New Saudi Cybersecurity Regulations
- The Bench

- 2 days ago
- 2 min read
The NCNICC-1:2025 FRAMEWORK

Saudi Arabia recently expanded mandatory cybersecurity compliance to the broader private sector.
Here is what your business need to know.
The National Cybersecurity Authority (NCA) has released NCNICC-1:2025 - a regulatory framework that brings cybersecurity obligations to private sector entities across the Kingdom that are not classified as critical national infrastructure. This marks a fundamental shift: cybersecurity compliance is no longer a concern reserved for banks or regulated companies. It now applies across the players in the market.
This is a direct extension of Vision 2030, which targets and empowers the private sector to play a vital role in the economy. As the private sector grows, so does the exposure to cyber risk – and the NCA is taking the necessary steps.
Does the NCNICC apply to your organization?
Category A - Large entities 250+ employees or Annual Revenue > SAR 200M
| Category B - SMEs 6 to 249 employees or Annual Revenue SAR 3M - 200M
|
65 mandatory controls 22 subsidiary components 3 core components
| 26 mandatory controls 13 subsidiary components 1 core component
|
Note: Micro-enterprises below these thresholds are currently outside mandatory scope - but the NCA strongly encourages them to adopt these controls voluntarily for strengthening their security posture.
Non-compliance is not just a legal risk. It is also a reputational and operational one. The question is not whether to comply - it is how to do so efficiently and without disrupting your business.
We have had the pleasure of assisting organisations in Saudi to navigate these obligations, translating regulatory requirements into practical action plans.
If you wonder whether your organisation falls within NCNICC or are unsure where to start, reach out directly to our Head of FinTech Jouhayna Amr jouhayna@thebenchlaw.com or your normal contact at The Bench.





Comments