HomeFrameworksSaudi NCNICC
National Cybersecurity Authority (NCA) · Saudi Arabia

Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC-1:2025) compliance software

NCA's cybersecurity baseline for Saudi private sector entities outside critical national infrastructure — 112 controls across governance, defense and third-party/cloud security, scoped to the entity's own size category.

At a glance
  • Issuing authorityNational Cybersecurity Authority (NCA)
  • InstrumentNCNICC-1:2025
  • Structure3 components, 22 subdomains, 112 controls
  • ApplicabilityCategory A — all mandatory; Category B — mandatory/recommended per control
Saudi NCNICCAvailable
Overview

What Saudi NCNICC requires

Who it applies to

  • Saudi private sector entities not designated Critical National Infrastructure
  • Category A entities — over 250 employees or SAR 200m+ annual revenue
  • Category B small and medium entities — 6–249 employees or SAR 3–200m revenue
  • Group compliance functions determining which entities in scope fall into which category

The Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC-1:2025) are issued by Saudi Arabia's National Cybersecurity Authority for private sector organisations that are not designated Critical National Infrastructure — the population NCA ECC does not reach. The controls set a minimum cybersecurity baseline scaled to the size of the entity.

NCA splits applicability into two categories: Category A, entities with more than 250 full-time employees or more than SAR 200 million in annual revenue, and Category B, entities with 6 to 249 employees or SAR 3–200 million in revenue, following the SME definition of the General Authority for Small and Medium Enterprises. Every control is mandatory for Category A; for Category B, NCA marks each control mandatory or recommended individually, and the mandatory set sits almost entirely inside the Cybersecurity Defense component.

112 controls span three components — Cybersecurity Governance, Cybersecurity Defense and Third-Party and Cloud Computing Cybersecurity — across 22 subdomains. GRCLens carries the controls with both categories' applicability marked on every control, so an entity declares its category once and the assessment, dashboard and report scope to what NCA actually requires of it.

In the platform

How GRCLens supports Saudi NCNICC

Saudi NCNICC runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Category picker scopes the assessment

Declare Category A or Category B once and the dashboard reports against the applicability NCA actually set for that category — a Category B entity is not held to controls NCA marked recommended for it.

Mandatory scope tracked separately

Category B's mandatory controls sit almost entirely inside Cybersecurity Defense; Governance and Third-Party/Cloud are recommended only. The dashboard reports the mandatory tier on its own so it cannot hide behind a healthy overall average.

112 controls, NCA's own structure

Governance, Defense, and Third-Party and Cloud Computing Cybersecurity, each control carrying its own applicability marker and deliverable.

Arabic and English

Every control, category and guidance note is carried in both languages, matching NCA's Arabic original.

Questions

Saudi NCNICC frequently asked questions

Who has to comply with NCNICC-1:2025?

Private sector entities in Saudi Arabia that are not designated Critical National Infrastructure. CNI operators and government entities fall under NCA ECC instead; cloud service providers and tenants have their own CCC-2:2024 controls.

What is the difference between Category A and Category B?

Category A is entities with more than 250 employees or over SAR 200 million in annual revenue; Category B is 6 to 249 employees or SAR 3–200 million revenue, following the General Authority for Small and Medium Enterprises' SME definition. Category A must meet every control; Category B's mandatory set is a defined subset, concentrated in the Defense component.

How does this relate to NCA ECC and the CCC?

NCA ECC is the baseline for government entities and Critical National Infrastructure operators; the CCC-2:2024 governs cloud service providers and tenants. NCNICC-1:2025 fills the remaining gap — private sector entities that are neither CNI nor primarily a cloud arrangement.

Talk to us about Saudi NCNICC

Security Solution Consultants provides Saudi NCA compliance advisory alongside the platform, so you can combine tooling with hands-on expertise.