NCNICC-1:2025 Explained: NCA Cybersecurity Controls for Saudi Private Companies
NCNICC-1:2025 is the set of cybersecurity controls the National Cybersecurity Authority (NCA) issued on 28 December 2025 for private-sector companies in Saudi Arabia that are not critical national infrastructure. It contains 65 controls in 3 components. Large companies (Category A: over 250 full-time employees or over SAR 200 million revenue) must apply all 65; small and medium companies (Category B: 6–249 employees or SAR 3–200 million revenue) must apply 26 mandatory controls, with the other 39 recommended.
| Official name (Arabic) | ضوابط الأمن السيبراني لجهات القطاع الخاص من غير ذوات البنى التحتية الحساسة |
|---|---|
| Code | NCNICC-1:2025 |
| Issued by | National Cybersecurity Authority (NCA) |
| Issue date | 28 December 2025 |
| Who it covers | Private-sector entities in Saudi Arabia that are not critical national infrastructure |
| Structure | 3 components · 22 sub-components · 65 controls |
| Category A | >250 full-time employees or >SAR 200M revenue → all 65 controls mandatory |
| Category B | 6–249 employees or SAR 3–200M revenue → 26 mandatory, 39 recommended |
| Certification | None. NCA assesses compliance through the mechanism it deems appropriate |
What is NCNICC-1:2025?
Until recently, Saudi Arabia's best-known cybersecurity baseline, the NCA's Essential Cybersecurity Controls (ECC), was aimed at government bodies and operators of critical national infrastructure. Most private companies (a fintech, a clinic group, an e-commerce brand, a logistics firm) had no NCA framework written specifically for them.
NCNICC-1:2025 closes that gap. The NCA published it in Arabic on 28 December 2025 as ضوابط الأمن السيبراني لجهات القطاع الخاص من غير ذوات البنى التحتية الحساسة, which translates as the cybersecurity controls for private-sector entities that are not critical infrastructure. There is no official English version; law firms use translations such as "Cybersecurity Controls for Private Sector Entities Not Considered Critical Infrastructure."
The document requires continuous compliance rather than setting a one-off deadline. In practice that means you should be able to show, at any time, that the controls apply in your company and are documented.
Who has to comply?
The controls cover small, medium and large private-sector entities operating in Saudi Arabia that are not classified as critical national infrastructure (CNI). They do not cover:
- Government entities and CNI operators. These follow ECC-2:2024 and other NCA frameworks instead.
- Micro entities. The Category B threshold starts at 6 employees, so very small businesses fall outside the two categories.
Commentary from Baker McKenzie also notes that the NCA may apply the controls "as notified by the Authority" in borderline cases. If you are unsure, assume you are in scope and confirm your category.
Category A vs Category B
Your category depends on either headcount or revenue. Meeting one test is enough.
| Category | Threshold | What applies |
|---|---|---|
| A — large | More than 250 full-time employees, or annual revenue above SAR 200 million | All 65 controls are mandatory |
| B — small & medium | 6–249 full-time employees, or annual revenue of SAR 3–200 million | 26 controls mandatory; 39 recommended |
Category B still moves toward the same baseline over time. "Recommended" controls are the first thing an auditor, a bank partner or an enterprise client will ask about after an incident, so treat them as your roadmap.
The 3 components and what they cover
1. Cybersecurity governance
Cybersecurity management and roles, policies and procedures, risk management, periodic review and audit, and awareness and training.
2. Cybersecurity defense
Asset management, identity and access management, system protection, email protection, network security, mobile devices, data protection, cryptography, backups, vulnerability management, penetration testing, logging and monitoring, incident management, physical security and web application protection.
3. Third-party and cloud cybersecurity
Cybersecurity requirements for suppliers and service providers, and for cloud computing and hosting.
The official document is Arabic-only and lists each control and sub-control. Always map your gap assessment to the official control numbers, not to a vendor summary.
Notable requirements
Based on the published controls and legal commentary from firms such as Baker McKenzie, requirements that surprise companies most include:
- An independent cybersecurity function. It sits separately from IT operations, with a defined head of cybersecurity.
- Saudi nationals in key roles. The head of cybersecurity and other sensitive roles should be qualified, full-time Saudi nationals.
- A managed security operations centre (SOC) from an NCA-licensed provider. This is mandatory for Category A and recommended for Category B.
- Multi-factor authentication for remote access. It also applies to privileged accounts, and cryptography must follow the National Cryptographic Standards.
- Cybersecurity clauses in third-party contracts. These are required, along with data classification and environment separation in the cloud.
Enforcement and penalties
There is no NCNICC certificate. The NCA assesses compliance "by the mechanism it deems appropriate," which in practice means documented evidence: policies, a gap assessment, procedures, logs and records.
The NCA's statutory violations framework (Royal Decree M/117, 1446H) lists failure to comply with NCA controls among its violations. It allows warnings, licence or service suspension, and fines of up to SAR 25 million. That figure is a maximum, and enforcement practice for NCNICC specifically is still developing. The more immediate commercial risk is losing tenders, bank partnerships and enterprise contracts that now ask for proof of NCA alignment.
NCNICC-1:2025 vs ECC-2:2024
See our full ECC-2:2024 guide for the details of the essential controls.
| NCNICC-1:2025 | ECC-2:2024 | |
|---|---|---|
| Who | Private companies that are not CNI | Government entities and CNI owners/operators |
| Size | 65 controls, 3 components | 108 main controls, 4 domains |
| Scaling | Category A (all) / Category B (26 mandatory) | Full set for entities in scope |
A fintech licensed by SAMA must also meet the SAMA Cyber Security Framework. Every company handling personal data must meet the Personal Data Protection Law (PDPL). These frameworks overlap heavily, so one well-structured policy set can serve all three.
How to comply: step by step
- Confirm your category. Use your full-time headcount and annual revenue, and document the basis.
- Run a gap assessment. Check every applicable control and rate each one as met, partial or missing.
- Write the policy set. This means an information security policy, acceptable use, access control, incident response, backup, third-party and cloud policies.
- Build a remediation roadmap. Put technical fixes (MFA, logging, backups, email security) in priority order with owners and dates.
- Train staff and keep evidence. Keep attendance, logs, reviews and sign-offs, because evidence is what an assessment checks.
- Review periodically. Compliance is continuous: re-assess when your size, systems or suppliers change.
NCNICC-1:2025 compliance checklist
- Category (A or B) determined and documented
- Cybersecurity function and head of cybersecurity defined, independent of IT
- Board- or CEO-approved information security policy
- Risk assessment completed and risk register maintained
- Asset inventory (hardware, software, cloud, data)
- MFA enforced for remote and privileged access
- Email protection and anti-phishing controls in place
- Backups tested and documented
- Vulnerability scanning and penetration testing schedule
- Logging and monitoring (managed SOC for Category A)
- Incident response plan with roles and contacts
- Cybersecurity clauses in supplier and cloud contracts
- Staff awareness training delivered and recorded
- Periodic review and internal audit scheduled
Frequently Asked Questions
When did NCNICC-1:2025 come out?
The National Cybersecurity Authority issued it on 28 December 2025. The document requires continuous compliance and does not set a separate grace period.
Does NCNICC apply to my company?
It applies to private-sector companies in Saudi Arabia that are not critical national infrastructure. Category A covers companies with more than 250 full-time employees or more than SAR 200 million in revenue; Category B covers 6–249 employees or SAR 3–200 million in revenue.
How many controls does Category B have to implement?
Category B must implement 26 mandatory controls out of 65. The remaining 39 are recommended.
Is there an NCNICC certificate?
No. The NCA does not issue a certificate for NCNICC. Compliance is shown through documented evidence such as policies, a gap assessment, procedures and records.
What is the penalty for not complying?
The NCA statutory violations framework allows warnings, licence or service suspension and fines of up to SAR 25 million. That is a maximum; enforcement practice for NCNICC is still developing.
Is NCNICC the same as ECC?
No. ECC-2:2024 covers government entities and critical infrastructure operators with 108 main controls. NCNICC-1:2025 covers other private-sector companies with 65 controls.
Related guides
Sources
- NCA — NCNICC-1:2025 official page (Arabic)
- NCA news release, 28 Dec 2025 (Arabic)
- Saudi Press Agency announcement
- CMS — New Cybersecurity Controls for the Private Sector
- Baker McKenzie — Cybersecurity Controls for Private Entities (2026)
- Bird & Bird — NCA Regulations 2024 (penalties)
- NCA — Essential Cybersecurity Controls ECC-2:2024 (PDF)
This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.