Explained

Saudi NCA Compliance: Complete Guide & Requirements

Complete guide to NCA compliance in Saudi Arabia. Learn every framework, key obligations, and practical steps to get started with compliance.

Mountain landscape representing leadership perspective and vision
Written by
Trio Content Team
Published on
29 Mar 2026
Modified on
29 Mar 2026

Saudi Arabia's cybersecurity market reached SAR 15.2 billion in total spending in 2024, a 14% increase year-on-year, a figure that reflects how seriously the Kingdom is treating digital security as a national priority. NCA compliance Saudi Arabia organizations must demonstrate is no longer a background regulatory concern. It is a funded, actively enforced obligation with real consequences for organizations that fall short.

So what does NCA compliance mean in practice? NCA compliance means demonstrating adherence to one or more cybersecurity frameworks issued by Saudi Arabia's National Cybersecurity Authority. The baseline framework is ECC-2:2024, updated in October 2024. Historically, these frameworks applied primarily to government entities and Critical National Infrastructure (CNI) operators, but that scope has formally expanded, and private sector companies now have their own mandatory framework under NCNICC-1:2025.

The mandatory question has a clear answer: yes, for most organizations operating in Saudi Arabia. Since December 2024, the NCA holds formal enforcement authority and can impose penalties of up to SAR 25 million for non-compliance. Which specific framework applies to your organization depends on entity type and size, and this article maps that out precisely.

What follows covers the full NCA framework ecosystem (ECC, CSCC, CCC, OTCC, TCC, and NCNICC), the material changes from ECC-1:2018 to ECC-2:2024, which organizations are required to comply and under what conditions, how the December 2024 enforcement shift changed the stakes, and a practical sequence for getting started.

TL;DR
  • NCA compliance means following cybersecurity frameworks issued by Saudi Arabia's National Cybersecurity Authority, the baseline framework is ECC-2:2024, updated in October 2024.

  • Yes, it is mandatory, for government entities, CNI operators, and (under NCNICC-1:2025, published December 2025, enforcement deadline TBD) all non-CNI private sector organizations above minimum size thresholds.

  • Since December 2024, the NCA has formal enforcement authority and can impose penalties of up to SAR 25 million for non-compliance.

  • The NCA ecosystem includes six frameworks: ECC, CSCC, CCC, OTCC, TCC, and NCNICC, which ones apply to your organization depends on your entity type and operational environment.

  • ECC-2:2024 reorganized into four domains and explicitly includes NCA essential cybersecurity controls Saudi Arabia organizations must meet, with Mobile Devices Security (Subdomain 2-6) as a named compliance requirement.

  • Start with a gap assessment against the applicable framework before building a remediation plan, prioritize the Cybersecurity Defense domain for the most immediate security return.

What Is NCA Compliance?

If you already understand what the NCA is and what compliance with its frameworks means, skip ahead to the next section for the full framework breakdown.

NCA compliance is organizational adherence to the cybersecurity frameworks, controls, and standards issued by the National Cybersecurity Authority of Saudi Arabia. The NCA cybersecurity framework authority was established in October 2017 by Royal Decree as the central government body for cybersecurity governance, directly tied to Vision 2030's digital transformation agenda. Before 2017, national cybersecurity oversight was fragmented across two separate centers under different ministries, the NCA Saudi Arabia mandate unified that authority under a single body.

NCA compliance is not a single certification or audit pass. It is adherence to one or more of several distinct frameworks, each with specific applicability criteria based on entity type, operational environment, and size. Think of it as Saudi Arabia's mandatory analogue to internationally recognized frameworks like ISO 27001 or SOC 2, except that compliance is legally required rather than voluntary for most in-scope organizations. The NCA framework ecosystem is covered in the next section.

The NCA mandate also sits within a broader regulatory picture. NCA compliance sits within the broader category of IT compliance that organizations manage alongside other regulatory obligations, including sector-specific rules from SAMA, CITC, and MOH depending on industry.

The NCA Framework Ecosystem: Which Controls Apply to You

The NCA has issued six distinct cybersecurity frameworks since 2018, governed by NCA regulations that set mandatory applicability criteria for each. They are not interchangeable, each addresses a specific entity type or operational environment. Understanding which ones apply to your organization is the essential first step before any compliance work begins, and working through an NCA compliance checklist means first determining which of these frameworks governs your entity type.

These frameworks do share structural similarities, particularly in their Defense and Governance domains, meaning work done for one framework often reduces the gap for others. NCA requirements Saudi Arabia organizations must meet are not entirely duplicated across frameworks; the overlap is manageable with systematic tooling.

Essential Cybersecurity Controls (ECC-2:2024)

Published October 2024 (version 2, replacing ECC-1:2018), ECC-2:2024 is the baseline framework for government entities, ministries, authorities, and organizations owning, operating, or hosting CNI. All other NCA frameworks either build on ECC or require ECC compliance as a prerequisite.

ECC-2:2024 is organized into four domains:

  • Cybersecurity Governance (10 subdomains)
  • Cybersecurity Defense (15 subdomains, including Mobile Devices Security at Subdomain 2-6)
  • Cybersecurity Resilience (1 subdomain)
  • Third-Party and Cloud Computing Cybersecurity (2 subdomains)

If your organization is subject to ECC-2:2024, that also triggers applicability of CCC if you run any cloud workloads and TCC if any staff work remotely, compliance scope tends to expand once you look closely.

Critical Systems Cybersecurity Controls (CSCC-1:2019)

Published in 2019, CSCC applies to organizations owning or operating systems NCA has formally classified as "critical." It adds controls above the ECC baseline for those designated systems. ECC compliance is a mandatory prerequisite before CSCC applies.

Cloud Cybersecurity Controls (CCC-1:2020)

Published in 2020, CCC applies to any organization running workloads in public, private, or hybrid cloud environments. It covers cloud-specific security requirements that ECC does not fully address on its own.

Operational Technology Cybersecurity Controls (OTCC-1:2022)

Published in 2022, OTCC applies to organizations with OT/ICS environments and scales by criticality level (L1–L3). ECC-1:2018 compliance is a mandatory prerequisite. Controls must be implemented without jeopardizing continuity of operations, a practical consideration that shapes how organizations sequence their OT compliance work.

Telework Cybersecurity Controls (TCC-1:2021)

Published in 2021, TCC applies to organizations with remote or telework arrangements. It covers device protection for remote endpoints, secure remote access, and employee security awareness. For organizations managing remote fleets, TCC sits directly at the intersection of compliance and mobile device management.

Non-Critical National Infrastructure Private Sector Cybersecurity Controls (NCNICC-1:2025)

Published December 28, 2025, NCNICC-1:2025 is the first mandatory framework ever issued specifically for non-CNI private sector entities. Many private sector organizations historically assumed NCA frameworks didn't apply to them, NCNICC-1:2025 formally closes that assumption.

It applies to all non-CNI private sector companies and uses a two-tier structure:

  • Large entities: 250+ employees or SAR 200M+ annual revenue
  • SMEs: 6–249 employees or SAR 3M–SAR 200M annual revenue

Three components apply: Cybersecurity Governance, Cybersecurity Defense (asset management, access control, secure configuration, endpoint security, vulnerability management, incident response, backup and recovery), and Third-Party and Cloud Computing Cybersecurity. The compliance deadline has not yet been specified by NCA, but enforcement powers are already in place.

Which NCA framework applies to your organization?

You are a government entity or operate CNI → ECC-2:2024 (plus CSCC, CCC, OTCC, and TCC as applicable to your environment)

You are a non-CNI private sector company with 6+ employees or SAR 3M+ revenue → NCNICC-1:2025 (plus CCC and TCC if applicable)

Not sure? → Default to NCNICC-1:2025 if you are a private sector company; use NCA's MATURITY self-assessment platform to confirm your classification before committing to a remediation scope

NCA Framework Ecosystem at a Glance

FrameworkPublishedWho It Applies ToKey Focus AreasCurrent Status
ECC-2:2024October 2024Government entities, CNI owners/operatorsGovernance, Defense (incl. mobile devices), Resilience, Third-Party & CloudCurrent (replaces ECC-1:2018)
CSCC-1:20192019Organizations with NCA-designated critical systemsControls above ECC baseline for critical systemsCurrent
CCC-1:20202020Organizations using cloud environmentsCloud-specific security requirementsCurrent
OTCC-1:20222022Organizations with OT/ICS environmentsOperational technology security; L1–L3 criticality scalingCurrent
TCC-1:20212021Organizations with remote/telework arrangementsRemote device protection, secure access, employee awarenessCurrent
NCNICC-1:2025December 28, 2025All non-CNI private sector entities (6+ employees or SAR 3M+ revenue)Governance, Defense, Third-Party & Cloud; size-tiered requirementsNew, enforcement timeline TBD

What Changed With ECC-2:2024, and Why It Matters

Most articles about NCA ECC compliance online are still describing ECC-1:2018. The October 2024 update changed the framework materially, and if your organization completed a gap assessment before that date, that assessment is now outdated. Map your existing controls against the ECC-2:2024 four-domain structure before building a remediation plan.

Key changes from ECC-1:2018 to ECC-2:2024:

  • From 5 domains to 4 domains: The ICS/OT domain was removed from ECC-2:2024 and is now handled by the standalone OTCC-1:2022 framework. For non-OT organizations, this reduces ECC scope.
  • Streamlined control count: ECC-2:2024 covers 4 domains across 18 subdomains, reducing the overall control footprint compared to ECC-1:2018's 114 controls.
  • New subdomain added: Web Application Security (Subdomain 2-15) is new in ECC-2:2024, organizations running web applications now have explicit control requirements.
  • Data localization authority transferred: Previously handled within ECC, data localization requirements now sit with ICT Regulations and sector-specific rules.
  • New Saudization requirements: Specific cybersecurity positions must now be filled by Saudi nationals. This workforce Saudization requirement is consistently cited as the hardest control to meet, not because of technology, but because of labor market constraints.
  • Evidence requirements strengthened: ECC-2:2024 moves away from documentation-only compliance to demonstrated compliance, organizations must show controls are enforced, not just written down. This is where NCA compliance automation tools become directly relevant: they generate the audit trails that demonstrate enforcement, not just documentation.
  • Updated assessment tools: NCA introduced a revised self-assessment methodology aligned with the updated four-domain control structure.

Mobile Devices Security is explicitly named as Subdomain 2-6 within the Cybersecurity Defense domain. Any organization subject to ECC-2:2024 must demonstrate active controls over mobile devices, not just a policy stating they should exist.

The shift to evidence-based compliance is a direct response to the "checkbox compliance" problem practitioners reported under ECC-1:2018. ECC-2:2024's evidence requirements make checkbox compliance significantly harder, which is a positive development for organizations that want their compliance posture to reflect their actual security posture, not just their documentation library.

Is NCA Compliance Mandatory? The Honest Answer by Organization Type

Yes, NCA compliance is mandatory for most organizations operating in Saudi Arabia. Many private sector organizations have historically assumed these frameworks didn't apply to them. That assumption is no longer valid. The breakdown by entity type:

  • Government entities and CNI operators: Mandatory under ECC-2:2024. Has been mandatory since ECC-1:2018 in 2018. No grace period.
  • Non-CNI private sector (large entities): Mandatory under NCNICC-1:2025 for organizations with 250+ employees or SAR 200 million annual revenue.
  • Non-CNI private sector (SMEs): Mandatory under NCNICC-1:2025 for organizations with 6–249 employees or SAR 3–200 million annual revenue. Proportionate requirements apply at the SME tier.
  • Organizations with cloud workloads: Also subject to CCC-1:2020 alongside their primary framework obligation.
  • Organizations with remote workers: Also subject to TCC-1:2021.
  • Entities below size thresholds or not operating in Saudi Arabia: ECC compliance is not mandatory but is formally encouraged by NCA.

On the deadline question for NCNICC-1:2025: the framework does not specify a compliance deadline, but formal NCA enforcement powers are already in place. BSA Law's commentary explicitly flags this ambiguity and advises organizations not to treat the lack of a deadline as an invitation to delay. The enforcement window is open now.

The December 2024 NCA Regulations are the legal instrument that formally established enforcement authority and the SAR 25 million penalty ceiling. Once you confirm mandatory applicability under any framework, scope tends to expand, a private sector company subject to NCNICC-1:2025 that also uses cloud infrastructure and has remote workers is simultaneously subject to CCC-1:2020 and TCC-1:2021.

Organizations managing multiple mandatory frameworks are increasingly turning to automated compliance software to track controls across requirements simultaneously.

Penalties and Enforcement: What Happens If You Don't Comply

Before December 2024, the NCA lacked explicit statutory authority to act on non-compliance. The December 2024 NCA Regulations closed that gap, formally establishing enforcement powers and setting a clear penalty ceiling. Organizations that fail to meet NCA compliance standards now face structured consequences.

The key enforcement provisions:

  • Penalty ceiling: Penalties of up to SAR 25 million for non-compliance. Actual amounts are determined by NCA-appointed committees, not applied as a flat fine.
  • Violations covered: Practicing regulated cybersecurity activities without an NCA license; making cybersecurity devices or tools available without required permits; general non-compliance with NCA standards.
  • Inspection authority: The NCA Governor appoints inspectors with authority to monitor compliance, conduct physical site visits, and review systems and documents.
  • Regulatory accountability: NCA is required to submit a comprehensive implementation report four years after the December 2024 Regulations, confirming that formal accountability operates at the regulatory level as well.
  • Haseen registry: Cybersecurity service and product providers must register with NCA's Haseen national registry. Organizations procuring cybersecurity vendors need to confirm their vendors are registered, adding a supply chain compliance layer.

Formal enforcement is now established. The window for organizations to voluntarily align before active audit activity begins is narrowing.

Where to Start With NCA Compliance

Starting your NCA compliance program can feel overwhelming, 110+ controls across multiple frameworks is a genuine challenge for an IT manager running a small team. The scope is real, but it is manageable with a clear starting sequence.

A practical four-step approach:

  • Step 1, Determine your applicable framework(s): Government or CNI → ECC-2:2024 (plus CSCC, CCC, OTCC, TCC as applicable). Private sector non-CNI → NCNICC-1:2025 (plus CCC and TCC as applicable). Cross-reference the decision tree in the framework ecosystem section above to confirm your classification.
  • Step 2, Conduct a gap assessment: Map your current controls against the applicable framework before doing anything else. Without a baseline gap assessment, remediation effort gets scattered across the control set with no clear priority order. NCA compliance practitioners consistently identify gap assessment as the mandatory first step, remediation without a baseline produces scattered effort and no clear priority order.
  • Step 3, Prioritize the Cybersecurity Defense domain: Defense controls deliver the most immediate security return and are the first area auditors scrutinize. Don't wait for governance documentation to be fully mature before addressing defense controls, they are not sequentially dependent.
  • Step 4, Build toward evidence-based compliance: Policy documents are not enough under ECC-2:2024. You need configuration audit logs, access control records, and incident monitoring data. Compliance automation platforms can run continuous control testing so gaps don't reopen after initial remediation.

If your gap assessment shows hundreds of open items and no clear priority order, check whether you've separated mandatory controls from recommended controls, not everything carries equal compliance weight under NCA's assessment methodology.

Starting with defense controls first means your governance documentation may lag behind. That is acceptable in the short term, but auditors will eventually want to see both in alignment. For organizations subject to NCNICC-1:2025, the SME tier has proportionately lighter requirements, SMEs should focus on the core Cybersecurity Defense component first before addressing governance and third-party controls.

How Trio MDM Helps With NCA Compliance

Trio MDM addresses the technical device management layer of NCA compliance, specifically, the device-level controls within ECC-2:2024's Cybersecurity Defense domain, including Subdomain 2-6 (Mobile Devices Security), and the equivalent endpoint security controls in NCNICC-1:2025. This is where most organizations experience the greatest control gap, while governance documentation is more straightforward to produce, enforced technical controls require actual tooling.

What Trio MDM handles across managed device fleets:

  • Automated control testing and one-click remediation: Trio MDM continuously monitors security controls on managed devices and shows real-time compliance status against configured policies. When a control fails, administrators can trigger one-click remediation for most issues, and for controls requiring manual steps, Trio MDM provides fix instructions and retests the device automatically afterward.
  • Encryption and password policy enforcement: Trio MDM enforces encryption and password policies across managed devices, satisfying core Cybersecurity Defense controls in both ECC-2:2024 and NCNICC-1:2025.
  • Audit logs and compliance reports: Trio MDM maintains logs of admin panel activities, device activities, incidents, and actions taken on devices, providing the audit trails that ECC-2:2024's evidence-based compliance requirements demand. These are accessible separately from compliance reports and cover the full evidence scope ECC-2:2024 requires.
  • Remote lock and wipe: Trio MDM supports remote lock and wipe for lost or stolen devices, a direct control requirement under the Mobile Devices Security subdomain.
  • Cross-platform support: Trio MDM manages Android, iOS/iPadOS, macOS, and Windows devices, covering the mixed device fleets typical in SMB environments now subject to NCNICC-1:2025.
  • Automated policy enforcement: Trio MDM applies security profiles and configurations automatically, reducing the manual overhead of maintaining continuous compliance for small IT teams.

Governance documentation, Saudization workforce obligations, and audit certification sit outside MDM scope, those need to be managed by your team and compliance advisors in parallel. Trio MDM covers the technical device control layer, which is where most organizations carry their largest compliance gap.

Ready to close your device-level control gaps? Start your free trial or Book a demo to see how Trio MDM maps to your NCA compliance requirements.

Ready-to-use Templates

Must-have Template Toolkit for IT Admins

Explore All
Template Toolkit

Start your free trial

No credit card required
Full access to all features

Get Ahead of the Curve

Every organization today needs a solution to automate time-consuming tasks and strengthen security. Without the right tools, manual processes drain resources and leave gaps in protection. Trio MDM is designed to solve this problem, automating key tasks, boosting security, and ensuring compliance with ease.

Don't let inefficiencies hold you back.

Every organization today needs a solution to automate time-consuming tasks and strengthen security. Without the right tools, manual processes drain resources and leave gaps in protection. Trio MDM is designed to solve this problem, automating key tasks, boosting security, and ensuring compliance with ease.

Smiling womanAbstract geometric patternAbstract geometric patternSmiling womanSmiling woman

Frequently Asked Questions (FAQ)

Yes. An organization subject to NCNICC-1:2025 that also uses cloud workloads and employs remote workers is simultaneously subject to CCC-1:2020 and TCC-1:2021. These frameworks share significant structural overlap in their Defense and Governance domains, meaning controls implemented for one framework reduce the gap for others. A gap assessment that maps controls across all applicable frameworks prevents redundant remediation work and clarifies exactly where the real gaps are.

Evidence in the ECC-2:2024 context means demonstrable proof that a control is actively enforced, not just a policy document stating that it should be. This includes configuration audit logs showing encryption is enforced on managed devices, access control records showing only authorized users have system access, and incident monitoring logs showing active detection and response. The shift is from "we have a policy about this" to "here is the log showing the policy is being enforced right now."

No. The NCA Regulations 2024 already established formal enforcement authority and a SAR 25 million penalty ceiling. The absence of a specific NCNICC-1:2025 deadline does not mean the framework is unenforceable, it means the enforcement timeline is at NCA's discretion. BSA Law's commentary explicitly advises against treating deadline ambiguity as an invitation to delay. Starting with a gap assessment now costs nothing and positions your organization ahead of enforcement activity.

Partially. ISO 27001 and NCA ECC-2:2024 share common principles in governance and risk management, and an existing ISO 27001 information security management system can serve as a useful engine for driving ECC compliance activities. They are not equivalent frameworks, though, ECC-2:2024 is prescriptive, with specific named controls that are mandatory, while ISO 27001 is a risk management framework without prescriptive technical mandates. An ISO 27001 certification does not satisfy ECC-2:2024 obligations, and both may need to be maintained simultaneously.

Subdomain 2-6 sits within the Cybersecurity Defense domain and covers the mandatory control requirements for mobile device management in NCA-regulated organizations. Controls in this category typically address device enrollment and registration, enforcement of encryption and password policies, remote wipe capability for lost or stolen devices, app management and restriction of unauthorized applications, and monitoring of device compliance status. For the exact control text, consult the NCA official ECC-2:2024 PDF directly, control-level specifics require reading from the primary source.

Related

From the blog

The related industry news, interviews, technologies, and resources.