In brief

  • The Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (NCINCC-1:2025) issued by the National Cybersecurity Authority (NCA) establish a minimum cybersecurity baseline for private sector entities operating in Saudi Arabia.
  • The framework adopts a tiered approach, distinguishing between large entities and small/medium entities (SMEs).
  • Large entities are subject to a substantially broader set of requirements, including governance, audit, third-party and cloud-related controls.
  • SMEs are subject to a narrower but still meaningful set of mandatory technical and operational controls.
  • The framework embeds Saudi-specific compliance expectations, including alignment with NCA platforms, standards and licensed-provider models.
  • Potentially in-scope businesses should begin internal scoping and gap-assessment exercises promptly.
      

Key takeaways

The introduction of the Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC) marks an important development in Saudi Arabia’s cybersecurity regulatory landscape. It signals that baseline cybersecurity compliance is no longer a concern only for government bodies, critical infrastructure operators or highly regulated sectors. Instead, a broader range of private sector entities is now expected to implement and maintain a documented set of cybersecurity controls appropriate to their size and risk profile.

For large entities, the framework introduces a significant governance and third-party compliance agenda in addition to technical controls. For SMEs, the controls are narrower, but still substantial enough to require meaningful internal assessment and implementation work.

Businesses operating in Saudi Arabia should therefore be aware of the NCNICC as a practical compliance development that may require near-term action across legal, compliance, procurement, information security and operational teams.

Recommended actions

Businesses that fall within scope should consider taking four immediate steps:

  1. Confirm likely classification and applicability by reference to headcount, revenue, and the framework’s “as notified by the Authority” wording.
  2. Run a gap assessment against the mandatory controls relevant to the entity’s category, with particular focus on access controls, endpoint security, email security, vulnerability management, monitoring and incident handling.
  3. Review governance, third-party and cloud arrangements, especially where Saudi operations depend on global templates, outsourced IT, group-shared services or public cloud environments.
  4. Assess Saudi-specific implementation points, including Haseen-related email controls, alignment with the National Cryptographic Standards, and monitoring/escalation arrangements that may involve NCA-licensed providers.
      

In more detail

The new framework is significant because it extends Saudi Arabia’s cybersecurity compliance architecture more clearly into the wider private sector. While Saudi cybersecurity regulation has historically focused more heavily on government entities, critical national infrastructure and other highly regulated sectors, the NCNICC establishes a tailored minimum-control framework for non-CNI private sector entities, calibrated by reference to entity size and risk profile.

Who is in scope?

The NCNICC applies to non-CNI private sector entities in Saudi Arabia and distinguishes between two principal categories by reference to entity size:

  • Large entities, being entities with more than 250 full-time employees or annual revenues exceeding SAR 200 million; and
  • Small and medium entities, being entities with between 6 and 249 full-time employees or annual revenues between SAR 3 million and SAR 200 million.

Importantly, the text indicates that the controls apply to the relevant categories of entities “as notified by the Authority”. As a result, while the size thresholds are central to determining likely applicability, businesses should avoid assuming that classification is purely mechanical. In practice, businesses should consider both their position against the stated thresholds and whether any NCA notification, engagement, or broader regulatory expectation may be relevant to their compliance posture.

As at the date of this alert, the NCA has not publicly confirmed the issuance of any individual notifications identifying specific entities as being brought into scope. The NCNICC are drafted to apply directly, by their own terms, to non-CNI private sector entities meeting the size or revenue thresholds. The reference to application “as notified by the Authority” is therefore best understood as (i) a residual power for the NCA to confirm classification and applicability in borderline or mixed cases, and (ii) a discretionary power to impose additional or heightened controls on entities or sectors that present higher cyber risk. Based on the NCA’s approach under the Essential Cybersecurity Controls and its published sectoral focus, we would expect any such notifications to be directed at sectors or categories of activity rather than issued as individual entity notices, and to be reinforced where necessary through direct supervisory engagement. Entities that clearly meet the size or revenue thresholds should therefore not defer scoping and gap-assessment work pending a formal notification.

The framework also makes clear that the NCA may, at its discretion, require an entity to comply with additional controls where necessary. This is an important point for businesses operating in sectors or on business models that may present heightened cyber risk, even if they do not traditionally consider themselves part of Saudi Arabia’s more heavily regulated cybersecurity perimeter.

What are the core controls?

The NCNICC is structured around three cybersecurity components, further broken down into sub-components and individual essential controls. Large entities are required to implement the full set of three components, 22 sub-components and 65 essential controls. SMEs are subject to a proportionate subset comprising 13 sub-components and 26 essential controls, some of which are designated as “recommended” rather than “mandatory”.

The first component addresses cybersecurity governance and covers policies and procedures, defined roles and responsibilities, a documented cybersecurity risk management methodology, awareness and training, and periodic review, audit and compliance oversight. For large entities in particular, it requires a cybersecurity function that is independent from the IT function, with the head of cybersecurity and other sensitive roles held by suitably qualified Saudi nationals on a fully dedicated basis.

The second component sets the core operational and technical baseline. It addresses asset management, identity and access management (including multi-factor authentication for remote access), secure configuration and hardening, network and endpoint security, mobile device security, email security (with alignment to the NCA’s Haseen platform), data and information protection, cryptography (including alignment with the National Cryptographic Standards), backup and recovery, vulnerability management, penetration testing, cybersecurity event logging and monitoring, and cybersecurity incident and threat management, physical security and web application security.

The third component addresses cybersecurity risk arising from supply-chain, outsourcing and hosted environments. It requires cybersecurity requirements to be embedded in third-party contracts (covering matters such as confidentiality and communication of cybersecurity incidents affecting third parties) and imposes specific expectations for the use of cloud and hosting services, including data classification, separation of the entity’s environment from those of other tenants, and return of data (in a usable format) on termination of the service.

Why does this matter?

For large entities, the framework goes well beyond a basic technical checklist. It requires, among other things, a dedicated cybersecurity unit that is independent from IT, documented governance and risk management arrangements, periodic review and audit, and cybersecurity awareness and training. It also includes a notable requirement that the cybersecurity function and sensitive roles be headed by Saudi nationals who are fully dedicated and appropriately qualified.

For small and medium entities, the framework is narrower, but it is not light-touch. The mandatory baseline still covers core cybersecurity defence measures. In practical terms, many SMEs may still need to formalise controls around MFA, phishing protection, patching, backups, incident response and reporting.

The framework is also likely to be particularly relevant for businesses that rely heavily on outsourcing, shared services or cloud infrastructure. For large entities, the NCNICC expects cybersecurity requirements to be built into third-party contracts and cloud/hosting arrangements, including confidentiality, incident communication, data classification, environment separation, and return of data on termination.

Should you wish to discuss the potential impact of the new controls on your organisation, please contact Dino Wilkinson and Maher Ghalloussi, whose contact information is provided in this alert.

Explore More Insight