NCA ECC-2:2024 · Saudi Arabia
NCA ECC-2:2024 phishing
awareness, evidenced.
Control 1-10-3 of Saudi Arabia’s NCA Essential Cybersecurity Controls (ECC-2:2024) requires the awareness programme to cover secure handling of email, especially phishing emails, plus mobile devices and storage media, safe browsing and social media, and the newer NCNICC-1:2025 controls bring similar awareness duties to non-critical private companies.
- Framework
- NCA Essential Cybersecurity Controls, ECC-2:2024, subdomain 1-10
- Applies to
- Government bodies, their companies and private operators of critical national infrastructure
- Private sector
- NCNICC-1:2025 control 1-5-1: phishing and reporting suspicious behaviour, mandatory for Category A
- KeenSec evidence
- Phishing simulation results, report logs, LMS certificates, policy acknowledgements
What NCA says about awareness
Phishing is named
in the control itself.
ECC controls are numbered by subdomain.
| Control | What it says | Applies to |
|---|---|---|
| ECC 1-10-1 and 1-10-2 | An awareness programme delivered through multiple channels, periodically developed, approved and implemented. | ECC entities |
| ECC 1-10-3 | Cover the latest threats, including secure handling of email, especially phishing emails, mobile devices and storage media, browsing and social media. | ECC entities |
| ECC 1-10-4 | Specialised training for cybersecurity staff, developers and executive and supervisory positions. | ECC entities |
| ECC 1-9-4 | Cybersecurity awareness during onboarding and throughout employment. | ECC entities |
| NCNICC 1-5-1 | Awareness tailored to roles, covering phishing, ransomware, passwords, social media and reporting suspicious behaviour. | Category A mandatory, Category B recommended |
Control 1-10-3 topics
What the programme covers,
and what KeenSec records.
| Topic | How KeenSec helps | Evidence |
|---|---|---|
| Email, especially phishing | Email phishing, credential-capture, attachment and QR simulations, plus one-click reporting | Simulation results and Phishing Reporter logs |
| Mobile devices | SMS and RCS, WhatsApp and voice simulations that reach people on their phones | Results per channel and person |
| Browsing | Credential-capture landing pages and browser-based ransomware simulation | Who entered details, who reported |
| Programme delivery | LMS courses, micro-learning, assessments and certificates | Completions and certificates |
Topic summary from control 1-10-3. Read the full control text with your compliance team.
Expectation to record
Proof for the
awareness programme.
Staff tested on email and mobile.
Outcomes per channel, team and campaign.
Staff report phishing.
Phishing Reporter submissions with automated analysis.
Staff complete awareness lessons.
LMS completions, assessments and certificates.
Staff accept email and device policies.
Dated records from Policy Manager.
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Primary sources
What this page is based on.
Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.
Questions buyers ask
Frequently asked questions.
Does NCA require phishing simulation?
The controls do not require it. They require awareness that covers phishing, reviewed periodically. NCA also runs an optional Phishing Simulation Service through its Haseen portal, which shows the kind of measurement it values.
We are a private company, not critical infrastructure. What applies?
NCA’s NCNICC-1:2025 controls cover non-critical private companies. Control 1-5-1 asks for awareness on phishing and reporting suspicious behaviour, mandatory for larger Category A companies and recommended for Category B.
Does KeenSec make us compliant with NCA ECC?
No tool makes you compliant on its own. KeenSec helps you run and evidence the awareness programme; your auditor and the NCA decide compliance.
Can KeenSec simulate phishing on mobile channels?
Yes. KeenSec simulates SMS and RCS, WhatsApp and voice, alongside email, Microsoft Teams and Slack.
Let’s connect the dots
Email, mobile, browsing.
Tested and on record.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo