Saudi Arabia's essential cybersecurity controls framework, issued by the National Cybersecurity Authority (NCA), structured into 4 domains, 28 sub-domains, and roughly 110 controls.
Last updated — August 22, 2026
Saudi organizations classified as Class A or Class B entities based on their criticality, along with their cybersecurity service providers. Additional sector-specific rules apply depending on the activity, notably from SAMA (financial sector), CITC (telecoms), and SDAIA (data and artificial intelligence).
Implementation of roughly 110 controls spanning the 4 domains and 28 sub-domains of ECC-2:2024, with the level of stringency differentiated by the entity's classification (Class A or Class B). The framework also mandates Saudization of key cybersecurity roles, which directly shapes how a foreign provider can operate in this market.
Deadlines
Compliance deadlines are set by the NCA based on the entity's classification and the rollout timeline applicable to its sector.
Sanctions
Sanctions fall under the NCA and the relevant sector authorities (SAMA, CITC, SDAIA depending on sector); they are not detailed here in the absence of a consolidated public scale.
Determine the entity's classification (Class A or Class B)
Gap analysis against the roughly 110 ECC-2:2024 controls
Structure the compliance plan by domain and sub-domain
Implement the required technical and organizational controls
Document compliance for NCA review purposes
| Framework | Covered |
|---|---|
| sama-csf | ✓ |
Get the checklist by email.
The classification reflects the entity's criticality level and determines the degree of rigor expected in implementing the controls; it is determined by the NCA.
ECC-2:2024 requires that certain key cybersecurity roles be filled by Saudi nationals, which structurally limits direct market entry for foreign providers on this scope.
On roles subject to Saudization, EBH Security delivers its services alongside local Saudi actors — providing methodological support and technical expertise, while its Saudi partners handle direct work within the regulated market, in line with the Saudization requirement.
An adjacent framework issued within the same Saudi regulatory ecosystem as ECC-2:2024, whose detailed content falls outside the scope of this page.
Yes, for entities within their respective sectors — finance for SAMA, telecommunications for CITC, data and AI for SDAIA — these rules apply in addition to, not instead of, the ECC-2:2024 controls.