HomeInsightsNCA, SAMA & PDPL: A Practical Compliance Guide for Saudi Organisations

Cybersecurity

NCA, SAMA & PDPL: A Practical Compliance Guide for Saudi Organisations

Updated 23 Jun 2026

Saudi Arabia's regulatory landscape for cybersecurity and data protection has matured quickly. For most organisations three names matter most: the NCA Essential Cybersecurity Controls (ECC), the SAMA Cyber Security Framework, and the Personal Data Protection Law (PDPL).

This guide is an overview for planning purposes, not legal advice. Your exact obligations depend on your sector, size and the data you handle.

NCA Essential Cybersecurity Controls (ECC)

The ECC is the National Cybersecurity Authority's baseline set of controls for protecting an organisation's information and technology assets, spanning governance, defence, resilience and third-party risk. The practical starting point is a gap assessment against the ECC domains, then prioritising the gaps that carry the most risk.

SAMA Cyber Security Framework

Entities regulated by the Saudi Central Bank (SAMA) must align to the SAMA Cyber Security Framework, which sets expectations for cyber governance, risk management and resilience appropriate to the sensitivity of financial data. It overlaps substantially with the ECC, so a single well-designed control programme can address both.

Personal Data Protection Law (PDPL)

The PDPL governs how personal data is collected, processed, stored and shared in the Kingdom. Compliance is as much about process and accountability — knowing what personal data you hold, why, and on what basis — as it is about technical controls.

A practical, risk-led approach

Trying to satisfy every requirement at once is the most common way programmes stall. A risk-led sequence works better:

  • Assess — map your current controls and data flows against the relevant framework.
  • Prioritise — rank gaps by risk, not by checklist order.
  • Remediate — close the highest-risk gaps first.
  • Monitor — put detection and reporting in place so you can demonstrate ongoing compliance.

Key takeaways

  • ECC, SAMA and PDPL overlap — one control programme can satisfy several requirements.
  • Start with a gap assessment and a prioritised roadmap.
  • Accountability and process matter as much as technology.

Our cybersecurity services follow exactly this sequence — assessment, prioritised roadmap, implementation and ongoing support.

FAQ

Frequently asked questions

Do all three frameworks apply to every organisation?
No. The ECC applies broadly, the SAMA framework applies to entities regulated by the Saudi Central Bank, and the PDPL applies wherever personal data is processed. Scope depends on your sector and data.
Where should we start?
With a gap assessment against the relevant framework, followed by a prioritised roadmap so you tackle the highest-risk gaps first.

Ready to discuss your project?

Talk to our engineers for a free, no-obligation assessment and a tailored proposal for your environment.