Insight · Cybersecurity Published: June 2026

NCA and SAMA compliance: what Saudi enterprises actually need to do

NCA and SAMA compliance: what Saudi enterprises actually need to do

Two regulators shape almost every security and cloud decision in Saudi Arabia: the National Cybersecurity Authority (NCA) and, for financial institutions, the Saudi Central Bank (SAMA). What each requires, how they fit together, and the practical steps to reach and prove compliance.

The NCA frameworks: ECC and CCC

Essential Cybersecurity Controls (ECC) are the NCA's baseline. They set the minimum cybersecurity requirements for in-scope national organisations across governance, defence, resilience, and third-party and cloud risk. If you operate critical or sensitive systems in the Kingdom, ECC is the floor — not the ceiling.

Cloud Cybersecurity Controls (CCC) extend the ECC specifically for the cloud. They define requirements for both cloud service providers and cloud tenants (your organisation, when you consume cloud), covering classification, data location, encryption, identity, monitoring, incident response, and exit. The CCC is why a lift-and-shift to the cloud in Saudi Arabia is never just a technical migration — the controls gate what can move, where it can be hosted, and how it must be protected. A compliant move usually pairs cloud migration with documented in-Kingdom hosting on Google Cloud.

Data residency is the control that catches teams out

Sensitive and government-classified data generally must be hosted inside the Kingdom, in accredited data centres, with no processing or transfer outside Saudi borders. Before you migrate a workload, you classify the data, confirm the hosting region and provider meet the controls, and document the decision. Getting this wrong is the most common reason a cloud project stalls in audit.

The SAMA Cybersecurity Framework (financial sector)

If you're a bank, insurer, fintech, or other SAMA-regulated entity, you also fall under the SAMA Cybersecurity Framework — a sector-specific, more prescriptive regime. Financial institutions typically must satisfy both NCA (ECC/CCC) and SAMA simultaneously, and SAMA adds stricter expectations in areas such as governance maturity, third-party risk, and prior approval for cloud hosting of financial data.

The practical takeaway: a fintech moving to the cloud in Saudi Arabia is solving for two overlapping frameworks at once. The fastest path is to map controls once, to a single evidence set, rather than running two parallel compliance programs.

How the frameworks fit together

FrameworkWho it applies toWhat it governs
NCA ECCIn-scope national organisationsBaseline cybersecurity controls (the minimum)
NCA CCCCloud providers and cloud tenantsCloud-specific controls, data location, exit
SAMA CSFSAMA-regulated financial entitiesSector framework — stricter, runs alongside NCA

A practical compliance path

  1. Classify your data and systems — you can't apply controls until you know what's sensitive and where it lives.
  2. Map controls once — to a single control set that satisfies ECC, CCC, and (if applicable) SAMA, so you collect evidence one time.
  3. Fix the gapsidentity and privileged access, network segmentation and WAF, endpoint protection, logging and monitoring, backup and ransomware recovery, and a tested incident-response plan.
  4. Choose compliant hosting — confirm region, residency, and provider controls before migrating anything.
  5. Operate and prove it — continuous monitoring, documented runbooks, and audit-ready evidence on demand.

How Apex Aether helps

Apex Aether is a Saudi-based team that designs, secures, documents, and hands over technology built to these controls — Saudi-led, no black boxes. We align delivery to NCA and SAMA standards and bring the platforms the controls call for:

  • Cloud & data residency — secure migration on Google Cloud with in-Kingdom hosting decisions documented.
  • Identity & privileged accessCyberArk-based privileged access and identity controls.
  • Network & perimeterFortinet next-gen firewall, Secure SD-WAN, and WAF.
  • EndpointKaspersky / EDR protection across servers, endpoints, and users.
  • Backup & resilienceVeeam backup, ransomware recovery, and tested DR.
  • Monitoring & operations — 24/7 monitoring and support, with everything documented and handed to your team.

Every engagement ends the way compliance auditors like: documented, validated, and owned by you. Scoping a migration or a compliance gap? Talk to an engineer →

Apex Aether
Apex Aether · Editorial Team
Engineered in Saudi Arabia. We build it, secure it, document it — your team owns it after.

Frequently asked questions

What is the NCA ECC?
The Essential Cybersecurity Controls are the NCA's minimum cybersecurity requirements for in-scope organisations in Saudi Arabia, spanning governance, defence, resilience, and third-party / cloud risk.
Who must comply with the Cloud Cybersecurity Controls (CCC)?
Both cloud service providers and cloud tenants — so if your organisation consumes cloud services in the Kingdom, the CCC applies to you, not just your provider.
Do financial institutions follow NCA or SAMA?
Both. SAMA-regulated entities must meet the SAMA Cybersecurity Framework and the relevant NCA controls; SAMA is generally more prescriptive and applies on top.
Does our data have to stay in Saudi Arabia?
Sensitive and government-classified data generally must be hosted in-Kingdom in accredited facilities. Classify data and confirm hosting before migrating.
Can Apex Aether help us reach compliance?
Yes — we assess gaps, implement the required controls with proven platforms, and hand over documented, audit-ready evidence, aligned to NCA and SAMA standards.

Let's build something your team will actually own.

Tell us what you're modernizing. We'll design, secure, document, and hand it over.

Talk to an engineer