Back to blog
Compliance

NCNICC Compliance Saudi Arabia - Practical Implementation Guide

NCNICC compliance Saudi Arabia guide covering applicability, controls, evidence, gap assessments, and remediation planning with support from Cyberactics.

Cyberactics Security Team23 Aug 202615 min read
On this page(11)

NCNICC-1:2025 defines minimum cybersecurity controls for designated non-CNI private-sector entities in Saudi Arabia based on entity category.

A Saudi private-sector company may already have endpoint protection, multifactor authentication, backups, security policies, and an outsourced security provider. Management may therefore believe that its cybersecurity foundations are reasonably mature.

Then a different question reaches the CIO or CISO: "Are we ready for NCNICC-1:2025?"

That question cannot be answered by counting security products. It begins with determining whether the organization falls within the framework's scope, which category applies, which controls are mandatory for that category, and whether the organization can demonstrate that those controls actually operate.

Saudi Arabia's National Cybersecurity Authority (NCA) issued the Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC-1:2025) on December 28, 2025. The framework establishes minimum cybersecurity controls for specified private-sector entities that do not have Critical National Infrastructure (CNI). Importantly, the NCA document does not say that every private company in Saudi Arabia is automatically subject to mandatory NCNICC compliance. Its scope refers to non-CNI private entities in the Kingdom designated by the Authority.

For organizations investigating NCNICC compliance in Saudi Arabia, that qualification should shape the entire project. The first task is not buying technology. It is establishing applicability and building an evidence-based implementation plan. This article forms part of our complete guide to ISO 27001 & Compliance Services for GCC SMBs.

What NCNICC-1:2025 Is

The NCA describes NCNICC-1:2025 as a set of minimum cybersecurity controls intended to reduce risks arising from internal and external threats and protect private-sector organizations' information and technology assets. The controls were developed after consideration of leading international cybersecurity practices for small, medium, and large entities and are based on the NCA's Essential Cybersecurity Controls (ECC).

The authoritative baseline is the NCA's NCNICC-1:2025 control document. Organizations should work from the current NCA-published version rather than relying solely on summaries or third-party control lists.

The framework organizes its requirements around three main components:

  • Cybersecurity Governance, covering cybersecurity management, policies and procedures, risk management, review and audit, and awareness and training.
  • Cybersecurity Defense, covering assets, identities and privileges, systems and information-processing devices, email, networks, mobile devices, data protection, encryption, backups, vulnerabilities, penetration testing, security monitoring, incident management, physical cybersecurity, and web applications.
  • Third-Party and Cloud Computing Cybersecurity, addressing cybersecurity requirements involving suppliers, contractual relationships, cloud computing, and hosting.

This structure matters because NCNICC readiness is not simply an IT hardening exercise. Governance, operational security, monitoring, recovery, suppliers, and cloud services all become part of the assessment, subject to the applicability rules for the entity's category.

Which Saudi Private-Sector Organizations Should Assess NCNICC Applicability

NCNICC is specifically concerned with private-sector entities without Critical National Infrastructure in Saudi Arabia. Organizations should, however, avoid turning that description into an unconditional statement of legal applicability.

The official document states that the controls apply to small, medium, and large non-CNI private entities in the Kingdom that are designated by the NCA. Entities outside the framework's scope are given responsibility for benefiting from the controls as appropriate to implement best practices and strengthen their cybersecurity.

That distinction creates an important first workstream for management. An organization investigating NCNICC should establish its NCA designation status, confirm that it is not being treated under a different cybersecurity scope, determine its organizational size category, and identify other national or sector-specific cybersecurity requirements that may apply.

This is particularly important for corporate groups. A Saudi subsidiary should not assume that its parent company's ISO certification, regional security program, or internal global standard automatically resolves Saudi regulatory applicability.

Likewise, "private sector" and "non-CNI" should not be treated as synonyms for "NCNICC is mandatory for us." Applicability needs to be established against the NCA's actual scope.

Large-Entity Versus Small-and-Medium-Entity Requirements

NCNICC separates relevant organizations into two categories based on the definition used by Saudi Arabia's Small and Medium Enterprises General Authority, Monsha'at.

Category A - large entities are organizations with 250 or more full-time employees or annual revenue exceeding SAR 200 million. For designated organizations in this category, the framework identifies 3 main components, 22 subcomponents, and 65 mandatory main controls.

Category B - small and medium entities have 6 to 249 full-time employees or annual revenue from SAR 3 million to SAR 200 million. For designated organizations in this category, it identifies 1 main component, 13 subcomponents, and 26 mandatory main controls.

This is more than a difference in the length of a checklist. The control tables indicate applicability for each category. Some requirements are mandatory for both, while others are mandatory for Category A and recommended for Category B. The NCA also reserves the ability to require additional controls where necessary.

An assessment should therefore preserve the control-level applicability logic. Simply copying every NCNICC requirement into a spreadsheet and giving every row equal status can obscure what the NCA framework actually requires for the entity's category.

NCNICC Versus ECC: How the Scopes Differ

One source of confusion is the relationship between NCNICC and the NCA's Essential Cybersecurity Controls.

NCNICC was developed based on the ECC but is designed as a more appropriate baseline for the private-sector entities within NCNICC's particular scope.

The Essential Cybersecurity Controls (ECC 2-2024), meanwhile, apply to government organizations in Saudi Arabia and their affiliated companies and entities, as well as private-sector organizations that own, operate, or host Critical National Infrastructure. The ECC also contains technology-dependent applicability considerations.

The difference should therefore not be reduced to "ECC for large companies, NCNICC for smaller ones." Scope is the key distinction. NCNICC addresses designated non-CNI private-sector entities and then differentiates requirements according to entity size. ECC has a different scope that includes government entities and private-sector organizations associated with CNI.

A company should identify the regulatory baseline first and map overlapping controls second, rather than choosing whichever framework appears simpler.

What an NCNICC Gap Assessment Should Review

Once scope and category have been established, the practical question becomes: Can the organization show that each applicable requirement is implemented?

A gap assessment translates NCNICC from control language into the organization's actual environment.

Consider identity management. The framework contains requirements governing identities, access privileges, authentication, and access control. For remote access, including email and external applications, it specifically requires multi-factor authentication (MFA), where authentication relies on more than one factor.

Writing "MFA enabled" in an assessment is not enough. An assessor needs to understand where MFA is enforced, which identities are covered, whether exceptions exist, how privileged accounts are handled, and what evidence demonstrates that the documented requirement corresponds with the deployed configuration. Our guidance on identity-first Zero Trust for Microsoft 365 covers how that enforcement is designed in practice.

The same principle applies throughout the framework. For backup management, NCNICC addresses periodic backups of critical business systems and periodic testing to confirm the effectiveness of backup restoration. For vulnerability management, it addresses patching and updates, vulnerability scanning, scanning of externally accessible applications, and remediation based on vulnerability classification.

For cybersecurity incidents, it addresses documented incident management requirements, response plans, and relevant escalation mechanisms. Its controls also include notifying the NCA when a cybersecurity incident occurs and sharing cybersecurity information with the Authority.

A useful gap assessment therefore asks three questions repeatedly:

  1. What does the applicable control require?
  2. What has the organization actually implemented?
  3. What evidence proves it?

That moves the exercise from policy review to operational assurance.

Evidence to Prepare Before the Assessment

Evidence is often where an apparently mature security program begins to show weaknesses.

A policy may exist but have no approval record. A vulnerability scanner may be deployed but have incomplete coverage. Backups may run every night, but nobody can produce recent restoration-test evidence. A Security Information and Event Management (SIEM) platform may collect logs without demonstrating that the relevant sources are monitored and acted upon.

Evidence should be mapped directly to applicable controls and may include approved policies and procedures, organizational structures and responsibility assignments, cybersecurity risk documentation, asset records, configuration evidence, access-control records, security monitoring outputs, vulnerability and patch records, backup and recovery-test results, incident-response documentation, training records, audit outputs, supplier contracts, and cloud-security documentation.

Organizations that have not yet assembled this material can start from our cybersecurity assessment checklist for Saudi Arabia SMBs, which sets out the evidence worth gathering about assets, identities, cloud services, backups, and ownership.

From Gap Register to Remediation Roadmap

A gap register identifies problems. A remediation roadmap turns those problems into accountable work.

Suppose an assessment finds weak privileged-access controls, inconsistent vulnerability remediation, insufficient event monitoring, untested recovery procedures, and missing cybersecurity clauses in supplier contracts. Treating these as five isolated compliance findings misses the operational picture. Together, they may indicate weaknesses across prevention, visibility, response, and recovery.

Each material finding should therefore move through a practical sequence:

Control requirement → observed state → evidence → gap → risk → corrective action → owner → target date → validation

Priorities should reflect more than how easy a gap is to close. Organizations should consider whether a requirement is mandatory for their category, the risk created by the weakness, dependencies between controls, the effort required for remediation, and the operational effect of making the change.

Some gaps are largely procedural. Others require architecture changes or sustained operating capability. A missing approval signature might be fixed quickly. Establishing effective security monitoring across cloud workloads, endpoints, identity systems, and networks may require new integrations, tuning, ownership, escalation procedures, and ongoing operations.

This is why NCNICC implementation should be planned as a program rather than a document-production exercise.

Governance, Technical, and Third-Party Workstreams

For many organizations, implementation becomes easier to manage when remediation is divided into connected workstreams.

Governance and Risk

Governance establishes who owns cybersecurity and how decisions are made.

NCNICC's governance component addresses areas including cybersecurity management, policies, cybersecurity risk management, periodic review and audit, and awareness and training. For example, requirements concerning a dedicated cybersecurity administrative function apply differently according to organization category, while some other controls are mandatory for both categories.

The practical goal is accountability. Security controls that have no owner often become controls that gradually stop operating.

Technical Defense and Visibility

Technical remediation may touch identity, endpoints, networks, email, data protection, cryptography, backups, vulnerability management, logging, incident response, and externally exposed applications.

NCNICC, for example, includes vulnerability-management requirements and addresses penetration testing of externally delivered services and their technical components. It also includes event-log management and cybersecurity monitoring requirements.

Organizations may therefore need to determine whether existing tools are merely installed or actually provide the required capability.

Cyberactics can support relevant technical work in areas such as cybersecurity assessments, vulnerability management, identity and access management, Microsoft 365 and cloud security, SIEM implementation and management, managed detection and response, incident response, and managed cybersecurity. The objective should be to close verified control gaps with maintainable capabilities rather than add tools without a defined requirement.

Third Parties and Cloud Services

Suppliers deserve their own workstream because much of an organization's risk may sit outside infrastructure it directly administers.

NCNICC's third-party controls address cybersecurity requirements in contracts and agreements, including information confidentiality and communications following cybersecurity incidents that could affect the organization's data or services. Its cloud and hosting controls address cybersecurity requirements for services hosted, processed, or managed by external parties.

That means procurement, legal, business owners, cloud teams, and cybersecurity may all need to participate. A technically secure cloud deployment does not by itself resolve a contractual gap. Likewise, a strong contract does not prove that the supplier's technical controls operate effectively.

What NCNICC Means for GCC Organizations

NCNICC-1:2025 is a Saudi framework. It should not be presented as a GCC-wide regulatory requirement.

That boundary matters for organizations operating across the GCC and wider MENA region. A business headquartered in the UAE or Oman may operate a Saudi subsidiary, employ staff in Saudi Arabia, or use a shared regional Microsoft 365 tenant, security operations center (SOC), cloud environment, identity platform, or managed infrastructure. The Saudi entity may therefore need an NCNICC applicability assessment even when much of its technology is governed or operated elsewhere in the GCC.

For a regional group, the practical solution is not necessarily to build a completely isolated security program for every jurisdiction. A common cybersecurity baseline can instead be mapped to country-specific requirements, subject to each jurisdiction's applicable legal, regulatory, and sector-specific obligations.

The same principle applies to ISO/IEC 27001. Certification against ISO/IEC 27001 and implementation of NCNICC are not interchangeable exercises. Existing ISO governance, risk, control, and evidence processes may provide useful foundations, but the organization still needs to assess NCNICC's specific scope and requirements.

Organizations building a broader regional compliance program can use our ISO 27001 compliance guide for GCC SMBs alongside the Saudi framework, while keeping NCNICC separate from ISO certification and from sector-specific Saudi requirements such as those applicable to regulated financial institutions.

Questions to Ask an NCNICC Assessment Provider

An NCNICC engagement should produce more than a branded spreadsheet.

Before appointing an assessment provider, determine whether it can explain how it will establish the entity category and applicable control set, map evidence to individual requirements, distinguish mandatory from recommended controls, document assumptions, validate technical implementation, and turn findings into an actionable remediation program.

Ask how technical evidence will be collected and how identity, cloud, vulnerability management, logging, incident response, third-party risk, and recovery will be tested rather than accepted solely from policy documents.

Also establish what the final deliverables will contain. Management should be able to see which requirements are satisfied, which have insufficient evidence, which contain material gaps, who owns remediation, and what needs to happen next.

An assessment should also preserve the distinction between helping an organization prepare for NCNICC and determining or representing the NCA's own compliance judgment. The NCA states that organizations within scope must implement measures that achieve ongoing and continuous compliance and that the Authority assesses compliance according to the mechanisms it considers appropriate.

From Initial Assessment to Ongoing Compliance

The first assessment is a baseline, not the finish line.

Once findings are validated, organizations should assign remediation owners, prioritize mandatory and high-risk gaps, build dependencies into the implementation schedule, collect evidence as controls are completed, and retest technical changes. Where controls depend on recurring activities, those activities should become part of normal operations rather than one-time compliance tasks.

The NCA states that NCNICC will be periodically reviewed and updated and that the Authority will announce and publish updated versions. Organizations should therefore rely on versions published through the Authority's website.

Configuration and evidence management remain important long after the initial project. Policies change. Employees join and leave. Cloud services are added. Vendors change. Vulnerabilities appear. Security monitoring coverage drifts. Compliance therefore has to be sustained through operational processes.

For Saudi private-sector organizations beginning this work, the practical sequence is straightforward: confirm applicability, establish the correct category, map applicable controls, collect evidence, validate implementation, prioritize gaps, remediate, and reassess.

NCNICC-1:2025 gives designated Saudi non-CNI private-sector entities a defined minimum cybersecurity baseline, while entities outside its mandatory scope are encouraged to benefit from the controls as appropriate. Effective implementation depends on translating applicable requirements into controls that work in day-to-day operations and can be supported by evidence.

Cyberactics provides cybersecurity assessments, implementation and advisory services, vulnerability management, identity and access management, cloud security, SIEM, incident response, and managed cybersecurity capabilities that can support organizations addressing relevant control gaps. Explore our compliance and risk services or get in touch to plan an assessment and build a remediation roadmap around your actual Saudi regulatory and operational environment.

#NCNICC compliance Saudi Arabia#NCNICC implementation#NCA cybersecurity compliance#NCNICC gap assessment#NCNICC-1:2025
CY

Cyberactics Security Team

Compliance & Risk

We help SMBs across Jordan, Saudi Arabia, and the UAE run secure, automated IT - from Zero Trust rollouts to ISO 27001 certification.

Ready to start?

Want the runbook behind this article?

Book a 30-minute call with one of our senior engineers and we'll walk you through the templates we deploy for clients across the MENA region.