Wadira: Find your way through Saudi data & privacy law.
Home › Frameworks › Cybersecurity › Operational Technology Cybersecurity Controls: Methodology & Mapping Annex
| Type | Framework |
|---|---|
| Issuing authority | National Cybersecurity Authority (NCA) |
| Framework | Cybersecurity |
| Tier | Rules, controls & standards |
| Legal status | Guidance |
The Operational Technology Cybersecurity Controls Methodology and Mapping Annex (OTCCMM-1:2022) is a National Cybersecurity Authority annex explaining how the Operational Technology Cybersecurity Controls (OTCC-1:2022) were designed and how they relate to other standards. The OTCC are an extension of the Essential Cybersecurity Controls (ECC): applicable organisations comply with the ECC first, then with the additional OT-specific controls.
The annex sets out the OTCC design principles and methodology, the main domains and subdomains, and how controls and subcontrols are assigned to levels, and it details the relationship between the OTCC and ECC Domain 5. It also maps the controls to the international references used in their development, including the ISA/IEC 62443 series on security for industrial automation and control systems (62443-2-1, 62443-3-2 and 62443-3-3), the NIST Cybersecurity Framework and NIST Special Publication 800-53. It accompanies the OTCC and their separate implementation guide (GOTCC-1:2023).
Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13