Saudi Arabia's National Cybersecurity Authority (NCA) is hosting the Global Cybersecurity Forum (GCF) Annual Meeting in Riyadh on 7-8 October 2026. The theme, per search listings I could not confirm on the GCF's own event page, is 'Institutionalizing Adaptive Collaborations in Cyberspace'. The theme suggests a shift from agenda-setting toward standing cooperation. The more consequential story is domestic. The NCA has extended mandatory controls to a very large population of ordinary private firms.
What the NCA actually adopted
On 28 December 2025 the NCA adopted the Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC-1:2025), according to the Digital Policy Alert record of the measure. The framework covers private entities that do not own, operate or host critical national infrastructure (CNI). Those operators were already under the NCA's Essential Cybersecurity Controls.
The framework has two tiers, as summarised by CMS and Baker McKenzie:
- Large entities: more than 250 full-time employees or revenue above SAR 200 million. They face 65 essential controls across 22 sub-components, covering governance, defence, and third-party and cloud security.
- SMEs: 6 to 249 full-time employees, or revenue between SAR 3 million and SAR 200 million. They face 26 essential controls across 13 sub-components, and some of these are marked 'recommended' rather than mandatory.
CMS describes the controls as legally mandatory for both categories. Baker McKenzie notes that the framework applies to entities 'as notified by the Authority', so the NCA retains discretion over classification and can add requirements for higher-risk sectors. Neither summary specified transition periods or penalties. I could not read the NCA's own Arabic PDF in full, so the compliance timetable remains unverified.
The strongest case for the NCA
The case for this approach deserves a fair hearing. Attackers rarely target a nation's critical infrastructure directly. They go through the smaller suppliers, managed-service providers and subcontractors that connect to it. A control regime that stops at the CNI boundary leaves the most common entry points unprotected. A baseline also gives small firms something they usually lack, a checklist that a customer or insurer will recognise. A tiered design, with fewer controls for smaller firms, is a sensible attempt at proportionality. The NCA's approach is more thoughtful than a flat mandate that treats a six-person agency like a bank.
Where proportionality gets tested
Even so, a floor of six employees is low. A firm that size typically has no security staff. Twenty-six essential controls still mean asset inventories, access management, vulnerability handling and incident response, and a small firm will probably buy those as consulting or managed services. The compliance cost is real, and it falls on the smallest firms hardest. Saudi Arabia is trying to grow its private digital sector, and a compliance floor that is expensive for startups works against that goal.
Three design questions will decide whether the regime helps or hurts:
- Notification and clarity. If the NCA decides case by case who is covered, firms need prompt notice and a clear route to confirm their tier. Uncertainty is itself a cost, and it falls on firms with no in-house counsel.
- Outcome over paperwork. Controls that are measured by evidence of reduced incidents will do more than controls measured by documents. The risk of any mandatory checklist is that firms optimise for the audit, not for resilience.
- Phased, supported enforcement. Published transition periods, templates and cheap assessment tools matter more for six-person firms than for large ones. Penalties applied before capacity exists teach firms to avoid scrutiny.
The cloud and third-party component also needs care. If vendor-vetting requirements push small firms toward a narrow set of pre-approved providers, the market for local and open-source tooling shrinks. Technology-neutral requirements keep that market open.
What the forum can and cannot add
The GCF's stated aim of 'institutionalizing' collaboration is a fair ambition. Cyber incidents cross borders, and informal conferences produce communiqués more reliably than shared practice. The Riyadh meeting would be more credible if it published how Saudi controls compare with other regimes, and how firms that comply with international standards can show equivalence. Mutual recognition of baselines would cut duplicated audits for companies that operate in several markets. Whether the forum delivers that is unknown. Programme details for the 2026 meeting were not available to me when I checked, so any claims about its outcomes are premature.
The NCA is not wrong to extend baseline security to the wider economy. The open question is whether it does so in a way that small firms can sustain. The tiering is a good start. The NCA should publish its notification process, transition timelines and any penalty schedule so that six-person firms can plan. It should also measure results in incidents prevented, not in checklists completed. If it does, the extension of controls will make the Saudi digital economy more resilient. If it does not, it risks teaching small firms that compliance and security are two different activities.