Saudi Arabia's NCA Extends Mandatory Cybersecurity Controls to the Private Sector

Saudi Arabia's National Cybersecurity Authority has issued new mandatory cybersecurity controls for private sector entities outside critical national infrastructure, extending baseline compliance obligations to businesses that have never previously fallen under national cybersecurity regulation.

Layla Haddad
Cyber Policy & Digital Risk Correspondent5 min read
Corporate compliance officer reviewing regulatory documentation in a Saudi Arabian office setting

Corporate compliance officer reviewing regulatory documentation in a Saudi Arabian office setting

Saudi Arabia's National Cybersecurity Authority has issued new Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities, establishing a mandatory baseline that extends the country's cybersecurity compliance architecture well beyond the government bodies, critical infrastructure operators, and heavily regulated sectors it has historically targeted.

Who now falls in scope

Building on our June compliance guide detailing the NCA's broader ECC-2 framework, the new NCNICC-1 framework explicitly distinguishes between two categories of entity based on size. Large entities, defined as those with more than 250 full-time employees or annual revenues exceeding SAR 200 million, face the framework's full requirements. Small and medium entities, defined as those with between 6 and 249 employees or annual revenues between SAR 3 million and SAR 200 million, face a narrower but still substantial mandatory baseline.

Crucially, the controls apply to relevant entities "as notified by the Authority," language that legal analysis from Baker McKenzie interprets as a residual power letting the NCA confirm classification in borderline cases and impose additional or heightened requirements on higher-risk sectors, rather than a precondition businesses can wait on before beginning compliance work. The firm's guidance is direct on this point: entities that clearly meet the size or revenue thresholds should not defer scoping and gap-assessment work pending a formal individual notification.

The scale of what large entities must implement

Large entities are required to implement a full set of three cybersecurity components, broken into 22 sub-components and 65 individual essential controls. Small and medium entities face a proportionate subset of 13 sub-components and 26 essential controls, some designated as recommended rather than mandatory.

The first component covers cybersecurity governance: documented policies, defined roles and responsibilities, a formal risk management methodology, staff awareness training, and periodic audit and compliance review. For large entities specifically, this includes a notable structural requirement: a cybersecurity function that sits independently from the IT function, with the head of cybersecurity and other sensitive roles held by suitably qualified Saudi nationals working on a fully dedicated basis.

The technical and third-party obligations

The second component sets the core operational baseline, spanning asset management, identity and access management including mandatory multi-factor authentication for remote access, secure configuration, network and endpoint security, mobile device security, email security aligned with the NCA's Haseen platform, data protection, cryptography aligned with the National Cryptographic Standards, backup and recovery, vulnerability management, penetration testing, logging and monitoring, incident and threat management, physical security, and web application security. That monitoring and incident-handling requirement lands on top of a trend already well underway across the region, where enterprises facing threats that outpace what internal teams can track unassisted have increasingly turned to continuous, round-the-clock threat monitoring as a structural rather than optional part of their security programme.

The third component addresses supply chain and cloud risk directly, requiring cybersecurity obligations to be embedded in third-party contracts, including confidentiality terms and incident communication clauses, alongside specific expectations for cloud and hosting arrangements covering data classification, tenant environment separation, and the return of data in a usable format upon contract termination. This is not a theoretical concern for the Kingdom. The exposure created when a widely deployed vendor is compromised has already played out in practice: when Trellix confirmed unauthorised access to its own source code repository earlier this year, the incident became a live illustration of exactly the third-party dependency risk this new framework is designed to force businesses to formally account for, rather than treat as an informal vendor management matter.

Why this reaches further than a typical compliance update

For small and medium entities, the framework is narrower than what large entities face but is not a light-touch exercise. The mandatory baseline still requires formalising controls around multi-factor authentication, phishing protection, patching, backups, and incident response and reporting, obligations many smaller businesses in the Kingdom have not previously had to document formally.

The framework is likely to land hardest on businesses that rely heavily on outsourcing, shared services, or cloud infrastructure, since large entities specifically must build cybersecurity requirements directly into third-party contracts and cloud arrangements rather than treating vendor risk as a separate, informal consideration. This mirrors a broader regional pattern already flagged in analysis of systemic financial sector risk, where regulators including Saudi Arabia's own National Cybersecurity Authority have been pushed toward formalising third-party risk and supply chain controls precisely because interconnected vendor relationships have become one of the least visible parts of enterprise risk exposure.

What businesses operating in Saudi Arabia should do now

Baker McKenzie's guidance for potentially in-scope entities centres on four immediate steps: confirming likely classification against the headcount and revenue thresholds, running a gap assessment against the mandatory controls relevant to the entity's category with particular attention to access controls, endpoint security, email security, vulnerability management, monitoring, and incident handling, reviewing governance and third-party or cloud arrangements especially where Saudi operations rely on global templates or outsourced IT, and assessing Saudi-specific implementation points including Haseen-related email controls and alignment with the National Cryptographic Standards.

This lands alongside a broader pattern of GCC governments formalising private sector cybersecurity obligations that were previously informal expectations, and businesses with Saudi operations dependent on global compliance templates should treat this as a prompt to verify those templates actually satisfy Saudi-specific requirements rather than assuming general international best practice is sufficient.

Layla Haddad

Cyber Policy & Digital Risk Correspondent

Layla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.

Intelligence Focus Areas

Compliance & PolicyCybersecurity GovernanceGCC Regulatory Frameworks