Six months is EIE’s planning assumption for a first NCA Essential Cybersecurity Controls programme, but only when the schedule is assembled around evidence rather than intentions. Here is what those twenty-six weeks look like phase by phase, what each phase has to produce, and where Saudi organisations most often lose the date.
Scope note: practical guidance drawn from published frameworks and field practice; it is not legal advice. Verify current requirements with the regulator.
Durations in this article are EIE’s indicative planning models, not regulator deadlines or predicted outcomes. NCA communicates compliance expectations through its own correspondence and the sector regulators.
Our NCA implementation guide describes the default twelve-month cadence. This article is the compressed path for organisations whose audit window is shorter.
Why six months is the planning assumption
Every organisation approaching the Essential Cybersecurity Controls for the first time hears the same estimate: about six months. It is a reasonable planning figure rather than a regulator deadline, and it is also why so many programmes overrun. Six months is not a duration you can purchase. It is a duration you earn by holding a sequence, and the sequence is unforgiving. Run phases in parallel that cannot be, or leave evidence until the end, and the same scope stretches towards eighteen months without anyone deciding that it should.
The National Cybersecurity Authority publishes the ECC as the national floor, spanning cybersecurity governance, defence, resilience and third-party security, with an elevated control set for organisations whose disruption would carry national consequence. The control text is public and finite. What is not public is the operating rhythm that converts a control list into an audit-ready posture.
The gap pattern is consistent across sectors. Technical controls are usually in better shape than the sponsor expects, because perimeter filtering, endpoint detection, multi-factor authentication and backup tooling already exist in some form. Governance is usually worse: no asset inventory reflecting the estate as it stands today, no risk register anyone updates, no minuted board oversight, no supplier assessment file, no evidence the incident plan has ever been exercised. A programme that opens by procuring tooling has misread the gap.
The twenty-six-week ECC implementation timeline
The table below is the sequence as it works in practice. Week numbers are indicative and phases overlap at their edges, but the order does not change: you cannot package evidence for controls that do not yet exist, and you cannot rehearse against an incomplete package.
| Phase | Weeks | Work in the phase | Evidence the phase must produce |
|---|---|---|---|
| 1. Discovery and gap analysis | 1 to 2 | Documentation review, stakeholder interviews and control-by-control assessment across every domain in scope. | Gap analysis with maturity scoring, a written scoping statement, a prioritised remediation list. |
| 2. Roadmap and quick wins | 3 to 6 | Findings converted into a task plan with an accountable name and a date on every item. Low-effort fixes executed now. | Approved plan, responsibility matrix, governance calendar, first closed findings. |
| 3. Implementation by control domain | 7 to 16 | The long phase. Each control receives documentation, technical change, process change and training, with governance and third-party work running alongside. | Implemented controls, each with a traceable change record and a named caretaker. |
| 4. Evidence collection and packaging | 17 to 22 | Every in-scope control mapped to its proof: configuration exports, log samples, approval records, training registers, exception register, supplier assessments. | A structured evidence repository indexed to the control set. |
| 5. Audit preparation and dry run | 23 to 26 | Internal or independent rehearsal against the package, interview practice for caretakers, triage of whatever the rehearsal surfaces. | Rehearsal report, closed corrective actions, an organisation that can be examined. |
Inside each phase
Weeks 1 to 2: discovery and gap analysis
The programme opens with documentation review and stakeholder interviews rather than with scanning. The purpose of the first fortnight is an accurate current state across every domain in scope, scored control by control, plus a scoping statement saying explicitly which entities, systems and data classes are covered and which are not. Scope written loosely here is the most expensive mistake available, because every later phase inherits it.
Two questions decide everything that follows. Is the organisation assessed against the essential control set alone, or does its designation pull in the Critical Systems Cybersecurity Controls (CSCC) as well? And does the estate contain operational or industrial control technology, which NCA covers through the separate OTCC extension? Most administrative environments do not, and that question closes quickly. For scale: ECC-2:2024 runs to 108 main controls and 92 subcontrols across four domains, and CSCC-1:2019 adds 32 main controls and 73 subcontrols for national critical systems. Where such technology exists, it deserves a dedicated work stream from week one.
Weeks 3 to 6: roadmap and quick wins
Gap findings become a task plan with an accountable person and a date against every item. This is also when the cheap findings get closed, because momentum matters to sponsors: logging gaps closed, the asset register brought current, dormant accounts removed, the exception register created, policy drafting started so that legal review proceeds while technical work continues.
The deliverable that matters most here is not the plan. It is the governance calendar: a fixed weekly working session and a fixed monthly steering review, with dates placed in diaries now rather than negotiated later. Programmes that skip this step routinely lose weeks to rescheduling before they reach week twenty.
Weeks 7 to 16: implementation by control domain
This is the long phase, and the one most likely to be underestimated, because each control needs four things rather than one: documentation, technical change, process change and training. A control is not implemented when the setting is enabled. It is implemented when an accountable person can describe how it operates, demonstrate it, and show that it operated last quarter too.
Governance is usually the slowest domain, because policy approval runs at the speed of committees rather than change tickets. Third-party security is usually the most under-scoped, because the supplier inventory is always bigger than the finance system suggests. Every party holding credentialed access belongs in it, including facilities contractors, application support providers and anyone with a remote-access path granted long ago and never reviewed since.
Weeks 17 to 22: evidence collection and packaging
Auditors do not accept assertions. They accept artefacts, and the artefacts have to be findable. This phase maps every in-scope control to its proof: configuration exports, representative log samples with retention demonstrated, approval records carrying dates and approvers, training registers, the exception register with expiry dates and compensating measures, supplier assessment outcomes, and minutes of the exercises showing resilience was tested rather than merely planned.
Structure the repository to the control set. An evidence store organised by team is a store nobody can navigate under audit pressure, and an examiner who cannot find the proof records the finding as though the proof did not exist.
Weeks 23 to 26: audit preparation and dry run
The rehearsal is the cheapest phase and the one most often cut. A dry run tests three things: whether the package answers the control text, whether the people accountable for each control can explain it under questioning, and whether the exception register survives scrutiny. Findings raised here cost a fortnight. The same findings raised in a real examination cost a cycle.
Where the six months are usually lost
- Sponsor availability. Executive reviews slip because diaries were never locked. Fix the dates for all twenty-six weeks in week one.
- Policy approval cycles. Committee review is measured in weeks, not days. Start drafting in week three so approval runs alongside implementation instead of after it.
- Third-party inventory. The supplier list is always longer than expected. Give it a dedicated resource from week five rather than treating it as a side task.
- Evidence sprawl. Proof collected ad hoc into shared drives cannot be assembled at the end. Open the structured repository on day one and file as you go.
- Silent scope drift. A subsidiary, a cloud tenancy or an acquired system appears in month four and resets the gap analysis. Fix scope in writing, and change it only through the steering review.
- Treating the audit as the finish line. Controls have to keep operating afterwards, so the recurring cadence belongs in business-as-usual before the programme closes.
When the audit window is shorter than six months
Compressed programmes are possible, typically at around four months, but the compression is real and it is paid for somewhere. Discovery and roadmap collapse into a single three-week block, which means the sponsor decides scope rather than discovering it through interviews. Evidence packaging runs concurrently with implementation, demanding discipline from every work stream rather than a coordinator at the end. And the organisation has to accept a documented remediation plan for a small set of controls that will not be fully operational on audit day.
What cannot be compressed is committee time and human change. If policy approval needs three committee cycles, no amount of resourcing shortens it, and a four-month plan assuming otherwise is a six-month plan with an optimistic cover page.
Where EIE fits
EIE supports Saudi organisations with the engineering side of this work: assessment, control design and remediation, monitoring and response arrangements governed by each customer’s service agreement, and audit-ready evidence packs — from our Jeddah headquarters, with Kingdom-wide service coverage. Talk to our team.
Frequently asked questions
Does the six-month timeline change if we fall under the Critical Systems Cybersecurity Controls (CSCC)?
Yes. The CSCC extension adds depth to the same four domains, so budget additional weeks for the extra controls and their evidence; the sequence of phases does not change.
Can an ECC programme run at the same time as a personal-data compliance programme?
Yes, and it is normally cheaper than running them in sequence, because the asset inventory, data classification, access reviews, supplier assessments and incident records serve both regimes. The mistake is running them as separate projects with separate repositories, which duplicates effort and produces contradictory evidence.
How much of the programme can be delivered by an external team?
The assessment, the roadmap, much of the technical change and the evidence packaging can be. Accountability cannot. The control caretakers named in the responsibility matrix are the people an examiner interviews, so each needs to be an employee who can explain the control without a script.
When should we start, relative to the audit date?
Count back twenty-six weeks from the examination, then add a buffer for the committee calendar and for leave periods. Starting later is possible. Starting later and expecting an unchanged outcome is not.
Sources and further reading
The authoritative texts are published by the bodies that supervise them, and should be read at source rather than through a summary, including this one. The National Cybersecurity Authority publishes the Essential Cybersecurity Controls (ECC-2:2024), the Critical Systems Cybersecurity Controls (CSCC-1:2019) and the Operational Technology Cybersecurity Controls (OTCC-1:2022). The Saudi Data and Artificial Intelligence Authority publishes the Personal Data Protection Law and its Implementing Regulations, which overlap with several ECC domains. The Saudi Central Bank publishes its Cyber Security Framework for supervised financial institutions.
Related: Cybersecurity and compliance solutions and talk to us about your ECC timeline.