Saudi Arabia is not one regulatory stack. The first deliverable of any program is deciding which obligations actually apply — before a single control is written. A scoping matrix, by entity type.
| If you are… | Primary obligation | Likely add-ons |
|---|---|---|
| A licensed bank or credit bureau | SAMA Cyber Security Framework + Business Continuity Management Framework + IT Governance Framework Source: SAMA Rulebook — CSF §1.4, BCM §1.4, ITGF scope (“Banking Sector — Credit Bureaus”, circular 43028139) | NCA ECC, PDPL, NCA Cloud Cybersecurity Controls (CCC) where cloud services are used |
| A SAMA-licensed finance company or payment service provider | SAMA Cyber Security Framework + Business Continuity Management Framework; IT Governance Framework where SAMA’s applicable instruments require it (SAMA’s ITGF announcement names local banks, Saudi Payments and credit information companies) Source: SAMA Rulebook — CSF §1.4 and scope tags, BCM §1.4; SAMA ITGF announcement, 12 Dec 2021 | NCA ECC, PDPL, NCA Cloud Cybersecurity Controls (CCC) where cloud services are used |
| Seeking a SAMA licence or a Regulatory Sandbox place | SAMA Cyber Resilience Fundamental Requirements (CRFR) now; CSF and BCM obligations apply after licensing Source: SAMA Rulebook — CRFR §1.2 | NCA ECC and PDPL as applicable to the entity |
| Government / public sector | NCA Essential Cybersecurity Controls (ECC-2:2024) Source: NCA regulatory documents | NCA Data Cybersecurity Controls (DCC-1:2022), NCA CCC, PDPL, NDMO data management & personal data protection standards |
| An operator of systems designated critical (CNI) | NCA Critical Systems Cybersecurity Controls (CSCC-1:2019), in addition to ECC Source: NCA regulatory documents | NCA CCC, DCC, and sector-specific rules; NCA OTCC where industrial/OT estates are in scope |
| Cloud / telecom / hosting | NCA Cloud Cybersecurity Controls (CCC-2:2024) · CST Cybersecurity Regulatory Framework (CRF, levels CL1–CL3) Source: NCA regulatory documents; CST regulatory framework | Data-localization requirements, NCA ECC; CST cloud framework obligations for licensed cloud providers |
| Anyone processing personal data | PDPL + Implementing Regulations (SDAIA). Article 2 scope: any processing of personal data of individuals residing in the Kingdom, including by entities outside it; purely personal or family use is excluded Source: PDPL and Implementing Regulations, SDAIA | Personal Data Transfer Regulation (cross-border); NDMO standards for public entities and partners handling government data |
| An Aramco supplier | SACS-002/SACS-210 supplier cybersecurity requirements (current version) + the Aramco Cybersecurity Compliance Certificate (CCC / CCC+) route Source: Aramco supplier cybersecurity requirements | Third-party assurance obligations; NCA controls where the supplier is independently in NCA scope |
Naming collision, by the issuers' own choice: two unrelated instruments in this table are both abbreviated "CCC" — NCA's Cloud Cybersecurity Controls and Aramco's Cybersecurity Compliance Certificate. They share nothing but the initials; scope them separately.