Saudi OTCC-1:2022 — Operational Technology Cybersecurity Controls
OTCC-1:2022 is a mandatory cybersecurity regulation for operational technology environments in Saudi Arabia. Issued by the NCA, it defines 47 main controls and 122 sub-controls across 4 domains covering OT governance, asset protection, vulnerability management, and incident response. Non-compliance carries fines up to SAR 25 million.
47
Main Controls
122
Sub-Controls
SAR 25M
Max Fine
Mandatory
For CNI
OT cybersecurity strategy, organisational structure, roles and responsibilities, and periodic compliance reviews aligned with NCA requirements.
OT asset inventory, network segmentation, secure remote access, and access control specifically designed for operational technology environments.
OT-specific risk assessments, vulnerability scanning, and patch management adapted for operational continuity and safety requirements.
OT incident detection and response procedures, disaster recovery for OT systems, and mandatory NCA incident reporting.
Identify all OT assets and systems within NCA regulatory scope and determine applicable OTCC controls.
Evaluate current OT security posture against all 122 sub-controls and document gaps.
Establish OT cybersecurity policies, roles, reporting structures, and NCA compliance processes.
Implement network segmentation, access controls, monitoring, and secure remote access for OT environments.
Prepare comprehensive evidence and documentation for NCA audit and compliance review.
Ongoing compliance monitoring, periodic reassessment, and mandatory NCA reporting obligations.