NCNICC-1:2025 extends the National Cybersecurity Authority's structured control approach to private-sector organisations that sit outside critical national infrastructure. For a large part of the Saudi economy this is a shift: cybersecurity expectations that were previously implicit, or arrived only through customer contracts, become a defined framework to assess against.
Why it matters
The NCA's earlier frameworks concentrated on government entities and critical national infrastructure. That left a substantial gap - private-sector organisations that are not designated CNI but still hold significant data, serve regulated customers, or form part of critical supply chains. NCNICC addresses that population directly rather than reaching them indirectly through their clients.
Who should pay attention
- Private-sector organisations operating in the Kingdom outside the CNI designation.
- Companies supplying government entities or CNI operators, who already face security requirements through contracts.
- Fast-growing technology and services businesses that have outgrown informal security practices.
- Organisations that will need to demonstrate a defined cybersecurity posture to customers, insurers or investors.
Scope, applicability and timelines are set by the NCA and its published documentation. Confirm whether and how it applies to your organisation through the NCA or qualified local advisors before committing to a programme - this article is orientation, not a compliance determination.
What to expect from the control set
NCA frameworks share a consistent architecture - main domains, subdomains and specific controls, assessed on implementation with evidence. Based on that established pattern, prepare for requirements across familiar territory:
- Governance - documented policy, defined ownership, risk management, awareness.
- Asset management - knowing what you have, because everything else depends on it.
- Identity and access - authentication strength, privileged access, joiner-mover-leaver discipline.
- Data protection - classification, encryption, controlled handling.
- Technical hardening - secure configuration, patching, network protection.
- Logging, detection and incident response.
- Resilience - backup, recovery and continuity that has been tested.
- Third-party and cloud risk.
Find out where you stand
GRC Copilot assesses your organisation against NCNICC-1:2025 and reuses evidence from any ISO 27001 or ECC work you have already done - turning an unfamiliar framework into a prioritised gap list.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
How it relates to the ECC
The Essential Cybersecurity Controls remain the baseline for government entities and CNI operators. NCNICC applies the same regulatory philosophy - defined controls, implementation scoring, evidence - to a different population. If you already work toward the ECC because a customer requires it, you are substantially prepared. The control subject matter overlaps heavily; what differs is applicability and the specific set you are measured against.
A sensible first 90 days
- Determine applicability formally, and record the reasoning either way.
- Assign an owner with authority and budget.
- Build an asset inventory - it unblocks most other controls.
- Run a gap assessment and score honestly rather than optimistically.
- Fix identity first - MFA, privileged access and offboarding deliver the largest early risk reduction.
- Start capturing evidence now so you are not reconstructing history later.
- Map to what you already have - ISO 27001, ECC or customer security requirements all carry over.
Frequently asked questions
Does this apply to us?
Applicability is determined by the NCA's published scope. If you operate in the Kingdom outside CNI designation, check directly rather than assuming exclusion - and document your conclusion.
Is ISO 27001 enough?
It is a strong foundation and much of the evidence transfers, but a national framework has its own control set and expectations that must be addressed explicitly.
Where do organisations struggle most?
The same places as in every first assessment: an incomplete asset inventory, third-party and cloud controls, and evidence that exists only as intent rather than records.
What if we already comply with the ECC for a customer?
You are well placed. Map your existing controls across and focus on the differences rather than starting a second programme.
Key takeaways
- NCNICC extends structured NCA-style requirements to non-CNI private-sector entities.
- Confirm applicability formally with the NCA and document the reasoning.
- Expect the familiar domains: governance, assets, identity, data, hardening, resilience, third parties.
- Existing ISO 27001 or ECC work transfers substantially.