Wadira: Find your way through Saudi data & privacy law.
Home › Frameworks › Cybersecurity › Guide to Critical Systems Cybersecurity Controls (CSCC) Implementation
| Type | Framework |
|---|---|
| Issuing authority | National Cybersecurity Authority (NCA) |
| Framework | Cybersecurity |
| Tier | Rules, controls & standards |
| Legal status | Guidance |
The Guide to Cybersecurity Controls for Critical Systems (CSCC) Implementation (GCSCC-1:2023) is the National Cybersecurity Authority's public implementation guide for the Critical Systems Cybersecurity Controls, helping in-scope organisations translate the controls into practice.
It opens with the components and architecture of the CSCC across their four domains (cybersecurity governance, cybersecurity defence, cybersecurity resilience, and third-party and cloud computing cybersecurity), with subdomains ranging from cybersecurity strategy, risk management and periodic review and audit through identity and access management, cryptography, penetration testing and vulnerability management to business-continuity resilience and cloud-hosting security. General implementation guidance is followed by guidance under each domain in turn. The CSCC themselves build on the NCA's Essential Cybersecurity Controls (ECC) baseline, tightening requirements for the critical national systems whose compromise would carry the greatest impact; the guide is part of the NCA's series of implementation guides for its control sets.
Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13