On 27 July 2026, Baker McKenzie published an analysis of the National Cybersecurity Authority's Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (NCNICC-1:2025). Secondary sources date the NCA's release to January 2026; we could not confirm that date against an NCA page. The analysis is a law-firm reading of an existing framework, not a new NCA issuance. It still matters because it shows how far Saudi cyber regulation now reaches into ordinary commercial life.
The strongest case for the framework
The argument for a private-sector baseline is serious. Until now, the NCA's flagship Essential Cybersecurity Controls (ECC-2:2024) applied to government bodies, their affiliates, and private entities that own, operate or host Critical National Infrastructure. Attackers do not respect that boundary. A logistics firm, a mid-sized software vendor or a payroll processor can be the soft entry point into a bank or a ministry. A floor of basic hygiene (access control, patching, email security, incident handling) across the wider economy is a reasonable answer, and a country building a digital economy has a legitimate interest in it.
What the framework does
According to Baker McKenzie, the controls apply directly to private companies outside critical infrastructure, and they are tiered by size:
- Large entities (more than 250 full-time staff or annual revenue above SAR 200 million) face 65 essential controls across 22 sub-components.
- SMEs (6-249 staff or SAR 3-200 million in revenue) face 26 essential controls across 13 sub-components, with some marked recommended rather than mandatory.
- Large entities must have their cybersecurity function and sensitive roles headed by Saudi nationals who are fully dedicated and appropriately qualified.
The tiering is the framework's best feature. Applying the same 65 controls to a six-person firm would be a tax on small business. Splitting the baseline so that small firms carry roughly 40% of the large-entity list is proportionate in design, and it is the right instinct. Law firm CMS's summary of the framework reaches the same thresholds and counts.
Where the process falls short
The gaps are procedural, and they carry real costs for firms.
First, there is no stated compliance deadline. Baker McKenzie notes that the framework applies to entities "as notified by the Authority," and that the NCA has not publicly confirmed any individual notifications. A firm that meets the size thresholds cannot tell whether it is in scope today, whether it will be in scope next year, or how long it will have to comply once notified. Businesses budget against dates. An open-ended obligation forces them either to spend now on a guess or to wait and risk a compressed timeline later. Baker McKenzie's advice is not to defer preparation pending notification, which is prudent but shifts the uncertainty onto companies.
Second, the Saudi-national leadership requirement is a real constraint. Localising security leadership has an obvious national-capacity rationale. But a dedicated, qualified head of cybersecurity is a scarce hire everywhere, and a rule that narrows the candidate pool for every large private firm can raise costs and slow hiring without improving security. That risk is highest for foreign-owned subsidiaries that currently share a regional security function. We would want the NCA to publish how it will assess "qualified" and how long firms will have to build a pipeline.
Third, we found no public enforcement or penalty detail in the analyses we reviewed. Baker McKenzie's alert did not describe enforcement mechanisms. Obligations without clear consequences or clear process are hard to plan around, and that helps neither regulators nor firms.
A useful comparison: standards over rigid mandates
The Electronic Frontier Foundation made a related point in September 2026 about US frontier-AI security rules. It argued that "legal standards tied to well-established cybersecurity best practices are far more likely to stand the test of time," and that regulation must be "careful, precise, and practical." The context is different, but the principle carries over. The NCA's approach of a defined control set, scaled by firm size, is a best-practice baseline rather than a technology-specific mandate. That is a strength, provided it is administered predictably.
What the NCA should do next
The fixes are inexpensive and do not weaken security:
- Publish a notification timetable, including how entities will be identified and a minimum lead time between notification and enforcement.
- Clarify the Saudi-leadership rule, including qualification criteria and a transition period.
- State enforcement and appeal procedures so that firms know what non-compliance costs.
- Keep the SME tier light, and resist expanding the mandatory list without evidence that specific controls reduce incidents.
Bottom line
Saudi Arabia has built a private-sector baseline that is, on paper, better proportioned than many. Its scaling by firm size is thoughtful and its content is conventional. What is missing is the scaffolding that turns a framework into something businesses can plan around: dates, notification and enforcement detail. A security regime earns compliance when firms can see what is required, by when, and why. Clarity on those points would let the NCA raise the security floor without slowing the businesses it depends on.