NCA's New Cybersecurity Controls for Private Sector Entities (NCNICC-1:2025): Who Must Comply and How to Prepare

   Disclaimer: This article is for educational guidance only and reflects publicly available secondary-source reporting on the NCA's Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025) as of the publication date above. The National Cybersecurity Authority's official document could not be independently...

  • September 30, 2026
  • 7Mins
مشهد حضري حديث في السعودية يضم مباني أعمال خاصة محاطة بإطار رقمي للأمن السيبراني، مع درع حماية مركزي وأيقونات ترمز إلى الحوكمة والحوسبة السحابية والخوادم وإدارة الوصول والأطراف الثالثة.
  

Disclaimer: This article is for educational guidance only and reflects publicly available secondary-source reporting on the NCA's Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025) as of the publication date above. The National Cybersecurity Authority's official document could not be independently re-verified at the time of writing; organizations should confirm current requirements directly against the NCA's published controls document before making compliance decisions.

Arabic infographic explaining that NCNICC-1:2025 introduces new mandatory cybersecurity controls that bring most Saudi private-sector organizations within scope, illustrated with business buildings and a compliance check mark.

Why This Matters Now

For years, Saudi Arabia's cybersecurity compliance conversation has centered on two audiences: government entities and operators of critical national infrastructure, governed by the Essential Cybersecurity Controls (ECC), and banks and financial institutions, governed by SAMA's own frameworks. Everyone else — the retailer, the logistics firm, the mid-sized manufacturer, the professional services company — has largely operated without a dedicated national cybersecurity baseline.

That changed with NCNICC-1:2025, the National Cybersecurity Authority's Cybersecurity Controls for Private Sector Entities Not Considered Critical Infrastructure. Multiple international law firms tracking Saudi regulatory developments — including Baker McKenzie, CMS Law, and BSA Law — confirm the NCA published these controls in late December 2025, extending a mandatory cybersecurity baseline to private-sector organizations across the Kingdom for the first time, regardless of industry.

This guide explains who falls in scope, what the controls actually require, how NCNICC-1 differs from the ECC and sector frameworks like SAMA's Cybersecurity Framework, and the practical steps to start closing the gap. Structured training such as the institute's own Cybersecurity Governance, Risk & Compliance (GRC) course can shorten that path considerably for teams building this capability from scratch.

What Is NCNICC-1:2025?

NCNICC-1:2025 is a standalone controls document issued by the NCA that applies specifically to private organizations operating in Saudi Arabia that are not classified as critical national infrastructure and are not already subject to a sector-specific framework such as the ECC or SAMA's cybersecurity requirements. Its stated purpose is to raise the baseline cybersecurity posture of the broader private sector — the segment of the economy that previously had no dedicated national cybersecurity mandate at all.

Source: Baker McKenzie, "Saudi Arabia: Cybersecurity Controls for Private Entities" (2026); CMS Law legal update (2026).

Unlike the ECC — which was written for large, often state-linked entities managing sensitive national systems — NCNICC-1 is calibrated for organizations that range from small growing companies to large private employers. It is the first time a huge share of Saudi Arabia's private economy has a named, structured cybersecurity obligation to work against.

Who Must Comply: The Two Entity Categories

The NCA scopes obligations by organization size, using employee count or annual revenue, whichever applies:

Category

Employee Count

Annual Revenue

Compliance Load

Category A — Large Entities

More than 250 full-time employees

More than SAR 200 million

Full control set: ~65 controls across 22 sub-components

Category B — SMEs

6–249 full-time employees

SAR 3 million – SAR 200 million

Reduced set: ~26 controls across 13 sub-components, some "Recommended"

Source: CMS Law (2026); Baker McKenzie (2026).

Organizations below the Category B floor (fewer than 6 employees and under SAR 3 million in revenue) are not currently in scope, though the NCA retains discretion to bring specific entities into scope where it judges the risk warrants it — for example, a small company handling unusually sensitive data or serving a critical-sector client.

If your organization already complies with the ECC (because you are part of critical infrastructure) or with SAMA's cybersecurity requirements (because you are a regulated financial institution), NCNICC-1 is not a second, overlapping obligation — it is specifically scoped to organizations outside those existing frameworks.

The Three Control Pillars

NCNICC-1 organizes its requirements around three core themes, each broken into further sub-components depending on entity category:

1. Cybersecurity Governance — board- and management-level accountability, a documented cybersecurity policy, defined roles and responsibilities, risk management processes, staff awareness and training, and internal audit of the cybersecurity program.

2. Cybersecurity Defense — the operational and technical baseline: asset inventory and classification, identity and access management, endpoint and network security, secure configuration, vulnerability management, cryptography aligned with the NCA's National Cryptographic Standards, and incident detection and response.

3. Third-Party and Cloud Computing Security — contractual cybersecurity requirements for vendors and service providers, data classification obligations when data leaves the organization's own environment, environment separation, and oversight of cloud service providers.

Source: Baker McKenzie (2026); CMS Law (2026); CyberArrow, "What Is NCA NCNICC-1:2025?" (2026).

Readers who have already worked through the ECC or built out a GRC framework will recognize the shape of these three pillars — NCNICC-1 borrows the same governance-defense-third-party logic, scaled down to match private-sector resourcing.

rabic comparison table showing three Saudi cybersecurity frameworks: NCA ECC, SAMA CSF, and NCNICC-1:2025, comparing covered entities, control depth, and compliance or enforcement status.

How NCNICC-1 Compares to the ECC and SAMA's Cybersecurity Framework

Framework

Who It Covers

Control Depth

Compliance Deadline

ECC (Essential Cybersecurity Controls)

Government entities and critical national infrastructure operators

114 controls across 5 domains

Mandatory, audited

SAMA Cybersecurity Framework (CSF)

Banks and SAMA-regulated financial institutions

Maturity-scored across 4 domains (L0–L5)

Mandatory, supervised

NCNICC-1:2025

All other private-sector entities (non-CNI, non-financial) above the SME floor

26–65 controls depending on entity size

Not yet published nationwide — see below

If your organization is exploring whether it sits under NCNICC-1, the ECC, or SAMA's framework, it's worth reading how the ECC audit process actually works — the underlying audit logic (evidence collection, control mapping, remediation planning) carries over from the ECC world even though NCNICC-1 is a lighter-weight framework.

What Happens If You Don't Prepare

NCNICC-1 does not currently carry a single, published nationwide compliance deadline in the way ZATCA's e-invoicing waves do. Instead, based on the secondary-source reporting available, the NCA appears to be applying it through individual notification — meaning specific entities may be formally brought into scope and given a compliance timeline directly by the Authority, rather than every eligible company facing the same fixed date.

That does not make the risk theoretical. In practice, unpreparedness for NCNICC-1 tends to surface in three ways:

Regulatory notification. If the NCA notifies your organization that it is in scope, you may have limited time to demonstrate governance and technical controls are already in place — starting from zero at that point is a difficult position.

Commercial due diligence. Larger clients, government tenders, and financial institutions increasingly ask private-sector vendors to demonstrate cybersecurity maturity as a condition of doing business — NCNICC-1 gives them a named national standard to ask about.

Incident response exposure. In the event of a breach, the absence of documented governance and technical controls consistent with a recognized national framework can significantly worsen both the regulatory and reputational outcome.

Organizations that have already built general cybersecurity GRC capability are typically much closer to NCNICC-1 readiness than those starting from nothing, since the governance and risk-management logic is largely shared across frameworks.

Arabic NCNICC-1 readiness checklist outlining seven steps for Saudi organizations, including determining scope, checking ECC or SAMA CSF coverage, conducting gap assessments, assigning governance responsibility, reviewing third-party and cloud exposure, prioritizing remediation, and documenting policies and risk records.

Readiness Checklist: Where to Start

1. Determine your category. Calculate your organization's full-time employee count and prior-year revenue against the Category A / Category B thresholds above.

2. Confirm you are genuinely in scope. Rule out that you are already covered by the ECC (critical infrastructure) or SAMA's frameworks (regulated financial institution) — if so, NCNICC-1 does not apply to you separately.

3. Run a gap assessment against all three pillars — governance, defense, and third-party/cloud — using your applicable control count (26 for most SMEs, 65 for Category A) as the checklist.

4. Assign accountable ownership. Name a person or committee responsible for the cybersecurity governance pillar specifically — this is usually the fastest-scoring gap for organizations with no prior cybersecurity function.

5. Inventory your third-party and cloud exposure. Map every vendor, SaaS tool, and cloud provider that touches company data; this pillar is frequently under-documented even in organizations with decent technical controls.

6. Build a prioritized remediation plan, closing governance gaps first (fastest and cheapest to fix), then technical defense gaps, then third-party contractual gaps.

7. Document everything. Evidence — policies, training records, risk registers, incident logs — is what turns a technical control into a defensible compliance position if the NCA ever asks.

Frequently Asked Questions

Find quick answers to frequently asked questions. Can't find what you're looking for?

Yes — that is precisely the gap NCNICC-1 was created to close. If your organization is a private-sector entity in Saudi Arabia with 6 or more full-time employees or SAR 3 million or more in annual revenue, and you are not already governed by the ECC or a sector framework like SAMA's, you likely fall within its scope.

Based on currently available secondary-source reporting, no single published nationwide deadline exists. The NCA appears to notify in-scope entities individually. Given that uncertainty, the safer approach is to begin a gap assessment now rather than wait for a formal notice.

The ECC targets government entities and critical national infrastructure operators, with 114 controls across 5 domains. NCNICC-1 targets the broader private sector outside critical infrastructure, with a lighter 26–65 control set depending on company size — read more in our guide to the ECC.

No. NCNICC-1 is scoped to entities outside existing sector-specific frameworks. If you are a SAMA-regulated financial institution already working to the CSF, that framework — not NCNICC-1 — is your governing standard.

Cybersecurity Governance, Cybersecurity Defense (the technical and operational baseline), and Third-Party and Cloud Computing Security. Category A entities work to the full control set across all three; Category B (SME) entities work to a reduced set, with some controls marked "Recommended" rather than mandatory.

Start with the governance pillar: naming an accountable owner, documenting a basic cybersecurity policy, and running staff awareness training. These steps are typically the fastest to implement and often reveal the scope of your remaining technical and third-party gaps.