Which KSA Cybersecurity Obligations Apply to You

Saudi Arabia is not one regulatory stack. The first deliverable of any program is deciding which obligations actually apply — before a single control is written. A scoping matrix, by entity type.

Provenance: curated from the regulators' own published instruments; each row carries its source. Last verified 2026-08-09. Scoping reference, not a legal determination — applicability turns on licence class, designation, and data, so confirm against the current official texts before relying on a row.
If you are…Primary obligationLikely add-ons
A licensed bank or credit bureau SAMA Cyber Security Framework + Business Continuity Management Framework + IT Governance Framework Source: SAMA Rulebook — CSF §1.4, BCM §1.4, ITGF scope (“Banking Sector — Credit Bureaus”, circular 43028139) NCA ECC, PDPL, NCA Cloud Cybersecurity Controls (CCC) where cloud services are used
A SAMA-licensed finance company or payment service provider SAMA Cyber Security Framework + Business Continuity Management Framework; IT Governance Framework where SAMA’s applicable instruments require it (SAMA’s ITGF announcement names local banks, Saudi Payments and credit information companies) Source: SAMA Rulebook — CSF §1.4 and scope tags, BCM §1.4; SAMA ITGF announcement, 12 Dec 2021 NCA ECC, PDPL, NCA Cloud Cybersecurity Controls (CCC) where cloud services are used
Seeking a SAMA licence or a Regulatory Sandbox place SAMA Cyber Resilience Fundamental Requirements (CRFR) now; CSF and BCM obligations apply after licensing Source: SAMA Rulebook — CRFR §1.2 NCA ECC and PDPL as applicable to the entity
Government / public sector NCA Essential Cybersecurity Controls (ECC-2:2024) Source: NCA regulatory documents NCA Data Cybersecurity Controls (DCC-1:2022), NCA CCC, PDPL, NDMO data management & personal data protection standards
An operator of systems designated critical (CNI) NCA Critical Systems Cybersecurity Controls (CSCC-1:2019), in addition to ECC Source: NCA regulatory documents NCA CCC, DCC, and sector-specific rules; NCA OTCC where industrial/OT estates are in scope
Cloud / telecom / hosting NCA Cloud Cybersecurity Controls (CCC-2:2024) · CST Cybersecurity Regulatory Framework (CRF, levels CL1–CL3) Source: NCA regulatory documents; CST regulatory framework Data-localization requirements, NCA ECC; CST cloud framework obligations for licensed cloud providers
Anyone processing personal data PDPL + Implementing Regulations (SDAIA). Article 2 scope: any processing of personal data of individuals residing in the Kingdom, including by entities outside it; purely personal or family use is excluded Source: PDPL and Implementing Regulations, SDAIA Personal Data Transfer Regulation (cross-border); NDMO standards for public entities and partners handling government data
An Aramco supplier SACS-002/SACS-210 supplier cybersecurity requirements (current version) + the Aramco Cybersecurity Compliance Certificate (CCC / CCC+) route Source: Aramco supplier cybersecurity requirements Third-party assurance obligations; NCA controls where the supplier is independently in NCA scope

Naming collision, by the issuers' own choice: two unrelated instruments in this table are both abbreviated "CCC" — NCA's Cloud Cybersecurity Controls and Aramco's Cybersecurity Compliance Certificate. They share nothing but the initials; scope them separately.