World Watch/Saudi Arabia/Cybersecurity

Cybersecurity · Saudi Arabia

Cybersecurity - Saudi Arabia

Comprehensive lawNational Cybersecurity Authority (NCA) — the supreme national cyber authority (established by Royal Order in 2017) issuing binding controls including the Essential Cybersecurity Controls (ECC); complemented by the Anti-Cyber Crime Law (Royal Decree M/17, 2007) and sectoral/data-protection regimes (SAMA, SDAIA/PDPL).

Saudi Arabia operates a comprehensive, centralized cybersecurity regime led by the National Cybersecurity Authority (NCA), which sets and enforces mandatory frameworks across government, critical national infrastructure (CNI), and the private sector. This is layered with the Anti-Cyber Crime Law (criminal offences), sector-specific rules from the Saudi Central Bank (SAMA) for financial institutions, and personal-data breach-notification duties under the PDPL administered by SDAIA. The regime has been progressively expanded, with updated controls (ECC-2:2024) and new private-sector controls (NCNICC-1:2025) issued recently.

Central national authority (NCA)

The National Cybersecurity Authority was established by Royal Order No. 6801 (31 Oct 2017, amended by Royal Order No. 7053 of 2021) as the kingdom's supreme cybersecurity reference, empowered to set national strategy and issue binding cybersecurity frameworks and controls.

Essential Cybersecurity Controls (ECC)

The NCA's Essential Cybersecurity Controls (originally ECC-1:2018, updated to ECC-2:2024) set mandatory minimum requirements across domains such as governance, defense, resilience, third-party/cloud, and industrial control systems. They apply to government bodies and to entities owning/operating Critical National Infrastructure.

Private-sector controls (NCNICC-1:2025)

The NCA issued new Cybersecurity Controls for Private Sector Entities Not Considered Critical Infrastructure (NCNICC-1:2025), extending mandatory baseline cybersecurity requirements to private organisations across the kingdom that fall outside CNI scope.

Anti-Cyber Crime Law (criminal offences)

The Anti-Cyber Crime Law, enacted by Royal Decree No. M/17 (2007), criminalizes unauthorized access, interception, data interference, and related offences, providing the penal backbone alongside the NCA's preventive/regulatory frameworks.

Financial-sector framework (SAMA)

The Saudi Central Bank (SAMA) Cyber Security Framework (launched 2017, based on NIST/ISO/PCI/ISF/BASEL) is mandatory for SAMA-regulated banks, insurers, finance companies, payment service providers and fintechs, covering risk management, security operations, incident response and governance.

Breach notification & incident reporting

Under the Personal Data Protection Law (PDPL), controllers must notify the data-protection regulator SDAIA of a personal-data breach within 72 hours of becoming aware (where harm or rights infringement may result) and inform affected individuals without delay; reporting runs through the National Data Governance Platform. NCA frameworks separately require incident-response procedures and reporting of cyber incidents.

Machine-assisted translation · verified 5/23/2026 · orientation, not legal advice. English version →