The NCA Cybersecurity Framework: A Complete Guide for Saudi Businesses in 2026

Saudi Arabia's cybersecurity rules changed significantly at the start of 2026. For the first time, every private sector company in the Kingdom now falls under mandatory cybersecurity obligations, not just government bodies and critical infrastructure operators. This guide explains exactly what that means, which rules apply to your organisation, and what you need to do about it.

Saudi Arabia's cybersecurity rules changed significantly at the start of 2026. For the first time, every private sector company in the Kingdom now falls under mandatory cybersecurity obligations, not just government bodies and critical infrastructure operators. This guide explains exactly what that means, which rules apply to your organisation, and what you need to do about it.

What Is the NCA and Why Does It Matter?

The National Cybersecurity Authority (NCA) is Saudi Arabia's sole national cybersecurity regulator. Established by Royal Order in 2017 and linked directly to the King, it sits outside any single ministry and holds authority over cybersecurity requirements across the entire Kingdom. This structure gives the NCA broader reach and independence than most equivalent bodies in the region.

The NCA's job is to set, issue, and enforce the cybersecurity frameworks that government bodies, critical infrastructure operators, and now every private company in Saudi Arabia must follow. It also coordinates national cybersecurity strategy, monitors cyber threats at the national level, and licenses organisations that provide managed security services in the Kingdom.

The NCA Cybersecurity Regulations 2024 gave the authority formal enforcement powers it did not previously hold. It can now carry out inspections without prior notice, demand documentation and evidence, and impose financial penalties. Non-compliance is no longer a reputational risk; it is a legal and financial one.

Important distinction: The NCA is not the same as SDAIA (which enforces the PDPL data protection law) or SAMA (which regulates cybersecurity in the financial sector). Some organisations in Saudi Arabia must comply with all three regulators simultaneously. The NCA framework is the cybersecurity baseline, and the others layer on top of it.

The NCA Framework Family: Which Framework Applies to You?

The NCA has published a connected family of cybersecurity frameworks. The Essential Cybersecurity Controls (ECC) are the foundation that everyone builds from, and the other frameworks add specific requirements for particular environments, sectors, or technologies. Understanding which apply to your organisation is the first compliance step.

Framework Full Name Who It Covers Status
ECC-2:2024 Essential Cybersecurity Controls Government entities, their affiliates, and private companies owning or operating Critical National Infrastructure (CNI) Mandatory
NCNICC-1:2025 Cybersecurity Controls for Non-CNI Private Sector Entities All private sector companies in Saudi Arabia not already covered by ECC as CNI operators. Released January 2026. Mandatory
CCC-2:2024 Cloud Cybersecurity Controls Organisations using or providing cloud computing services in Saudi Arabia Mandatory (in-scope)
CSCC Critical Systems Cybersecurity Controls Operators of systems where failure or compromise would have national-level impact Mandatory (in-scope)
OTCC-1:2022 Operational Technology Cybersecurity Controls Organisations with industrial control systems: energy, utilities, manufacturing, water Mandatory (in-scope)
DCC-1:2022 Data Cybersecurity Controls Organisations processing or storing significant data assets in Saudi Arabia Advisory (recommended)
TCC Telework Cybersecurity Controls Organisations with remote-working employees accessing corporate systems Advisory (recommended)

The January 2026 change that affects every private company: Before NCNICC-1:2025, many organisations in Saudi Arabia believed NCA frameworks applied only to government bodies and critical infrastructure. That assumption is no longer valid. Since January 2026, every private company operating in the Kingdom—including technology companies, SaaS providers, retail businesses, logistics firms, and professional services organisations—must implement a defined baseline of cybersecurity controls under NCNICC-1:2025.

Who Must Comply: ECC vs NCNICC-1:2025

The framework that applies to your organisation depends on whether you are considered a Critical National Infrastructure (CNI) operator or an ordinary private sector entity.

  • ECC-2:2024 applies to: All Saudi government entities, including ministries, authorities, and government-owned companies inside and outside the Kingdom. It also applies to any private sector company that owns, operates, or hosts Critical National Infrastructure, which includes energy, water, finance, healthcare, telecoms, and transport infrastructure designated by the government.
  • NCNICC-1:2025 applies to: Every other private sector company operating in Saudi Arabia that is not already covered by the ECC as a CNI operator. This includes IT companies, technology providers, e-commerce platforms, retail chains, logistics businesses, professional service firms, and startups.

Within NCNICC-1:2025, organisations are divided into two classes based on size:

  • Class A (Large Entities): Organisations with 250 or more employees, or annual revenue of SAR 200 million or above. Class A organisations must implement all mandatory controls and undergo an independent audit by an NCA-approved third party. A licensed managed SOC is mandatory for Class A.
  • Class B (Small and Medium Entities): Organisations below the Class A thresholds. Class B has 26 mandatory controls, with the remaining 39 recommended. Independent audits are recommended but not mandatory.

Both Class A and Class B must implement the same core baseline: multi-factor authentication, data encryption, regular system backups, and incident response logging. These four controls are the non-negotiable minimum for every private company in Saudi Arabia from 2026 onward.

ECC-2:2024: The 4 Domains and 108 Controls Explained

ECC-2:2024, published in October 2024, updated the original 2018 framework by reducing the control count from 114 to 108, restructuring from five domains to four, and introducing a tier-based compliance model. Here is what each domain actually requires from your IT team.

NCA ECC-2:2024 Four Domains Explained
  • Domain 1: Cybersecurity Governance (15 subdomains · 60 controls): Establishes the organisational foundation: cybersecurity strategy, policies, defined roles and responsibilities, risk management processes, regulatory compliance obligations, and staff awareness training. This domain requires that every organisation has a written cybersecurity strategy approved at leadership level and reviewed on a defined cycle.
  • Domain 2: Cybersecurity Defense (15 subdomains · 60 controls): The technical controls layer: asset management, identity and access management (IAM), network security, encryption, vulnerability management, application security, email security, and endpoint protection. This is where most of the day-to-day IT security work lives, and where NCA inspectors find the most gaps.
  • Domain 3: Cybersecurity Resilience (1 subdomain · 4 controls): Ensures your organisation can continue operating during a cyber incident and recover quickly after one. Controls focus on integrating cybersecurity into business continuity management, defining incident response procedures, and establishing recovery time objectives for critical systems.
  • Domain 4: Third-Party and Cloud Security (2 subdomains · 8 controls): Addresses the risk that comes through your supply chain and cloud environment. Requires formal vendor assessments before onboarding suppliers with access to your systems, contractual security obligations in third-party agreements, and specific controls for cloud-hosted workloads. This domain aligns closely with the separate NCA Cloud Cybersecurity Controls (CCC).

What changed from ECC-1:2018 to ECC-2:2024: The 2018 version had 114 controls across 5 domains, including a standalone domain for Industrial Control Systems. ECC-2:2024 reduced the count to 108, consolidated into 4 domains, introduced a tier-based compliance model, and expanded the Saudization requirement to cover all cybersecurity roles, not just senior ones.

The 2024 Change You Cannot Ignore: Cybersecurity Saudization

One change in ECC-2:2024 has caught many foreign and multinational companies off guard. The framework now requires that all cybersecurity positions, not just senior roles, are filled by qualified Saudi nationals. ECC-1:2018 applied this requirement only to the head of the cybersecurity function and certain supervisory roles. The 2024 update expanded it across every position in the cybersecurity team.

This has direct hiring implications for any organisation that currently staffs its security function with non-Saudi professionals. The Saudi Cybersecurity Workforce Framework (SCyWF), published by the NCA, defines the qualifications, experience requirements, and academic credentials that apply to each role.

Practical note for IT companies operating in KSA: Outsourcing your cybersecurity function to an NCA-registered managed security service provider with a qualified Saudi workforce is the most efficient solution for organisations that cannot fully staff a Saudi in-house team. Class A organisations under NCNICC-1:2025 are specifically required to use a licensed managed SOC, making this a compliance requirement, not just a convenience.

NCA ECC vs ISO 27001: What Is the Difference?

Many organisations in Saudi Arabia have invested in ISO 27001 certification and ask whether that work carries over to NCA ECC compliance. The short answer is that it helps significantly but does not replace it. Here is how the two compare.

Area NCA ECC-2:2024 ISO 27001:2022
Issuing body National Cybersecurity Authority, Saudi Arabia International Organisation for Standardisation (ISO)
Geographic scope Saudi Arabia only. Mandatory for in-scope organisations. International. Voluntary certification standard.
Legal standing in KSA Binding regulation with financial penalties and licence suspension for non-compliance. No direct legal standing under Saudi law. Voluntary.
Audit requirement NCA-conducted or NCA-approved third-party assessment. Self-assessment for smaller organisations. Independent accredited certification body audit every 3 years.
Control specificity Prescriptive: 108 specific controls with defined implementation requirements. Principles-based: 93 controls in Annex A, with flexibility in implementation approach.
Control overlap Approximately 60 to 70 per cent of underlying technical controls overlap between the two frameworks. An existing ISO 27001 programme significantly reduces the NCA ECC gap assessment workload.

The right approach for ISO 27001-certified organisations: Do not start your NCA compliance programme from zero. Map your existing ISO 27001 controls against the four ECC domains first. You will find a substantial foundation already in place, particularly in governance, access management, encryption, and incident response. The remaining gaps, typically in Saudization, Saudi-specific technical baselines, and the cloud domain, can then be addressed as a targeted remediation programme.

What Are the Penalties for Non-Compliance?

The NCA Cybersecurity Regulations 2024 created a formal enforcement regime with real financial consequences. A specialist Violations Committee has the authority to investigate alleged breaches, demand documentation, and impose penalties. Decisions can be appealed before the Administrative Court within 60 days of notification.

The full range of penalties available to the Committee includes:

  • A written warning for first or minor violations.
  • Fines of up to SAR 25 million (approximately USD 6.66 million) per violation.
  • Temporary or permanent suspension of the organisation's operating licence.
  • Suspension of a specific service or business activity.
  • Public disclosure of the violation at the organisation's expense.
  • Mandatory remediation, with any financial gains from the non-compliant activity transferred to the state treasury.

The commercial risk goes beyond fines: Many Saudi government contracts and large enterprise procurement processes now require demonstrable NCA compliance before an organisation can even bid. Non-compliance does not just create regulatory exposure; it creates a direct barrier to government and enterprise revenue in one of the fastest-growing markets in the region.

NCA Regulatory Timeline

  • 2017: NCA established by Royal Order. Linked directly to the King.
  • 2018: ECC-1:2018 published. 114 controls, 5 domains. Applies to government and CNI operators.
  • October 2024: ECC-2:2024 published. Restructured to 108 controls, 4 domains. Saudization requirement expanded to all cybersecurity roles.
  • 2024: NCA Cybersecurity Regulations 2024 published. NCA granted formal enforcement powers: inspections, penalties up to SAR 25M, licence suspension.
  • January 2026: NCNICC-1:2025 published. Every private sector company in Saudi Arabia now under mandatory NCA cybersecurity obligations for the first time.

How to Achieve NCA Compliance: A Practical 7-Step Roadmap

Whether you are starting from zero or building on an existing ISO 27001 or SAMA framework, the approach is the same: assess where you are, fix what is missing, and demonstrate it to the NCA. Here are the seven steps your IT and security team should follow.

How to Achieve NCA Compliance: A Practical 7-Step Roadmap
  1. Determine Which Frameworks Apply to Your Organisation: Start by establishing whether you fall under ECC-2:2024 as a government entity or CNI operator, or NCNICC-1:2025 as a non-CNI private sector company. Then assess whether additional frameworks apply: CCC-2:2024 if you use or provide cloud services, OTCC-1:2022 if you operate industrial control systems, or CSCC if you operate systems with national-level criticality. Most IT companies and managed service providers will be subject to both NCNICC-1:2025 and CCC-2:2024 at minimum.
  2. Run a Gap Assessment Against the Applicable Controls: A gap assessment compares your current security posture against each applicable NCA control and identifies what is missing, partially in place, or fully compliant. This produces your compliance baseline and tells you exactly where to prioritise remediation effort. For Class A organisations under NCNICC-1:2025, this assessment must be completed before an independent audit. If you have existing ISO 27001 or SAMA CSF documentation, use it as input to avoid duplicate work.
    GBG tip: GBG's security team conducts NCA gap assessments for enterprise clients in Saudi Arabia.
  3. Build Your Cybersecurity Governance Structure: Domain 1 of ECC-2:2024 requires a written, leadership-approved cybersecurity strategy, formal policies for every major security area, documented roles and responsibilities, a risk management process, and an annual staff awareness training programme. Many organisations have some of these elements in place informally. NCA compliance requires them to be formally documented, reviewed on a defined schedule, and accessible to assessors as evidence.
  4. Implement the Technical Controls (Domain 2): This is the largest workload in most compliance programmes. At minimum, your infrastructure must include: multi-factor authentication for all accounts with access to sensitive systems; encryption for data at rest and in transit; endpoint protection on every device; network segmentation between sensitive and general environments; a documented vulnerability management process with regular scanning and patching; and application security controls for any customer-facing or internal web applications. Penetration testing is required as part of the NCA assessment process.
    GBG tip: GBG's MSSP solution and Zero Trust Security Service directly implement the technical control requirements across Domains 1 and 2.
  5. Address Third-Party and Cloud Security (Domain 4): Review every vendor with access to your systems or data. Formal vendor security assessments must be completed before onboarding, and third-party contracts must include explicit cybersecurity obligations. For cloud deployments, organisations must implement the relevant controls from the NCA Cloud Cybersecurity Controls (CCC-2:2024), including data classification before cloud hosting, access control policies, and incident response procedures aligned to your cloud provider's notification timelines.
    GBG tip: GBG's Cloud Solutions team designs Azure architectures that align with CCC-2:2024 requirements and the NCA's data residency expectations.
  6. Plan Your Cybersecurity Workforce Saudization: ECC-2:2024 requires all cybersecurity positions to be held by qualified Saudi nationals. Audit your current cybersecurity team composition and assess the gap. For organisations that cannot immediately hire qualified Saudi nationals for all roles, the two main approaches are: a phased Saudization hiring plan with a defined timeline, or partnering with an NCA-registered managed security service provider whose security operations team already meets the Saudi workforce requirement. Both approaches are accepted by the NCA, but the arrangement must be documented and defensible.
  7. Prepare for the NCA Assessment: NCA compliance assessments can take the form of self-assessment for smaller organisations, NCA-conducted inspections, or independent third-party audits which are mandatory for Class A under NCNICC-1:2025. Prepare an evidence pack covering each domain: governance documentation, technical control implementation records, penetration test reports, staff training records, vendor assessment files, and incident response procedures. For Class A organisations, an NCA-registered audit firm must conduct the independent assessment. Register your organisation on the NCA's portal and ensure you have designated authorised representatives who can respond to NCA queries within the required timeframes.
    GBG tip: GBG's security team supports clients through the full NCA assessment preparation process.

Frequently Asked Questions About the NCA Cybersecurity Framework

What is the NCA cybersecurity framework in Saudi Arabia?

The National Cybersecurity Authority (NCA) is Saudi Arabia's national cybersecurity regulator, established by Royal Order in 2017. The NCA cybersecurity framework is a family of mandatory control standards that government entities, critical infrastructure operators, and private sector companies must implement. The foundational standard is the Essential Cybersecurity Controls (ECC-2:2024), which covers 108 controls across 4 domains: governance, defense, resilience, and third-party and cloud security.

Does the NCA ECC apply to private sector companies in Saudi Arabia?

The ECC itself applies to government entities and private companies that own or operate Critical National Infrastructure. However, since January 2026, all other private sector companies in Saudi Arabia must comply with a separate but related standard, NCNICC-1:2025, which was specifically designed for non-CNI private sector entities. As of 2026, no private company operating in Saudi Arabia is exempt from mandatory NCA cybersecurity obligations.

What is the difference between ECC-1:2018 and ECC-2:2024?

ECC-2:2024 updated the original 2018 framework in three main ways. First, the control count was reduced from 114 to 108 and the structure was consolidated from 5 domains to 4, with the standalone Industrial Control Systems domain integrated into the main framework. Second, a tier-based compliance model was introduced. Third, and most significantly for operational planning, the Saudization requirement was expanded: ECC-2:2024 requires all cybersecurity positions, not just senior roles, to be filled by qualified Saudi nationals.

What is NCNICC-1:2025 and who must comply with it?

NCNICC-1:2025 stands for Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities. It was published by the NCA in January 2026 and is the first NCA framework written specifically for ordinary private companies that are not CNI operators. It applies to all private sector organisations in Saudi Arabia, including technology companies, SaaS providers, retail businesses, logistics firms, and professional services organisations. Organisations are classified as Class A (large, 250 or more employees or SAR 200M revenue) or Class B (smaller entities), with proportionate but mandatory compliance requirements for both.

What are the four domains of NCA ECC-2:2024?

The four domains are: Cybersecurity Governance (15 subdomains, 60 controls covering strategy, policies, roles, risk management, and training); Cybersecurity Defense (15 subdomains, 60 controls covering asset management, identity and access management, network security, encryption, vulnerability management, and endpoint protection); Cybersecurity Resilience (1 subdomain, 4 controls covering business continuity and incident response integration); and Third-Party and Cloud Cybersecurity (2 subdomains, 8 controls covering vendor risk and cloud security).

What are the penalties for non-compliance with NCA regulations?

Under the NCA Cybersecurity Regulations 2024, the penalties include: written warnings; fines of up to SAR 25 million (approximately USD 6.66 million) per violation; temporary or permanent licence suspension; suspension of a specific service or business activity; and public disclosure of the violation at the organisation's expense. Organisations can appeal decisions before the Administrative Court within 60 days. Beyond formal penalties, non-compliance increasingly bars organisations from government procurement and large enterprise contracts in Saudi Arabia.

What is the Saudization requirement in ECC-2:2024?

ECC-2:2024 requires that all cybersecurity positions in in-scope organisations are filled by full-time, qualified Saudi nationals. This is an expansion from ECC-1:2018, which only applied this requirement to senior and supervisory cybersecurity roles. For foreign and multinational companies with international cybersecurity teams operating in Saudi Arabia, this requires either a direct hiring programme aligned to the Saudi Cybersecurity Workforce Framework (SCyWF), or partnering with an NCA-registered managed security service provider whose team meets the Saudi workforce requirement.

How does NCA ECC compare to ISO 27001?

NCA ECC compliance is a mandatory legal obligation for in-scope Saudi organisations. ISO 27001 is a voluntary international certification standard. Approximately 60 to 70 per cent of the underlying technical controls overlap between the two frameworks, so an existing ISO 27001 programme provides a significant head start on ECC compliance. However, ISO 27001 certification does not substitute for NCA ECC compliance, and NCA assessors require evidence of Saudi-specific controls including Saudization, Saudi-specific governance documentation, and alignment with the NCA's technical baseline requirements.

How does the NCA conduct compliance assessments?

The NCA conducts compliance assessments through three main methods. First, self-assessment, where organisations assess their own compliance using NCA tools and checklists, primarily applicable to smaller entities. Second, direct NCA-conducted inspections, which can happen without prior notice under the NCA Cybersecurity Regulations 2024. Third, independent audits by NCA-approved third-party assessors, which are mandatory for Class A organisations under NCNICC-1:2025. All methods require organisations to produce documented evidence across each domain.

What is the difference between the ECC, CCC, and CSCC?

These are three separate but related NCA frameworks. The ECC (Essential Cybersecurity Controls) is the foundational baseline for government entities and CNI operators. The CCC (Cloud Cybersecurity Controls) applies specifically to organisations using or providing cloud computing services and adds cloud-specific requirements on top of the ECC baseline. The CSCC (Critical Systems Cybersecurity Controls) applies to operators of systems whose failure would have national-level consequences and adds further requirements beyond the ECC for those environments. Organisations may be subject to more than one framework simultaneously.


Not Sure Which NCA Framework Applies to Your Business?

Our KSA-based security team conducts NCA gap assessments that identify exactly which frameworks apply to your organisation, map your current controls against the requirements, and deliver a prioritised remediation plan, without the legal jargon.

No commitment required · 30-minute consultation with a GBG security engineer · Available for KSA and Egypt-based teams.

Legal disclaimer: This article provides general information about the NCA cybersecurity framework for educational purposes. It does not constitute legal or regulatory advice. For guidance specific to your organisation's circumstances, consult a qualified cybersecurity compliance professional or legal adviser with expertise in Saudi regulations.

...

Need a bespoke IT solution for your business?

Start a complimentary and obligation-free 30-minute consultation with our business development engineers. Together, we’ll design an IT solution that suits your business operations and scale.

Global Brands Group has been inaugurated with an inventive spirit, and this spirit continues to guide us through our journey. Ever- listening and -answering to industry shifts and demands, GBG grows, transforms and caters to an ever-expanding customer base.

preloader