Saudi Arabia has one of the most structured cybersecurity regulatory environments in the region, and the confusion is rarely about any single framework - it is about which authority governs what. Once the map is clear, working out your obligations becomes straightforward.
The three authorities
NCA - National Cybersecurity Authority
The national cybersecurity regulator. Issues the frameworks that form the country's cybersecurity baseline, including:
- Essential Cybersecurity Controls (ECC) - the cross-sector baseline for government entities, CNI operators and organisations mandated through them. Current generation: ECC-2:2024.
- Cloud Cybersecurity Controls (CCC) - cloud-specific requirements split explicitly between providers and tenants.
- Controls for the wider private sector - extending structured requirements beyond CNI, such as NCNICC-1:2025.
- Additional specialised controls for areas such as critical systems and operational technology.
SAMA - Saudi Central Bank
The financial sector regulator. Its Cyber Security Framework applies to banks, insurers, finance companies, credit bureaus and financial market infrastructure - and is distinctive for scoring maturity from 0 to 5 rather than simple implementation. Level 3 is the usual baseline expectation; reaching level 4 requires measurement and reporting.
SDAIA - Saudi Data and AI Authority
The data and AI authority, responsible for the Personal Data Protection Law (PDPL) - the Kingdom's comprehensive privacy regime, applying extraterritorially to the personal data of residents.
Work out what applies to you
GRC Copilot assesses your organisation against the ECC, cloud controls, SAMA CSF and PDPL from a single control set - so overlapping obligations are mapped once, not repeated.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
How the pieces fit
- The ECC is the floor for organisations in its scope. Other frameworks build on it rather than replacing it.
- Sector regulation layers on top. A bank answers to SAMA for its framework while operating within the national cybersecurity direction.
- The PDPL runs alongside, governing personal data specifically. It applies regardless of sector, and regardless of whether you are established in the Kingdom.
- Customer standards reach further still. Large operators such as Aramco impose their own supplier requirements, which is how many international vendors first encounter Saudi cybersecurity expectations.
Determining what applies to you
- Are you a government entity or CNI operator? The ECC applies directly.
- Do you serve one, or are you mandated through one? Requirements reach you contractually.
- Are you regulated by SAMA? The Cyber Security Framework applies, with maturity scoring.
- Do you process personal data of people in the Kingdom? The PDPL applies, wherever you are established.
- Do you use or provide cloud services? The Cloud Cybersecurity Controls define your side of the boundary.
- Are you a private-sector entity outside CNI? Check the applicability of the newer private-sector controls.
- Do you supply a major operator? Expect their standard on top of everything above.
The efficient way to run it
These frameworks overlap heavily - access control, asset management, encryption, logging, incident response, resilience and third-party risk appear in all of them. The organisations that cope well do three things:
- Maintain one control library describing what they actually operate.
- Map every applicable framework onto it, recording where a mapping is only partial.
- Attach evidence to controls, so one artefact serves every framework that requires it.
Scoring differs even where controls match. The ECC asks whether a control is implemented; SAMA asks how mature it is. The same evidence can answer both - but only if you score twice from one source of truth rather than running two programmes.
Direction of travel
The trajectory is clear: broader scope, more sectors, and more explicit expectations for cloud, third parties and AI. Organisations that build a genuine control library now absorb each new framework as a mapping exercise. Those running framework-by-framework projects repeat the full cost every time.
Frameworks and their implementing guidance are updated periodically. Confirm current versions and applicability with the relevant authority or qualified local advisors.
Frequently asked questions
If we comply with the ECC, do we still need SAMA CSF?
Yes, if you are SAMA-regulated. The ECC covers much of the substance, but SAMA has its own control set and maturity scoring that must be addressed directly.
Does the PDPL apply to companies outside Saudi Arabia?
Yes, where they process the personal data of people residing in the Kingdom.
Is there a single certification covering everything?
No. These are distinct regulatory regimes with distinct reporting. ISO 27001 supports all of them by providing the management system and evidence discipline, but satisfies none of them by itself.
Where should an organisation start?
An asset inventory and a control library. Both are prerequisites for every framework here, and neither is wasted regardless of which obligations ultimately apply.
Key takeaways
- NCA governs national cybersecurity, SAMA the financial sector, SDAIA personal data.
- The ECC is the floor; sector and customer requirements layer on top.
- The PDPL applies extraterritorially and runs alongside everything else.
- One control library plus mapping absorbs new frameworks cheaply.