Solutions · Ministries

A ministry answers for its sector, not only for itself

Most ministry compliance programmes run one role well and forget the other two. You are a subject of the ECC like any entity, an overseer of everything affiliated beneath you, and often the body that sets policy for your sector. Those are three different jobs on three different clocks.

Three rolesSubject, overseer, policy-setter
Per entityAffiliated bodies keep their own scope
IsolatedEntities do not see each other
One viewSector coverage for the minister
This page reflects how we see compliance operate across ministry systems in practice. It is not an official reference. The relationship between a ministry and the entities affiliated to it varies considerably, and the authoritative sources for obligations are the documents published by the NCA, SDAIA, the NDMO and the DGA — confirm what applies to your ministry and to each affiliated entity against them.

Is this you, or one of the entities beneath you?

Both pages exist and they describe different problems. Thirty seconds now saves reading the wrong one.

Ministry

You answer for a sector

You carry your own ECC obligations, oversee affiliated authorities, agencies, funds and programmes, and frequently set policy that the sector follows. The problem is running three roles at once without confusing them.

Government entity

You answer for yourself

One entity, its own scope, its own assessment, its own submission to the authority. The problem is building and evidencing a programme that survives an assessment. That page is here.

And distinct from both: a regulator supervises licensees it does not own — external bodies operating under a licence. A ministry oversees entities inside its own government system, which is a different relationship with different leverage and a different reporting line.

Three roles, one entity

From the compliance programmes we build and run in Saudi Arabia: the most common failure in a ministry is treating the ministry as a large government entity and stopping there. The assessment gets passed, the submission gets filed, and nobody can answer what the affiliated entities are actually doing — which is the question that arrives first when something goes wrong.

1

Subject

The ministry has its own systems, its own data and its own ECC scope, assessed like any other entity in scope. Specialised control documents may apply on top, and the PDPL applies to the personal data it holds regardless.

2

Overseer

Authorities, agencies, funds and programmes affiliated to the ministry each carry their own obligations. The ministry is expected to know their position, and the extent of its authority over them varies by entity.

3

Policy-setter

Where the ministry issues sector policy, it creates obligations for others — and is then expected to demonstrate that it meets the standard it set. A policy the issuer does not follow is the one that gets cited back.

The three interact awkwardly. Role one is measured by an external assessor, role two by whether you can answer for entities you do not operate, and role three by whether your own house matches your published position. Running them from one programme is what keeps them consistent.

What a ministry carries

More than a single framework, and issued by more than one authority.

ObligationIssued byApplies to
NCA ECC National Cybersecurity Authority The ministry, and separately each entity in scope beneath it
Specialised control documents National Cybersecurity Authority Where critical systems, cloud, data or telework are in play — added to the baseline, not replacing it
Data management standards National Data Management Office Government data governance, classification and management
Digital government policy Digital Government Authority Digital services, including cloud adoption decisions
Saudi PDPL SDAIA Personal data of citizens and residents, frequently at national scale
Sector policy The ministry itself The sector — and, by expectation, the ministry that issued it

Note the second column. These come from four different authorities with four different cycles, and none of them coordinates with the others on your behalf. The overlap between them is substantial and invisible unless something is holding the mapping.

The entities beneath you

Role two is where ministry programmes are weakest, because the reporting relationship was designed for budget and delivery rather than for compliance.

Varied authority

Not every entity answers the same way

An agency inside the ministry, an authority with its own legal personality, and a programme with its own governance are three different relationships. Recording what you can require of each, rather than assuming uniformity, is where this starts.

Separate scopes

Each carries its own ECC position

An entity in scope is assessed on its own, submits on its own, and is not covered by the ministry's submission. Ministries that assume otherwise discover it during the assessment rather than before.

Uneven capability

Maturity differs enormously

A large authority may run a stronger programme than the ministry itself; a small fund may have nobody assigned. Averaging across them hides both, and the weak one is where the incident happens.

Narrative reporting

Updates that cannot be verified

Asking entities to describe their compliance position produces documents of uneven quality that arrive late and cannot be checked. Structured records from each entity answer the same question and can be.

Shared services

Who owns the control?

Where the ministry provides infrastructure or identity services to affiliated entities, one control protects several entities — and the entity assessed on it is not the one operating it. That relationship needs to be recorded rather than assumed.

Escalation

What must reach the ministry, and when

Without a defined threshold, a ministry learns about a material incident in an affiliated entity from the authority, or from the news. That threshold is a governance decision, not a technical one.

Ministry systems in Govrly

Each entity runs its own programme. The ministry sees across the sector without taking over the work.

Isolation

Entities work separately

Each affiliated entity has its own space — its controls, its evidence, its findings. One entity does not see another's open findings, which matters because affiliated bodies are peers rather than branches.

Own scope

Each against its own obligations

An entity in ECC scope runs its own assessment and its own submission. A ministry-issued policy sits alongside as a custom framework, applied to the entities your authority actually reaches.

Sector view

Coverage without collection

The ministry sees coverage, open findings and overdue items across affiliated entities from their own records — rather than from documents someone had to write, submit and reconcile.

Shared controls

Ministry services mapped once

Where the ministry operates infrastructure serving several entities, that control is recorded once and mapped to every entity relying on it — so the entity being assessed can evidence a control it does not operate.

Four authorities

One control library

An access control implemented once answers to the NCA baseline, a specialised control document, a data management standard and a PDPL safeguard — from the same record, each scored in its own terms.

Policy-setting

Your own standard, measured on yourself

A sector policy defined as a framework and applied to the ministry alongside everyone else. Publishing a standard you have not applied internally is the finding that lands hardest.

A sequence that works

Ministries that start with the sector before their own house end up defending a position they have not built.

  1. Fix role one firstYour own ECC position, properly evidenced. Overseeing entities while your own assessment is weak is a conversation that ends badly, and it costs you the standing to ask them for anything.
  2. Map the affiliated entities as they areEvery authority, agency, fund and programme, what obligations each carries, and what your authority over each actually permits. This list rarely exists in one place.
  3. Record which entities are in scope of whatECC scope is not automatic and is not inherited from the ministry. Establishing this per entity prevents the most expensive assumption in government compliance.
  4. Identify the shared servicesWhere the ministry provides infrastructure, identity or hosting to entities beneath it, one control serves several assessments. Record who operates it and who relies on it.
  5. Replace narrative reporting with structured recordsEntities keep their own programmes; the ministry reads coverage from those records rather than from submitted documents. This removes work from the entities, which is how you get cooperation.
  6. Set the escalation threshold explicitlyWhat an affiliated entity must tell the ministry and within what period. Decide this before an incident rather than during one.
  7. Apply your own policy to yourselfIf the ministry issues a sector standard, run it against the ministry as a framework like any other. The gap between published and practised is the one external parties look for.
  8. Support the weakest entityThe small fund with nobody assigned is where the incident happens. Portfolio-level visibility exists to find it, not to average it away.
What this looks like in Govrly

The ministry runs its own ECC programme on one control library covering the NCA baseline, specialised control documents, data management standards and the PDPL — while affiliated entities work in isolated spaces against their own scopes, and the ministry reads sector coverage from their records rather than from submitted reports.

See it in a demo →

Ministries — FAQs

How is this different from the government entities page?

A government entity answers for itself — one scope, one assessment, one submission. A ministry answers for its sector: it carries its own obligations, oversees affiliated entities beneath it, and often sets policy others follow. If you are a single entity without affiliated bodies reporting to you, the government entities page fits better.

Are affiliated entities covered by the ministry's ECC submission?

Generally no. An entity in scope is assessed on its own and submits on its own. Assuming otherwise is one of the more expensive mistakes we see, because it surfaces during an assessment rather than before one. Establishing scope per entity is worth doing explicitly rather than by inference.

How much authority does a ministry have over affiliated entities?

It varies considerably. An internal agency, an authority with its own legal personality, and a programme with its own governance are three different relationships. Recording what you can require of each — rather than issuing a uniform instruction — prevents a ministry standard that half the sector is not obliged to follow.

Can entities see each other's compliance data?

No. Each affiliated entity works in its own isolated space with its own controls, evidence and findings. This matters because affiliated bodies are peers rather than branches of the same organisation, and they frequently compete for the same budget.

We provide shared infrastructure to entities beneath us. How is that handled?

The control is recorded once where it is operated and mapped to every entity relying on it, so an entity being assessed can evidence a control the ministry runs on its behalf. Without that mapping, the entity is asked for evidence it cannot produce and the ministry is asked for evidence nobody told it was needed.

Do we need to comply with our own sector policy?

In practice, yes — and it is worth treating as a requirement rather than an aspiration. A standard the issuer has not applied internally is the finding that lands hardest, because it is the easiest one for an external party to identify and the hardest to explain.

How do we handle four authorities issuing different requirements?

With one control library rather than four programmes. The NCA baseline, specialised control documents, data management standards and the PDPL overlap substantially — an access control implemented once answers to all four, scored in each one's own terms. Managed separately, the same evidence is requested four times.

Should the ministry collect reports from affiliated entities?

Reading coverage from their records is better than collecting documents from them. Narrative reporting produces documents of uneven quality that arrive late and cannot be verified, and it adds work to entities whose cooperation you need. Removing that burden is usually what makes the arrangement acceptable to them.

Which affiliated entity carries the most risk?

Frequently the smallest one. A large authority often runs a stronger programme than the ministry itself, while a small fund may have nobody assigned to compliance at all. Sector-level visibility exists to find that entity, which is precisely what an averaged score would hide.

Where should a ministry start?

With its own position. Overseeing a sector while your own assessment is weak costs you the standing to ask entities for anything, and it is the first thing an assessor will notice. Fix role one, then extend to role two.

See the sector without collecting reports

Each entity against its own obligations, and one view across for the ministry.