NCA ECC-2:2024 · Saudi Arabia

NCA ECC-2:2024 phishing
awareness, evidenced.

Control 1-10-3 of Saudi Arabia’s NCA Essential Cybersecurity Controls (ECC-2:2024) requires the awareness programme to cover secure handling of email, especially phishing emails, plus mobile devices and storage media, safe browsing and social media, and the newer NCNICC-1:2025 controls bring similar awareness duties to non-critical private companies.

Framework
NCA Essential Cybersecurity Controls, ECC-2:2024, subdomain 1-10
Applies to
Government bodies, their companies and private operators of critical national infrastructure
Private sector
NCNICC-1:2025 control 1-5-1: phishing and reporting suspicious behaviour, mandatory for Category A
KeenSec evidence
Phishing simulation results, report logs, LMS certificates, policy acknowledgements

What NCA says about awareness

Phishing is named
in the control itself.

ECC controls are numbered by subdomain.

ControlWhat it saysApplies to
ECC 1-10-1 and 1-10-2An awareness programme delivered through multiple channels, periodically developed, approved and implemented.ECC entities
ECC 1-10-3Cover the latest threats, including secure handling of email, especially phishing emails, mobile devices and storage media, browsing and social media.ECC entities
ECC 1-10-4Specialised training for cybersecurity staff, developers and executive and supervisory positions.ECC entities
ECC 1-9-4Cybersecurity awareness during onboarding and throughout employment.ECC entities
NCNICC 1-5-1Awareness tailored to roles, covering phishing, ransomware, passwords, social media and reporting suspicious behaviour.Category A mandatory, Category B recommended

Control 1-10-3 topics

What the programme covers,
and what KeenSec records.

TopicHow KeenSec helpsEvidence
Email, especially phishingEmail phishing, credential-capture, attachment and QR simulations, plus one-click reportingSimulation results and Phishing Reporter logs
Mobile devicesSMS and RCS, WhatsApp and voice simulations that reach people on their phonesResults per channel and person
BrowsingCredential-capture landing pages and browser-based ransomware simulationWho entered details, who reported
Programme deliveryLMS courses, micro-learning, assessments and certificatesCompletions and certificates

Topic summary from control 1-10-3. Read the full control text with your compliance team.

Expectation to record

Proof for the
awareness programme.

SIMULATION RESULTS

Staff tested on email and mobile.

Outcomes per channel, team and campaign.

REPORT LOGS

Staff report phishing.

Phishing Reporter submissions with automated analysis.

TRAINING

Staff complete awareness lessons.

LMS completions, assessments and certificates.

POLICY ACKNOWLEDGEMENTS

Staff accept email and device policies.

Dated records from Policy Manager.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. NCA Essential Cybersecurity Controls, ECC-2:2024 (English)2024 · subdomain 1-10
  2. NCA Non-CNI Private Sector Entities Cybersecurity Controls, NCNICC-1:2025 (Arabic)Control 1-5-1

Questions buyers ask

Frequently asked questions.

Does NCA require phishing simulation?

The controls do not require it. They require awareness that covers phishing, reviewed periodically. NCA also runs an optional Phishing Simulation Service through its Haseen portal, which shows the kind of measurement it values.

We are a private company, not critical infrastructure. What applies?

NCA’s NCNICC-1:2025 controls cover non-critical private companies. Control 1-5-1 asks for awareness on phishing and reporting suspicious behaviour, mandatory for larger Category A companies and recommended for Category B.

Does KeenSec make us compliant with NCA ECC?

No tool makes you compliant on its own. KeenSec helps you run and evidence the awareness programme; your auditor and the NCA decide compliance.

Can KeenSec simulate phishing on mobile channels?

Yes. KeenSec simulates SMS and RCS, WhatsApp and voice, alongside email, Microsoft Teams and Slack.

Let’s connect the dots

Email, mobile, browsing.
Tested and on record.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo