) and their technical components, including infrastructure, websites, web applications, smartphone and tablet applications, email, and remote access".

Read that list again. Infrastructure, websites, web applications, mobile apps, email and remote access, all of it, everything you expose to the internet. You cannot scope a test to that standard without first enumerating what you expose, and most organisations discover during that exercise that the list is longer than they thought.

Now the correction. Control 2-10-3-1 requires "periodic vulnerabilities assessment and detection". It does not specify monthly. ECC-2 contains no numeric frequency anywhere in the document. The words monthly, quarterly and annually do not appear.

The widely repeated claim that "ECC requires monthly vulnerability scanning of internet-facing assets" is wrong, and it is the single most common error we encounter in Saudi compliance documentation. The monthly external and quarterly internal split comes from CSCC-1:2019 control 2-9-1-2, which applies to critical systems only, not to everything ECC covers. CSCC 2-10-2 is likewise where the six-monthly penetration testing figure lives, and CSCC 2-1-1-1 requires an annually updated critical asset inventory.

Getting this right matters commercially. If your consultant has quoted ECC for a monthly scanning obligation, they have cited the wrong instrument, and an assessor will notice.

NCNICC-1:2025, the overlooked driver

On 28 December 2025 the NCA issued its first control set aimed at ordinary private companies that are not critical national infrastructure. It is published in Arabic only, which is why most international vendors have not read it.

For Category A entities, meaning more than 250 employees, several controls are mandatory and directly relevant:

  • 2-10-1-2 requires periodic vulnerability scanning for all of the entity's assets.
  • 2-11-1 requires penetration test scope to cover all services provided over the internet.
  • 2-7-1-2 requires a brand protection service against impersonation.
  • 2-12-1-2 requires subscription to an NCA-licensed managed SOC.

Control 2-4-1-2 is mandatory for both Category A and Category B, and it is a domain inventory obligation in all but name: register the email domain on the Haseen platform with SPF, DKIM and DMARC configured.

Brand impersonation monitoring plus domain and email authentication registration plus scanning of all assets is, functionally, an external attack surface programme required of ordinary Saudi companies.

Aramco suppliers

If you contract with Saudi Aramco, SACS-002 binds you as a third party. TPC-85 requires monthly vulnerability scans across all five classifications. TPC-27 requires annual external penetration testing on IT infrastructure and internet-facing applications. TPC-91 sets remediation SLAs of 14 days for critical and one month for high. The Cybersecurity Compliance Certificate is valid two years, with an on-site CCC+ assessment for network connectivity and critical data processor categories.

One caution. There are credible indications that SACS-002 is being superseded by SACS-210, with a transition reportedly ending in August 2026, but Aramco's public materials still show SACS-002 throughout and only the February 2022 document is downloadable. Verify directly with Aramco rather than relying on consultancy summaries, including this one.

Financial sector

SAMA's Cyber Security Framework v1.0 from May 2017 remains operative. Section 3.2.4 item 2 states that customer and internet facing services should be subject to annual review and penetration tests. Section 3.3.17 covers vulnerability management on a risk-based rather than fixed frequency. Note the section number, since 3.3.15 is incident management and the two are frequently swapped in vendor documentation.

The practical point

Saudi requirements are unusually specific about internet-facing scope, and unusually vague about frequency in ECC itself. That combination means the burden of proof sits on you to show that your assessment cadence is defensible for your risk profile, and that your scope genuinely covered everything you expose.

Continuous external discovery answers both. It gives you a defensible cadence by default, and an evidenced scope you did not have to assemble by memory.

Other regions