The National Cybersecurity Authority sets the cybersecurity frameworks, standards and controls that apply in Saudi Arabia, and monitors compliance against them. Two of its frameworks govern any organisation operating industrial control systems in the Kingdom.
The Essential Cybersecurity Controls, published in 2018 and known as the ECC, establish the national cybersecurity baseline. The Operational Technology Cybersecurity Controls, published in 2022 as OTCC-1:2022 and known as the OTCC, extend that baseline into the industrial environment. Both are mandatory under item 3 of Article 10 of the Authority's mandate and under Royal Decree number 57231, dated 10/11/1439H, and the Authority requires continuous compliance rather than conformity demonstrated at a single point in time.

Why the OTCC Exists as a Separate Standard
General cybersecurity controls rest on assumptions that fail in an industrial environment. They assume a system can be patched when a correction is released, that a production asset can be scanned without operational consequence, and that a compromised machine can be taken off the network during an investigation.
In an industrial environment, patching a controller commonly requires the process it governs to be shut down, at a production loss that may exceed the loss the vulnerability would cause if exploited. A conventional vulnerability scanner can render a legacy field device inoperable, as such devices cannot reject traffic they were not designed to receive. Removing a compromised engineering workstation can deprive the control room of visibility of a running process. The consequences of failure also differ in kind, as an industrial incident produces injury to personnel, damage to equipment or release to the environment rather than the disclosure of information. The requirement taking precedence is therefore the safe and continuous operation of the physical process.
The Authority accordingly issued a dedicated document rather than expanding its enterprise framework. The OTCC defines a baseline expressed in terms that correspond to industrial operating conditions, and renders it auditable, so that compliance is measured against a fixed standard rather than the judgement of an individual assessor.
The ECC and How the OTCC Extends It
The ECC applies to government organisations in the Kingdom, including ministries, authorities and establishments together with their companies and entities, and to private sector organisations owning, operating or hosting Critical National Infrastructure. It contains five main domains and twenty nine subdomains.
| ECC domain | Subdomains |
|---|---|
| 1. Cybersecurity Governance | 10 |
| 2. Cybersecurity Defense | 15 |
| 3. Cybersecurity Resilience | 1 |
| 4. Third-Party and Cloud Computing Cybersecurity | 2 |
| 5. ICS Cybersecurity | 1 |
The fifth domain is the origin of the OTCC. The entire ECC treatment of industrial systems consists of one subdomain, 5-1, Industrial Control Systems Protection. The OTCC expands that one subdomain into four domains, twenty three subdomains, forty seven controls and one hundred and twenty two subcontrols.
The structural inheritance is evident in the domain titles. The OTCC retains the first three, narrows the fourth to Third-Party Cybersecurity by omitting cloud computing, and carries no equivalent of Domain 5 because it is the expansion of that domain.
Compliance with the ECC is a mandatory prerequisite, as an OTCC control is not a complete requirement in isolation. Each is drafted as an addition to a named ECC control, cites it by reference number, and then states what the industrial environment demands beyond it. Two consequences follow.
- The enterprise baseline cannot be deferred: the OTCC controls have no standalone meaning without the ECC controls they extend.
- The two frameworks should run as one programme: the corporate environment falls under the ECC and the industrial environment under the OTCC, and they meet at the boundary carrying the connections an intrusion would use to cross between them.

Who Must Comply, and Under What Authority
Two conditions determine whether the OTCC applies.
- The organisation must fall within one of two categories: government organisations, defined as including ministries, authorities and establishments, or private sector organisations that own, operate or host Critical National Infrastructure. A privately held company running infrastructure of national importance carries the same obligation as a government body.
- The facility must be critical: defined as one whose destruction or dysfunction may disrupt or discontinue the organisation's operation. Within it, the controls cover all devices, systems or networks used to operate or automate industrial processes, comprising controllers, engineering workstations, human machine interfaces, historians, safety systems and the connecting network equipment.
Two provisions extend the reach of the framework beyond those categories.
- Location does not limit the obligation: the controls apply whether the facilities are in the Kingdom or abroad.
- Organisations outside mandatory scope are still addressed: the Authority strongly encourages all others in the Kingdom to adopt the controls, and such organisations frequently meet the OTCC through requirements imposed by customers and partners.
No list of qualifying industries is published, as scope follows criticality rather than sector. Critical National Infrastructure in the Kingdom is concentrated in oil and gas, petrochemicals and chemicals, power generation and transmission, water and desalination, manufacturing, mining and metals, and transport and logistics.
One provision is frequently misread as an exemption. Organisations must comply with all applicable controls after ensuring that applying them will not jeopardise operational continuity. This does not permit omission of a control. It recognises that a control implemented without regard for process safety may introduce more risk than it removes. Where a requirement cannot be implemented, the justification must be documented and approved by the cybersecurity function and the Authorizing Official. Where a risk is accepted, alternative controls must be defined, approved, implemented for a defined period and reassessed continuously. Deviation is permissible only as a documented, approved and time-limited decision.

The Four Domains of the OTCC
The framework addresses four pillars, being strategy, people, process and technology. An organisation treating the OTCC as a technology purchase will satisfy the technology requirements and fail the remaining three.
Cybersecurity Governance, eight subdomains, determines who is accountable and how. Three requirements bind it to industrial practice. The OT risk methodology must sit within both the organisation's risk management and its safety risk management. At the highest criticality level, cybersecurity risk must be analysed within the Process Hazard Analysis and reapplied whenever plant operations or procedures change. At Levels 1 and 2, security requirements must be built into Factory Acceptance Testing, Site Acceptance Testing, commissioning, change testing, integration testing and source code review, placing verification before equipment is accepted.
Cybersecurity Defense, thirteen subdomains and the largest domain, carries the technical requirements, and its network provisions are specific. At all three levels, the industrial environment must be segmented from other networks, and Safety Instrumented Systems segmented again from the other industrial networks, so the systems that bring a process to a safe state cannot be reached through the systems that run it. Default credentials must be changed, disabled or removed on all industrial assets, at every level without exception. At Levels 1 and 2, direct communication between the corporate and industrial zones must be prevented, with required connections routed through a dedicated hardened jump host in the demilitarised zone, and remote access must be enabled only where justified, risk-assessed beforehand, multi-factor authenticated, limited in duration and privilege, and recorded throughout.
Cybersecurity Resilience, one subdomain, governs what happens once prevention has failed. The activities needed to sustain minimum operations must be defined, and OT requirements must be built into the business continuity plan, the business impact analysis and the recovery objectives rather than inherited from an enterprise plan written for information systems. Distinctively, where a cybersecurity incident causes a system failure, industrial systems must operate in an acceptable safe mode to achieve continuous operation.
Third-Party Cybersecurity, one subdomain, covers manufacturers, vendors and service suppliers, on whom industrial environments depend for configuration and maintenance. Cybersecurity requirements must be included in the procurement lifecycle, placing the obligation at the point of purchase.

The Three Facility Levels
The OTCC does not apply uniformly. It defines three levels, and the level assigned to a facility determines how many controls apply. Levels are set against three criteria: impact on the organisation's business and service availability, impact on health, safety and environment, and impact on the national economy, national security or social influence. The third criterion is what separates this from an internal risk rating, because it measures the cost to the country rather than to the organisation.
| Level | Criticality of the facility | Controls and subcontrols |
|---|---|---|
| Level 1 (L1) | High criticality, with severe effects on operations or catastrophic impacts on assets, resources or health, safety and environment | 151, including all Level 2 and Level 3 controls |
| Level 2 (L2) | Moderate criticality, with significant effects on operations, assets, resources or health, safety and environment | 117, including all Level 3 controls |
| Level 3 (L3) | Low criticality, with moderate adverse effects on operations, assets, resources or health, safety and environment | 56 |
The levels are cumulative, so a Level 1 facility carries roughly three times the requirements of a Level 3 one, and the additional controls are the hardest to engineer. Those applying at Level 1 alone include automated asset inventory collection, an identity lifecycle separate and independent from information technology, dedicated hardened engineering workstations and human machine interfaces, continuous in-depth log review, user behaviour analytics, and industrial threat intelligence feeding monitoring alerts.
Level assignment is itself a formal control requiring an approved methodology, and the Authority issues a Facility Level Identification Tool for it. The assigned level defines the scope of the programme and every estimate of cost, effort and duration derived from it. An incorrect classification does not reduce the work, it produces a plan built against the wrong control set, and the discrepancy usually emerges during assessment rather than planning.

How Compliance Is Assessed
Compliance is not self-declared and accepted on that basis. The Authority evaluates it through self-assessment by the organisation and through audit field visits conducted by the Authority or by third parties it designates, and issues an Assessment and Compliance Tool to structure the measurement. The framework additionally requires two internal reviews, both applying at all three levels.
- Annual review by the cybersecurity function: the organisation's own cybersecurity function must review implementation of the controls at least once a year.
- Independent review every three years: implementation must also be reviewed by independent parties from outside the cybersecurity function at least once every three years.
How Beacon Security Can Help
Beacon Security works exclusively in operational technology and industrial control system security across the Middle East, in oil and gas, petrochemicals, power generation, water and heavy manufacturing. Our services map directly onto what the OTCC requires.
- ICS/OT Cybersecurity Design: Security architecture for new and expanding plants, defining the zones and conduits, the demilitarised zone, the jump host and the separation of safety systems, issued as a design package suitable for construction.
- OT Policy and Procedure Development: OT cybersecurity policies, procedures and supporting guidelines, with ownership assigned for each and a defined review cycle to keep them current.
- ICS/OT Cybersecurity Assessment: Measurement of an existing OT environment against the framework, through three services.
- OT Risk Assessment: Identification and rating of the cybersecurity risks to the process, using a method integrated with the existing safety risk process, recorded in an OT risk register.
- OTCC Gap Assessment: Control-by-control evaluation of the OT environment at the applicable facility level, with the supporting evidence recorded for each control and a gap register issued alongside a prioritised remediation plan.
- OT Vulnerability Assessment: Identification of technical weaknesses across OT assets, scoped to avoid disturbance to production and ranked for remediation.
- OT Penetration Testing: Controlled simulated attack against deployed defences, conducted safely against production or against an identical offline environment, reporting the access achieved and the corrective actions required.
- ICS/OT Cybersecurity Implementation: Deployment of the controls, covering network segmentation and the demilitarised zone, firewalls, intrusion detection, secure remote access, device hardening, patch management, and backup coverage for engineering files and controller logic, handed over with as-built documentation on completion.
- ICS/OT SOC Deployment: Monitoring and detection for the OT environment, tuned to industrial protocols and OT threat intelligence rather than to enterprise alerting, together with the incident response procedures that support it.
- ICS/OT Security Training: Competence building for personnel working on and around control systems, including contractors, through three services.
- OT Cybersecurity Awareness Training: Training for operations and engineering personnel in the safe and secure handling of OT assets, with attendance and completion recorded.
- OT Cybersecurity Tabletop Exercises: OT incident scenarios run with the response, engineering and management teams, documenting the outcome and the corrective actions arising.
- OT Cybersecurity Testbed Development: An offline environment in which patches, changes and functionally equivalent replacement devices are validated before deployment to production.
Facility level identification precedes scoping, so that the programme is sized against the controls that apply. Remediation is then sequenced around maintenance windows, vendor dependencies and warranty conditions, and the documentation prepared for both the annual internal review and the independent review required every three years.
![]()
This is a general awareness guide, and it is not a substitute for the Operational Technology Cybersecurity Controls (OTCC-1:2022), the Essential Cybersecurity Controls, or the current guidance of the National Cybersecurity Authority, all of which take precedence. Beacon Security helps industrial organisations across Saudi Arabia and the wider Middle East achieve and sustain compliance with the NCA OTCC and ECC frameworks, mapped to IEC 62443. Contact us to discuss a facility level assessment, an OTCC gap assessment, or a compliance roadmap for your environment.

