What are the NCA OTCC and why do they matter?
The NCA OTCC (Operational Technology Cybersecurity Controls, OTCC-1:2022) are mandatory cybersecurity requirements issued by Saudi Arabia’s National Cybersecurity Authority. Specifically, they protect Industrial Control Systems (ICS) operating in critical facilities. Moreover, they exist because traditional IT security standards do not adequately address the unique risks of industrial environments, where failures can affect safety, production, and national infrastructure.
In practice, the OTCC framework fills the gap between enterprise cybersecurity and operational technology (OT) security. Furthermore, it connects directly to the NCA’s Essential Cybersecurity Controls (ECC), which organizations must implement before they can apply OTCC. As a result, OTCC builds on enterprise security foundations rather than replacing them.
Who must comply with the NCA OTCC?
OTCC applies to any organization that owns, operates, or hosts Industrial Control Systems in facilities designated as critical. Moreover, compliance covers a broad scope of entities, not just government bodies. In fact, affiliated entities both inside and outside the Kingdom fall within scope if they connect to or support designated critical facilities.
Specifically, three categories of organizations must comply:
- Government organizations that operate ICS environments in critical facilities
- Private operators of Critical National Infrastructure (CNI) in sectors such as energy, water, and manufacturing
- Affiliated entities that own, operate, or host ICS systems on behalf of designated organizations
Is ECC compliance required before applying the OTCC?
Yes. Compliance with the Essential Cybersecurity Controls (ECC-1:2018) is mandatory before OTCC applies. Specifically, ECC establishes the cybersecurity foundation for enterprise environments. OTCC then extends those principles to operational networks and industrial systems. In other words, ECC covers the IT layer and OTCC covers the OT layer.
In practice, this sequencing matters because OTCC controls assume that baseline enterprise security is already in place. As a result, an organization that has not implemented ECC cannot demonstrate valid OTCC compliance, even if it has deployed OT-specific technical controls.
How does the NCA assess OTCC compliance?
The NCA uses three mechanisms to validate OTCC compliance. Moreover, findings from any of these mechanisms can trigger remediation requirements or follow-up audits. Therefore, organizations should treat compliance as an ongoing program rather than a one-time exercise.
Specifically, the three assessment mechanisms are:
- Self-assessments: organizations evaluate their own controls against the OTCC requirements on a periodic basis
- On-site audits: the NCA or NCA-approved third parties conduct independent verification of controls in the operational environment
- The official OTCC-1:2022 Assessment and Compliance Tool: a standardized tool that structures the assessment process and produces documented compliance evidence
How does criticality level determine which OTCC controls apply?
OTCC applies different control sets depending on the risk level of each facility. Specifically, the NCA determines the applicable level through the OTCC Facility Level Identification Tool. Moreover, the higher the criticality, the more extensive the controls required. As a result, organizations operating multiple facilities may need to apply different control sets across their portfolio.
In practice, the three criticality levels work as follows:
- Level 1 (L1): applies to facilities with very high criticality where failure could have severe or catastrophic consequences. Specifically, L1 requires implementation of 151 controls
- Level 2 (L2): applies to facilities with moderate criticality and significant business impact. Furthermore, L2 requires 117 controls and includes all Level 3 requirements
- Level 3 (L3): applies to lower-risk facilities and requires 56 controls, forming the baseline that higher levels build upon