HomeBlogCritical Infrastructure
Critical Infrastructure

Saudi OTCC and CSCC: Which NCA Controls Apply?

Sep 2026 · 9 min read

Isometric illustration of an industrial control room, petrochemical plant, desalination plant and server building linked to a central security hub

Saudi Arabia's National Cybersecurity Authority publishes three control sets that critical infrastructure operators need to understand together: the Essential Cybersecurity Controls (ECC), the Critical Systems Cybersecurity Controls (CSCC) and the Operational Technology Cybersecurity Controls (OTCC). The question we hear most is not what each one says, but which one applies to which system. The answer is in NCA's own documents, and it is cleaner than most vendor summaries suggest.

What is NCA OTCC-1:2022?

OTCC-1:2022 is NCA's control set for industrial control systems and operational technology. It is structured as 4 main domains, 23 subdomains, 47 main controls and 122 subcontrols.

NCA describes it as an extension of the ECC focused on industrial control systems. NCA publishes a Methodology and Mapping Annex and an Assessment and Compliance Tool alongside it.

Who must comply with OTCC?

OTCC applies to industrial control systems in facilities deemed critical that are owned or operated by government organisations, or by private organisations that own, operate or host critical national infrastructure. It applies whether those facilities are inside the Kingdom or abroad.

Industrial control systems means any device, system or network used to operate or automate industrial processes. The obligation is qualified: organisations comply with applicable controls after ensuring that doing so will not jeopardise operational continuity. That qualification is real, and it should be documented, not assumed.

OTCC does not apply to every Saudi company running OT. NCA encourages other organisations to use it, but the obligation is scoped to critical facilities.

What are the four OTCC domains?

Cybersecurity Governance has eight subdomains, including ICS project management and change management. Cybersecurity Defense has thirteen, including physical security. Cybersecurity Resilience has one, covering business continuity. Third-Party Cybersecurity has one.

Unlike the ECC and CSCC, OTCC has no cloud subdomain.

What are OTCC facility levels L1, L2 and L3?

OTCC scales by facility criticality. NCA's published totals are 151 controls and subcontrols for Level 1, 117 for Level 2 and 56 for Level 3. Level 1 facilities implement everything, Level 2 facilities implement the Level 2 and Level 3 controls, and Level 3 facilities implement the Level 3 controls as a minimum.

The level is set using NCA's Facility Level Identification Tool against nine criteria, including health, safety and environmental impact and interdependencies. A facility takes the level of its most critical system.

You will see other totals online, such as 169 or 150 for Level 1. Those come from vendors counting rows themselves. Use NCA's figures, because those are what an assessor will use.

Is ECC compliance required before OTCC?

Yes. OTCC states that compliance with the Essential Cybersecurity Controls is a mandatory prerequisite.

There is a version wrinkle to be aware of. The OTCC text refers to ECC-1:2018, but the current ECC is ECC-2:2024, with 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols. ECC-2:2024 deleted the old industrial control systems domain and moved that content into OTCC. We could not find a published OTCC-2, so plan against ECC-2:2024 as the prerequisite and OTCC-1:2022 for OT.

What is NCA CSCC-1:2019?

CSCC-1:2019 covers critical systems that are not operational technology. It has 4 main domains, 21 subdomains, 32 main controls and 73 subcontrols across Governance, Defense, Resilience, and Third-Party and Cloud Computing. As with OTCC, ECC compliance is a prerequisite.

What counts as a critical system under CSCC?

CSCC defines a critical system as one whose failure or compromise may cause negative national-level economic, financial, security or social impact. It sets seven identification criteria, including losses above 0.01 percent of GDP, impact on more than 5 percent of the population, loss of life, and disclosure of Top Secret or Secret data.

Its stated scope is government organisations inside the Kingdom or abroad and subsidiaries of government or private organisations. Note that this is worded differently from the ECC and OTCC scope, so read it against your own structure rather than assuming it mirrors them.

Do OT systems fall under CSCC or OTCC?

OTCC only. NCA's Methodology and Mapping Annex is explicit: non-OT critical systems are subject to CSCC, while critical industrial control systems and operational technologies are only subject to OTCC.

This matters because some guidance tells OT operators to satisfy both. They do not need to. An organisation with both kinds of critical system runs CSCC for its critical IT and OTCC for its critical OT, with ECC underneath both.

Which CSCC obligations have hard frequencies?

CSCC is unusually specific. Risk assessment of critical systems at least annually, with the risk register reviewed monthly. Patching at least monthly for external or internet-connected critical systems and at least quarterly for internal ones. Vulnerability assessments monthly. Penetration testing at least every six months. Logs retained for at least 18 months. Backup restore tests quarterly. Disaster recovery testing at least annually.

It also carries localisation requirements: no remote access from outside the Kingdom, technical support and development roles filled by Saudi professionals, outsourcing to Saudi companies, and hosting in-house or with government or CCC-compliant Saudi cloud providers. These often have a bigger commercial impact than the technical controls.

How does NCA assess compliance?

For OTCC, assessment is by self-assessment and field audit visits by NCA or designated third parties, using the OTCC Assessment and Compliance Tool.

For CSCC, the organisation identifies its critical systems, complies within the compliance period NCA sets, and then maintains compliance continuously, assessed by self-assessment or on-site audit. CSCC also requires an internal review of implementation at least annually and an independent review, outside the cybersecurity function, at least every three years.

Which international standards does OTCC map to?

NCA's annex maps OTCC to ISA/IEC 62443 parts 2-1, 3-2 and 3-3, NIST CSF, NIST SP 800-53 revision 4 and SP 800-82 revision 2, NOG 104, NERC CIP version 6 and DOE C2M2.

Where OTCC and a referenced standard conflict, OTCC takes precedence. If you already run an IEC 62443 program, it gives you a head start, but it does not replace an OTCC assessment.

How GRCLens supports ECC, CSCC and OTCC

GRCLens implements NCA ECC as a full control catalogue, with Arabic and English interfaces and right-to-left reporting, and maps shared controls so that evidence collected once supports ECC, CSCC and OTCC. It can be deployed fully on-premises or air-gapped with its AI features running inside your own infrastructure, which is usually a requirement rather than a preference for critical system owners.

Primary sources

National Cybersecurity Authority: Operational Technology Cybersecurity Controls (OTCC-1:2022) and its Methodology and Mapping Annex; Critical Systems Cybersecurity Controls (CSCC-1:2019); Essential Cybersecurity Controls (ECC-2:2024). All are published on nca.gov.sa.

This article is general information. Confirm applicability of each control set with NCA or your regulator.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles