Saudi Arabia Saudi NCA cybersecurity national policy

Saudi Arabia's Private-Sector Cyber Baseline Is Sensible in Design but Unfinished in Process

Baker McKenzie's July 2026 analysis of the NCA's NCNICC-1:2025 shows a tiered baseline for private firms, with no stated deadline and no confirmed notifications.

Saudi NCA Private-Sector Cyber Baseline People of Internet Research · Saudi Arabia 65 Controls for large entities Across 22 sub-components. 26 Controls for SMEs Across 13 sub-components; some rec… SAR 200M+ Large-entity revenue threshold Or more than 250 full-time staff. peopleofinternet.com
Saudi NCA Private-Sector Cyber Baselin… People of Internet Research · Saudi Arabia 65 Controls for large entities 26 Controls for SMEs SAR 200M+ Large-entity revenue threshold peopleofinternet.com

Key Takeaways

On 27 July 2026, Baker McKenzie published an analysis of the National Cybersecurity Authority's Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (NCNICC-1:2025). Secondary sources date the NCA's release to January 2026; we could not confirm that date against an NCA page. The analysis is a law-firm reading of an existing framework, not a new NCA issuance. It still matters because it shows how far Saudi cyber regulation now reaches into ordinary commercial life.

The strongest case for the framework

The argument for a private-sector baseline is serious. Until now, the NCA's flagship Essential Cybersecurity Controls (ECC-2:2024) applied to government bodies, their affiliates, and private entities that own, operate or host Critical National Infrastructure. Attackers do not respect that boundary. A logistics firm, a mid-sized software vendor or a payroll processor can be the soft entry point into a bank or a ministry. A floor of basic hygiene (access control, patching, email security, incident handling) across the wider economy is a reasonable answer, and a country building a digital economy has a legitimate interest in it.

What the framework does

According to Baker McKenzie, the controls apply directly to private companies outside critical infrastructure, and they are tiered by size:

The tiering is the framework's best feature. Applying the same 65 controls to a six-person firm would be a tax on small business. Splitting the baseline so that small firms carry roughly 40% of the large-entity list is proportionate in design, and it is the right instinct. Law firm CMS's summary of the framework reaches the same thresholds and counts.

Where the process falls short

The gaps are procedural, and they carry real costs for firms.

First, there is no stated compliance deadline. Baker McKenzie notes that the framework applies to entities "as notified by the Authority," and that the NCA has not publicly confirmed any individual notifications. A firm that meets the size thresholds cannot tell whether it is in scope today, whether it will be in scope next year, or how long it will have to comply once notified. Businesses budget against dates. An open-ended obligation forces them either to spend now on a guess or to wait and risk a compressed timeline later. Baker McKenzie's advice is not to defer preparation pending notification, which is prudent but shifts the uncertainty onto companies.

Second, the Saudi-national leadership requirement is a real constraint. Localising security leadership has an obvious national-capacity rationale. But a dedicated, qualified head of cybersecurity is a scarce hire everywhere, and a rule that narrows the candidate pool for every large private firm can raise costs and slow hiring without improving security. That risk is highest for foreign-owned subsidiaries that currently share a regional security function. We would want the NCA to publish how it will assess "qualified" and how long firms will have to build a pipeline.

Third, we found no public enforcement or penalty detail in the analyses we reviewed. Baker McKenzie's alert did not describe enforcement mechanisms. Obligations without clear consequences or clear process are hard to plan around, and that helps neither regulators nor firms.

A useful comparison: standards over rigid mandates

The Electronic Frontier Foundation made a related point in September 2026 about US frontier-AI security rules. It argued that "legal standards tied to well-established cybersecurity best practices are far more likely to stand the test of time," and that regulation must be "careful, precise, and practical." The context is different, but the principle carries over. The NCA's approach of a defined control set, scaled by firm size, is a best-practice baseline rather than a technology-specific mandate. That is a strength, provided it is administered predictably.

What the NCA should do next

The fixes are inexpensive and do not weaken security:

Bottom line

Saudi Arabia has built a private-sector baseline that is, on paper, better proportioned than many. Its scaling by firm size is thoughtful and its content is conventional. What is missing is the scaffolding that turns a framework into something businesses can plan around: dates, notification and enforcement detail. A security regime earns compliance when firms can see what is required, by when, and why. Clarity on those points would let the NCA raise the security floor without slowing the businesses it depends on.

Sources & Citations

  1. Baker McKenzie: Saudi Arabia Cybersecurity Controls for Private Entities (27 Jul 2026)
  2. Baker McKenzie Connect On Tech alert
  3. NCA: Essential Cybersecurity Controls (ECC-2:2024)
  4. NCA: Essential Cybersecurity Controls page
  5. CMS: Saudi Arabia issues new Cybersecurity Controls for the Private Sector
  6. EFF: Ground AI Cybersecurity Rules in Best Practices