Saudi Arabia Saudi NCA cybersecurity national policy

Saudi Arabia's Cyber Rules Now Reach Six-Person Firms, and Proportionality Is the Test of Its Forum Diplomacy

As the NCA hosts the Global Cybersecurity Forum in Riyadh, its NCNICC-1:2025 controls extend mandatory cybersecurity duties to private firms with as few as six employees.

Saudi NCNICC-1:2025 at a glance People of Internet Research · Saudi Arabia 65 Controls for large entities Across 22 sub-components in three … 26 Controls for SMEs Across 13 sub-components; some onl… 6 Minimum covered employees SME tier starts at 6 full-time emp… peopleofinternet.com
Saudi NCNICC-1:2025 at a glance People of Internet Research · Saudi Arabia 65 Controls for large entities 26 Controls for SMEs 6 Minimum covered employees peopleofinternet.com

Key Takeaways

Saudi Arabia's National Cybersecurity Authority (NCA) is hosting the Global Cybersecurity Forum (GCF) Annual Meeting in Riyadh on 7-8 October 2026. The theme, per search listings I could not confirm on the GCF's own event page, is 'Institutionalizing Adaptive Collaborations in Cyberspace'. The theme suggests a shift from agenda-setting toward standing cooperation. The more consequential story is domestic. The NCA has extended mandatory controls to a very large population of ordinary private firms.

What the NCA actually adopted

On 28 December 2025 the NCA adopted the Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC-1:2025), according to the Digital Policy Alert record of the measure. The framework covers private entities that do not own, operate or host critical national infrastructure (CNI). Those operators were already under the NCA's Essential Cybersecurity Controls.

The framework has two tiers, as summarised by CMS and Baker McKenzie:

CMS describes the controls as legally mandatory for both categories. Baker McKenzie notes that the framework applies to entities 'as notified by the Authority', so the NCA retains discretion over classification and can add requirements for higher-risk sectors. Neither summary specified transition periods or penalties. I could not read the NCA's own Arabic PDF in full, so the compliance timetable remains unverified.

The strongest case for the NCA

The case for this approach deserves a fair hearing. Attackers rarely target a nation's critical infrastructure directly. They go through the smaller suppliers, managed-service providers and subcontractors that connect to it. A control regime that stops at the CNI boundary leaves the most common entry points unprotected. A baseline also gives small firms something they usually lack, a checklist that a customer or insurer will recognise. A tiered design, with fewer controls for smaller firms, is a sensible attempt at proportionality. The NCA's approach is more thoughtful than a flat mandate that treats a six-person agency like a bank.

Where proportionality gets tested

Even so, a floor of six employees is low. A firm that size typically has no security staff. Twenty-six essential controls still mean asset inventories, access management, vulnerability handling and incident response, and a small firm will probably buy those as consulting or managed services. The compliance cost is real, and it falls on the smallest firms hardest. Saudi Arabia is trying to grow its private digital sector, and a compliance floor that is expensive for startups works against that goal.

Three design questions will decide whether the regime helps or hurts:

  1. Notification and clarity. If the NCA decides case by case who is covered, firms need prompt notice and a clear route to confirm their tier. Uncertainty is itself a cost, and it falls on firms with no in-house counsel.
  2. Outcome over paperwork. Controls that are measured by evidence of reduced incidents will do more than controls measured by documents. The risk of any mandatory checklist is that firms optimise for the audit, not for resilience.
  3. Phased, supported enforcement. Published transition periods, templates and cheap assessment tools matter more for six-person firms than for large ones. Penalties applied before capacity exists teach firms to avoid scrutiny.

The cloud and third-party component also needs care. If vendor-vetting requirements push small firms toward a narrow set of pre-approved providers, the market for local and open-source tooling shrinks. Technology-neutral requirements keep that market open.

What the forum can and cannot add

The GCF's stated aim of 'institutionalizing' collaboration is a fair ambition. Cyber incidents cross borders, and informal conferences produce communiqués more reliably than shared practice. The Riyadh meeting would be more credible if it published how Saudi controls compare with other regimes, and how firms that comply with international standards can show equivalence. Mutual recognition of baselines would cut duplicated audits for companies that operate in several markets. Whether the forum delivers that is unknown. Programme details for the 2026 meeting were not available to me when I checked, so any claims about its outcomes are premature.

The NCA is not wrong to extend baseline security to the wider economy. The open question is whether it does so in a way that small firms can sustain. The tiering is a good start. The NCA should publish its notification process, transition timelines and any penalty schedule so that six-person firms can plan. It should also measure results in incidents prevented, not in checklists completed. If it does, the extension of controls will make the Saudi digital economy more resilient. If it does not, it risks teaching small firms that compliance and security are two different activities.

Sources & Citations

  1. NCA: NCNICC-1:2025 controls (Arabic PDF)
  2. Baker McKenzie: Saudi Arabia cybersecurity controls for private entities (NCNICC-1:2025)
  3. Digital Policy Alert: NCNICC-1:2025 adoption record
  4. CMS: new cybersecurity controls for the private sector
  5. Baker McKenzie: Saudi cybersecurity controls for private entities