A cybersecurity audit does not only inspect firewalls, logs, policies, and incident response plans. In Saudi Arabia, it may also inspect who is actually operating your cybersecurity function.
That is why the NCA ECC Checklist has become a workforce compliance issue, not only a technical security checklist. Under ECC-2:2024, organisations within scope must be ready to prove that cybersecurity roles are properly structured, staffed, documented, and aligned with Saudi national cybersecurity expectations. The updated NCA ECC framework states that all entities within its scope must take necessary measures for ongoing compliance, and that NCA may evaluate compliance through self-assessments, periodic compliance-tool reports, and field audits. (NCA)
For HR executives, operations heads, CISOs, and C-suite leaders, the question is no longer only: “Do we have a cybersecurity team?” The stronger question is: can we prove that our cybersecurity workforce structure satisfies the latest NCA expectations?
Disclaimer: This article is for educational guidance only. NCA ECC applicability, Saudization requirements, audit procedures, private-sector scope, and staffing rules may change. Organisations should confirm current obligations through the National Cybersecurity Authority, qualified Saudi legal counsel, and cybersecurity compliance advisers.
The Hidden Clause in ECC-2:2024
One of the most important changes in Essential Cybersecurity Controls 2024 is the staffing requirement under control 1-2-2.
The official ECC-2:2024 update table shows that the previous wording focused on the cybersecurity function head, such as the CISO, and related supervisory or critical positions. The updated wording states that all cybersecurity positions shall be filled with full-time and qualified Saudi cybersecurity professionals. (NCA)
This is the clause many organisations underestimate.
In practical terms, the change moves cybersecurity Saudization from a senior-leadership issue to a full workforce-structure issue for entities within ECC scope. It is not only about having a Saudi CISO or Saudi cybersecurity manager. It affects technical, operational, monitoring, response, governance, risk, and compliance positions inside the cybersecurity function.
|
Old Mindset |
ECC-2:2024 Audit Reality |
|
“Only the CISO role needs localisation.” |
All cybersecurity positions may need evidence of qualified Saudi staffing. |
|
“Our offshore SOC covers the function.” |
Outsourcing does not remove internal accountability. |
|
“HR owns Saudization.” |
Cybersecurity staffing is now part of audit evidence. |
|
“A vendor manages security.” |
Third-party risk and role ownership still need proof. |
|
“We have a policy.” |
Auditors may ask for personnel records, access reviews, and structural logs. |
This makes the Cybersecurity Saudization requirement a GRC issue. HR, IT, legal, procurement, and cybersecurity leadership must work from one evidence base.
Who Must Pay Attention to the NCA ECC Checklist?
The official ECC-2:2024 scope states that the controls apply to Saudi government agencies and their affiliated companies and entities inside and outside the Kingdom, as well as private-sector entities owning, operating, or hosting Critical National Infrastructure. NCA also strongly encourages other entities in the Kingdom to use the controls as best practice. (NCA)
So, the staffing clause should not be casually treated as “mandatory for every Saudi company” without checking scope. The safer and more accurate position is:
-
if your entity is directly within ECC scope, the requirement needs serious compliance attention;
-
if your entity is a supplier, contractor, cloud provider, healthcare operator, financial partner, or public-sector service provider, clients may still expect ECC-aligned evidence;
-
if your entity is not directly in ECC scope, ECC remains a strong benchmark for mature cybersecurity governance.
For private-sector organisations outside CNI, newer private-sector control frameworks may also apply depending on classification, size, sector, and NCA direction. That is why organisations should map both ECC and any applicable private-sector NCA requirements before designing the staffing model.
The Offshore Outsourcing Wall
Outsourcing is not automatically non-compliant. But relying heavily on offshore teams to perform core cybersecurity roles can create serious audit exposure.
ECC-2:2024 includes a dedicated domain for third-party and cloud computing cybersecurity, and the official ECC structure lists Third-Party Cybersecurity and Cloud Computing and Hosting Cybersecurity as part of the main control domains. (NCA) The NCA’s implementation guidance also expects cybersecurity requirements to be included in third-party contracts and for organisations to conduct third-party cybersecurity risk assessments. (NCA)
This matters when a company says:
“Our SOC is offshore, our incident responders are offshore, our IAM admins are offshore, and our cyber risk analysts are external.”
That model may create questions such as:
-
Who owns cybersecurity decisions inside the Saudi entity?
-
Which cybersecurity positions are internal versus outsourced?
-
Are all required positions filled by qualified Saudi professionals?
-
Can offshore analysts access sensitive Saudi systems?
-
Are privileged accounts localised and reviewed?
-
Are third-party contracts aligned with NCA expectations?
-
Is incident response dependent on a team outside the Kingdom?
-
Are logs, tickets, and playbooks available for audit?
A third-party can support operations, but it cannot become a black box. The organisation still needs local accountability, access governance, risk ownership, and evidence.
Building a Compliant Security Operations Center
A compliant SOC is not built by hiring names into an organisational chart. It is built by matching roles, skills, access, procedures, and evidence.
For entities affected by the Cybersecurity Saudization requirement, a SOC staffing model should show how qualified Saudi national talent covers the cybersecurity positions needed to operate, monitor, defend, respond, and report.
A practical SOC structure may include:
|
SOC / Cyber Function |
Evidence Needed |
|
SOC manager |
Saudi national status, job description, qualifications, full-time record |
|
Security analyst L1/L2/L3 |
Role profile, training record, shift schedule, SIEM access |
|
Incident responder |
Playbooks, response training, incident ticket ownership |
|
Threat intelligence analyst |
Intelligence sources, reporting responsibility |
|
IAM administrator |
Access-control role, privileged access review logs |
|
Vulnerability analyst |
Scan ownership, remediation tracking |
|
GRC analyst |
Risk register, control mapping, compliance reports |
|
Third-party risk owner |
Vendor assessments, contract control review |
|
Cloud security owner |
Tenant security, cloud access, configuration evidence |
This is where Qualified Saudi national staffing becomes measurable. It is not enough to say “we have Saudi cybersecurity staff.” The organisation should prove that each relevant position has a role description, qualification evidence, employment record, reporting line, access review, and operational responsibility.
For teams that need to connect control ownership, risk mapping, audit evidence, and workforce compliance, Cybersecurity Governance, Risk & Compliance (GRC) can support managers who need to build NCA-ready governance capability.
Can Outsourced Offshore Teams Still Be Used?
Yes, but carefully.
The problem is not using external support. The problem is allowing outsourced teams to replace the required cybersecurity function without local ownership, qualified Saudi staffing, documented risk acceptance, contract controls, and access governance.
A safer outsourcing model looks like this:
|
Area |
Better Practice |
|
SOC monitoring |
Local Saudi cyber owner with vendor support under contract |
|
Threat intelligence |
External feeds allowed, internal analysis ownership retained |
|
Incident response |
External specialists on retainer, internal Saudi response lead assigned |
|
Vulnerability scanning |
Vendor can run tools, internal team owns remediation decisions |
|
IAM operations |
Privileged access controlled and reviewed by internal authorised staff |
|
GRC reporting |
Internal GRC owner validates evidence before submission |
|
Cloud security |
Vendor supports configuration, entity owns tenant risk |
The key is to avoid a structure where the Saudi entity has no internal cyber capability and cannot explain who owns decisions.
The Audit Evidence Matrix
Passing an audit means producing evidence quickly. It is not enough to say the staffing model is compliant. The organisation must prove it.
A strong audit evidence matrix should include:
|
Evidence Category |
What Assessors May Check |
|
Cybersecurity organisation chart |
Shows roles, reporting lines, and function structure |
|
Job descriptions |
Proves cybersecurity positions are defined |
|
Employment records |
Confirms full-time status and employee identity |
|
Nationality records |
Supports Saudi national staffing evidence |
|
Qualification records |
Shows relevant cybersecurity qualifications or experience |
|
Training records |
Proves staff capability development |
|
Access review logs |
Confirms role-based access and localised control |
|
Privileged access records |
Shows who can administer critical systems |
|
SOC shift schedules |
Proves operational coverage |
|
Vendor contracts |
Shows third-party obligations and boundaries |
|
Third-party risk assessments |
Proves vendor risk review |
|
Incident ownership logs |
Shows who led response actions |
|
Compliance tool reports |
Supports NCA assessment process |
|
Field audit response pack |
Shows readiness for inspection |
The official ECC-2:2024 document notes that NCA will issue an assessment and compliance tool to organise assessment and measurement of compliance. (NCA) This means evidence discipline matters. If documentation is scattered across HR, IT, procurement, and vendor portals, the audit response becomes slow and weak.
Localised Access Reviews
One of the strongest ways to prove cybersecurity workforce control is through access evidence.
If your cybersecurity positions are filled by qualified Saudi professionals, your access logs should reflect that reality. Assessors may look for mismatch between the organisation chart and actual system access.
For example:
|
Audit Question |
Weak Answer |
Strong Answer |
|
Who administers SIEM? |
“Vendor team.” |
Named Saudi SOC staff with vendor support and reviewed access. |
|
Who approves firewall changes? |
“Network vendor.” |
Internal authorised Saudi cyber/network owner approves and logs change. |
|
Who owns incident response? |
“MSSP.” |
Internal Saudi incident lead coordinates MSSP support. |
|
Who reviews privileged accounts? |
“IT does it.” |
Named IAM owner reviews privileged access monthly. |
|
Who reports NCA compliance? |
“Consultant.” |
Internal GRC owner validates consultant-supported evidence. |
Access reviews should cover:
-
SIEM;
-
EDR/XDR;
-
firewalls;
-
IAM tools;
-
cloud consoles;
-
vulnerability scanners;
-
ticketing platforms;
-
GRC tools;
-
privileged access management;
-
email security gateways;
-
backup and recovery systems.
If offshore or third-party users have privileged access, the organisation should document why, how it is controlled, how long it lasts, and who approves it.
Cybersecurity Saudization and HR Operations
HR cannot treat cybersecurity Saudization as a general hiring target. It needs job-family precision.
Build a cybersecurity workforce register that includes:
-
role title;
-
role category;
-
business owner;
-
Saudi national status;
-
qualification or certification;
-
employment type;
-
full-time / contractor status;
-
access level;
-
systems supported;
-
vendor dependency;
-
backup person;
-
training plan;
-
evidence location.
This register should be reviewed with CISO, HR, legal, procurement, and compliance.
A practical roadmap:
Month 1: Map the Cybersecurity Function
List every cybersecurity activity and the person or vendor performing it.
Month 2: Identify Non-Compliant Role Coverage
Find roles filled by offshore personnel, temporary contractors, vendors, or undefined owners.
Month 3: Build Saudi Talent Coverage Plan
Prioritise SOC, IAM, GRC, incident response, cloud security, vulnerability management, and third-party risk.
Month 4: Train and Transition
Move operational ownership to qualified Saudi professionals while keeping vendor support where needed.
Month 5: Test Evidence
Run a mock audit using the NCA ECC checklist and evidence matrix.
Month 6: Stabilise and Monitor
Review monthly until the model is mature.
Temporary Contractors and the Saudization Question
The FAQ asks whether temporary contractors can fulfil technical cybersecurity roles under the Saudization requirement.
The safer answer is: do not assume they can.
ECC-2:2024’s updated wording refers to cybersecurity positions being filled with full-time and qualified Saudi cybersecurity professionals. (NCA) If a role is critical to the cybersecurity function, relying on temporary contractors may create audit questions unless the arrangement clearly satisfies the applicable requirement, is properly documented, and is accepted under the entity’s compliance interpretation.
A contractor may support projects, implementation, training, or surge capacity. But if the contractor is effectively filling a permanent cybersecurity position, the organisation should carefully assess the risk.
How NCA May Verify Employee Nationality During Audit
The brief asks how NCA verifies employee nationalities during a structural remote platform audit. The exact audit procedure can vary, and organisations should not assume one fixed method.
However, assessors may reasonably request evidence such as:
-
HR employee records;
-
national ID or verified employment identity records;
-
GOSI employment information where applicable;
-
job descriptions;
-
organisation chart;
-
employment contracts;
-
access logs;
-
shift schedules;
-
training certificates;
-
system ownership records;
-
vendor access lists;
-
compliance tool submissions.
The key point is that nationality evidence alone is not enough. The organisation must also prove that the person is actually performing the cybersecurity role and has the required qualification or experience.
NCA ECC Audit Readiness Checklist
Use this checklist before your next audit.
Workforce Structure
-
Are all cybersecurity positions listed?
-
Are role owners named?
-
Are Saudi national staffing requirements assessed?
-
Are full-time roles documented?
-
Are qualifications and training records available?
Outsourcing and Third Parties
-
Are MSSP and vendor roles clearly separated from internal roles?
-
Are third-party contracts updated with cybersecurity requirements?
-
Are third-party risk assessments completed?
-
Are offshore access rights reviewed?
-
Is vendor privileged access time-bound and approved?
SOC Operations
-
Are SOC shifts documented?
-
Are Saudi analysts assigned to monitoring roles?
-
Are incident response roles defined?
-
Are SIEM and EDR access logs reviewed?
-
Are escalation procedures tested?
Access Governance
-
Are privileged access reviews performed?
-
Are IAM roles mapped to named personnel?
-
Are access rights consistent with job roles?
-
Are offshore accounts justified?
-
Are terminated users removed quickly?
Audit Evidence
-
Is the ECC evidence folder ready?
-
Are HR records linked to cyber roles?
-
Are training certificates stored centrally?
-
Are compliance tool outputs retained?
-
Has a mock audit been completed?
Conclusion
Meeting the NCA ECC Checklist requires more than technical controls. It requires a deep understanding of local workforce compliance, cybersecurity governance, third-party boundaries, access evidence, and audit documentation.
The ECC-2:2024 staffing update is a serious operational signal: cybersecurity cannot be treated as a fully offshore or vendor-owned function. For entities within scope, all cybersecurity positions must be filled with full-time and qualified Saudi cybersecurity professionals. That means organisations must build internal Saudi talent pools, document role ownership, control third-party support, and prove the structure through HR and access evidence.
For executives, this is not only a compliance issue. It is a licence-to-operate issue. Cybersecurity resilience depends on people, not only tools.
Near the end of any ECC readiness programme, Cybersecurity Governance, Risk & Compliance (GRC) can support leaders who need to align NCA controls, workforce evidence, third-party risk, and audit-ready cybersecurity governance.
FAQs
Is 100% Saudization mandatory for all cybersecurity roles in Saudi Arabia?
For entities within ECC-2:2024 scope, the updated control wording states that all cybersecurity positions shall be filled with full-time and qualified Saudi cybersecurity professionals. Organisations must confirm whether they are directly in scope and how the requirement applies to their structure. (NCA)
Can temporary contractors fulfil technical cybersecurity roles under the Saudization requirement?
Do not assume this is acceptable. The updated ECC wording refers to full-time and qualified Saudi cybersecurity professionals. Contractors may support projects or surge work, but permanent cybersecurity positions should be assessed carefully with legal and compliance advisers.
How can a company pass an NCA ECC audit with outsourced offshore teams?
The company should maintain internal Saudi cybersecurity role ownership, document vendor boundaries, conduct third-party risk assessments, restrict and review offshore access, ensure contracts include cybersecurity requirements, and keep audit evidence showing that core cybersecurity positions are not simply outsourced without local accountability.
How does NCA verify employee nationalities during an audit?
Procedures may vary, but assessors may request HR records, employment contracts, national identity evidence, organisation charts, role descriptions, training records, access logs, SOC schedules, and system ownership evidence.
What is the biggest risk of offshore SOC outsourcing?
The biggest risk is loss of internal accountability. If the offshore provider owns monitoring, incident response, privileged access, and reporting without a qualified local cyber function, the organisation may struggle to prove control during an ECC audit.
What evidence is needed for NCA third-party risk management?
Evidence may include vendor risk assessments, contracts with cybersecurity clauses, access lists, service-level agreements, incident notification terms, audit rights, cloud/security reviews, and proof that the organisation reviews vendor performance and access regularly.


