العربية

Market · Kingdom of Saudi Arabia

Get Saudi-ready, and know which work must stay in the Kingdom

Saudi Arabia has the most developed cyber security control stack in the Gulf and the tightest rules about who is permitted to deliver services into it. The second fact decides whether the first one is any use to you.

Our supplier guide sets out the three gates a foreign cyber, cloud or IT supplier meets first: Haseen registration, the ECC clauses your client must pass to you, and where the data may go. Read the supplier guide

undefined

Read this before you brief anyone on Saudi work

Registration on the NCA's Haseen portal has been mandatory since August 2022 for any entity providing cyber security solutions, services or products in the Kingdom. Managed SOC licensing sits on top of it. And a draft licensing framework consulted on between February and March 2026 would go considerably further — requiring a Saudi legal entity, 75% Saudi ownership and SAR 10 million capital to serve government or critical national infrastructure, with full in-Kingdom data residency and no access from outside. Its enactment status is unconfirmed. We publish this register because it is useful; we do not promise Saudi delivery until that position is settled, and where the work must be performed in-Kingdom by a licensed provider we will say so and point you at one.

The stack

Saudi is the one Gulf market where the controls are genuinely layered rather than parallel — the NCA baseline sits underneath everything else. Reference numbers are as published by the authority.

NCA · baseline

Essential Cybersecurity Controls

ECC-2:2024

The foundation every other NCA control set builds on. Binds government entities and their contractors, and private-sector owners and operators of critical national infrastructure. The NCA has publicly committed to conducting over 7,000 cyber security assessments of national entities, run through the Haseen national portal.

Who signsNCA assessment programme, via Haseen.
NCA · specialised

Cloud, critical systems and operational technology

CCC-2:2024CSCC-1:2019OTCC-1:2022

Cloud controls apply to providers and tenants alike, and the 2024 revision reflects data-localisation requirements. Critical systems run to 32 main controls and 73 sub-controls across governance, defence, resilience and third-party. The OT set ships with its own methodology annex and a spreadsheet assessment tool, which is unusually practical for a national control set.

Who signsNCA programme; OT ships an assessment and compliance tool.
NCA · private sector

Controls for non-critical private entities

NCINCC-1:2025

The most significant recent development for ordinary Saudi business. Large entities — over 250 staff or revenue above SAR 200 million — face 22 sub-components and 65 essential controls, including an independent cyber security function with periodic review and compliance oversight. Smaller entities face 13 sub-components and 26 controls, some recommended rather than mandatory. No compliance deadline has been published.

Who signsAn independent cyber security function is required for large entities — internal, but separated from what it reviews.
SDAIA

Personal Data Protection Law

Royal Decree M/19am. M/148

Fully enforceable since September 2024, and enforcement here is real rather than theoretical — 48 enforcement decisions had been announced by mid-January 2026. Fines reach SAR 5 million, doubled for repeat violations, with publication of final penalties. Controllers register on the National Data Governance Platform. A DPO is mandatory for public bodies, for large-scale systematic monitoring, and for large-scale special-category processing.

Who signsRegistration on the National Data Governance Platform; qualification criteria set for the DPO role.
SDAIA

National AI Risk Management Framework

2026

Applies to public and private entities. Five phases from context definition through risk identification across seven categories, assessment on a four-by-four likelihood and impact matrix, treatment and monitoring. Deliberately sovereign: it makes no reference to ISO/IEC 42001, ISO/IEC 23894, the NIST AI RMF or the EU AI Act. SDAIA's AI Ethics Principles and its generative AI guidelines for government sit alongside it, all voluntary.

Who signsSelf-assessed. No certification scheme attaches to it.
SAMA

Cyber Security Framework

v1.0 · May 2017

Binds banks, insurers and reinsurers, financing companies, credit bureaus and financial market infrastructure. A six-level maturity model in which member organisations must reach at least level 3, and SAMA assigns the level itself. The Cyber Resilience Fundamental Requirements of January 2022 sit alongside it as a licensing-stage requirement, not a replacement.

Who signsThorough, independent and regular audits, plus annual penetration testing of internet-facing services. SAMA also audits directly.
CST

ICT sector framework and cloud classification

Decision 424/1442CCRF class A / B / C

The Cybersecurity Regulatory Framework binds entities licensed or registered by the Communications, Space and Technology Commission. Separately, cloud providers must register with CST and hold a class designation, which determines the data classifications and sectors they may serve — so your provider's class is a constraint on your architecture, not just their paperwork.

Who signsCST registration and class designation for providers.

Where the data has to live

Government data must remain in Saudi Arabia, subject only to narrow law-based exceptions. In the financial sector, offshore hosting requires prior SAMA approval, and in practice most providers default to full in-Kingdom hosting. Layer the PDPL transfer regulation and the CST cloud classes on top and the architecture question usually settles itself before the compliance question is even asked.

Before you commit budget

Four questions worth asking

  • Is our supplier registered on Haseen, and for which services?
  • Which NCA control set actually binds us — the baseline, the critical-systems set, or the private-sector one?
  • Where will the data sit, and does our cloud provider hold the right CST class for it?
  • If the licensing framework is enacted as drafted, what happens to this engagement?

Three things we could not verify

  • The NCINCC-1:2025 reference number. Confirmed through a major law firm, but not located on the NCA's own site.
  • Reference numbers for the telework, data and social media control sets. The NCA listing shows names and dates only.
  • The SAMA framework's primary text. The rulebook could not be accessed for this review, so the version, date and maturity threshold here come from secondary sources.

One commercial detail people miss

Saudi withholding tax on technical and consulting services supplied by non-residents is deducted at source at 5%, so a SAR 100,000 invoice nets SAR 95,000. Work characterised as management attracts 20%. The UK–Saudi double tax treaty may reduce it on certification of residence, but relief is claim-driven and slow. Price it in before you quote, and watch the characterisation.

Start with a scoping call

Tell us the entity and which of the NCA sets you are being measured against. If the honest answer is that a licensed in-Kingdom provider must do the work, you will hear it on the call.