Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity services — Saudi Arabia

Methodological support and subcontracting with Saudi-based actors, within a framework structured by the Saudization of cybersecurity roles.

Last updatedAugust 22, 2026

The local regulatory framework

Saudi Arabia's cybersecurity framework is overseen by the National Cybersecurity Authority (NCA), the Saudi Central Bank (SAMA), the Communications, Space & Technology Commission (CITC) and the Saudi Data & AI Authority (SDAIA). The central reference is the Essential Cybersecurity Controls (ECC-2:2024) — 4 domains, 28 sub-domains, around 110 controls split into classes A and B depending on the organization's criticality. It is complemented by the NCNICC-1:2025 for national critical infrastructure, sector-specific frameworks (CSCC, CCC, OTCC, DCC, TCC), the SAMA Cyber Security Framework for the financial sector, and the Personal Data Protection Law (PDPL).

Concrete obligations

Application of the ECC-2:2024 (around 110 controls across 4 domains and 28 sub-domains) according to the organization's assigned class A or B

Compliance with the NCNICC-1:2025 for national critical infrastructure operators

Compliance with the SAMA Cyber Security Framework for financial entities regulated by the Saudi Central Bank

Application of the NCA's complementary sector frameworks (CSCC, CCC, OTCC, DCC, TCC) depending on the activity

The Saudization requirement for cybersecurity roles set out in the ECC-2:2024, which structures direct market access for foreign providers

Delivered through subcontracting

In this market, EBH Security delivers exclusively through locally accredited subcontracting partners, in line with the applicable regulatory framework.

Priority sectors

FinanceEnergyCritical infrastructure

Delivery modalities

Engagement model

Delivery in partnership with Saudi-based actors, ensuring full compliance with Saudization requirements while drawing on EBH Security's expertise

Approach

The ECC-2:2024 governs the Saudization of cybersecurity roles; EBH Security relies on local partnerships to ensure full compliance with this requirement

Languages

Arabic, English, French

Local FAQ

Can EBH Security operate directly in Saudi Arabia?

On the segment regulated by the ECC-2:2024, EBH Security operates in partnership with Saudi-based actors, in compliance with the Saudization requirements for cybersecurity roles. This approach ensures full regulatory compliance while drawing on EBH Security's expertise and methodologies.

What is the ECC-2:2024?

The Essential Cybersecurity Controls framework issued by the National Cybersecurity Authority, structured into 4 domains and 28 sub-domains, comprising around 110 controls split into classes A and B depending on the organization's criticality.

Are all organizations subject to the ECC-2:2024?

The framework primarily targets government entities and critical infrastructure operators; its exact scope of application is determined by the NCA on a case-by-case basis.

What is the NCNICC-1:2025?

A complementary NCA framework dedicated to national critical infrastructure, applicable to operators designated as such.

Does the financial sector have specific obligations?

Yes, entities regulated by SAMA must comply with the SAMA Cyber Security Framework, in addition to the NCA framework.

How does EBH Security concretely work in this market?

Through methodological support — scoping, documentation review, skills transfer — to teams or providers based in Saudi Arabia, without substituting for a local actor on engagements requiring a direct presence.

Does this constraint also apply to penetration testing and technical audits?

Yes, technical engagements on systems subject to the ECC-2:2024 must be carried out by personnel meeting the Saudization requirements; EBH Security can contribute through remote methodological support or by training local teams.

Get in touch