October 1, 2026
The NCA's new cybersecurity controls reach private companies
For years, national cybersecurity controls were something banks and utilities worried about. NCNICC-1:2025 brings a baseline to any private company with six or more staff, and most of it lands on the software you already use.

Takeaway
NCNICC-1:2025 extends mandatory cybersecurity controls to private companies that are not critical infrastructure, from six employees upward. Here is what the controls mean for the POS, CRM, HR and ERP systems you run every day.
Until recently, Saudi Arabia's National Cybersecurity Authority (NCA) set binding controls mainly for government bodies and critical national infrastructure. With NCNICC-1:2025, the Cybersecurity Controls for Private Sector Entities not classified as critical infrastructure, that baseline now reaches ordinary private companies: restaurants and retail chains, clinics, logistics firms, distributors, agencies and software startups, from six full-time employees upward. Most of the controls are not about buying security products. They are about how your everyday business systems handle sign-in, access, logging, backups and vendors.
What happened
The NCA issued NCNICC-1:2025 to set minimum cybersecurity requirements for private-sector organisations outside critical infrastructure. The controls sort companies into two classes:
- Class A, large entities: more than 250 full-time employees, or annual revenue above SAR 200 million. All 65 main controls, across 22 sub-components, apply.
- Class B, small and medium entities: 6 to 249 full-time employees, or annual revenue between SAR 3 million and SAR 200 million. Twenty-six main controls are mandatory; the remaining controls are recommended.
The controls are grouped under three headings: governance, cybersecurity defence, and third-party and cloud cybersecurity. Law-firm summaries of the framework highlight requirements such as identity and access management, multi-factor authentication for remote access, event logging and monitoring, incident and threat management, backups, staff awareness, alignment with the National Cryptographic Standards, and cybersecurity terms in third-party contracts covering confidentiality and incident notification. For large entities, the governance controls include a cybersecurity function independent of IT, led by a suitably qualified Saudi national. The NCA keeps the authority to assess compliance and update the controls.
The summaries we reviewed do not give a single public compliance deadline, so check the NCA's current guidance for the date that applies to you rather than assuming you have time.
Why it matters for operators
For a typical Class B company, the controls read less like an IT project and more like a checklist for the systems the business already depends on. Take a 40-person restaurant group or distributor. Its sensitive data sits in a POS, a delivery-platform dashboard, a CRM or WhatsApp business account, an HR system with iqama copies and salaries, an accounting package, and a shared drive. The questions the controls ask are concrete:
- Who can sign in, and how? Shared logins on the POS back office or a single admin password for the HR system are the most common gap. Remote access is expected to use multi-factor authentication.
- Who can see what? Roles should limit a branch supervisor to their branch and keep salary data away from people who do not need it.
- What is recorded? If a price is changed, an employee record is exported or a refund is approved, the system should log who did it and when, and someone should review those logs.
- Can you recover? Backups need to exist, be tested, and not sit on the same account an attacker would compromise.
- What do your vendors promise? Your POS provider, cloud host and outsourced developer hold your data. Contracts should cover confidentiality and how quickly they tell you about an incident.
Off-the-shelf tools often support most of this, but switched off or on a higher plan. Custom systems built quickly for one branch often lack audit logs and role-based permissions entirely.
What to check in your systems
- Inventory: list every system that holds customer, employee or financial data, including the ones that "just" live in a spreadsheet or a phone.
- Sign-in: turn on multi-factor authentication for admin and remote access everywhere it is available, and remove shared accounts.
- Permissions: map roles to what each person actually needs, and remove access for people who have left on their last day.
- Audit logs: make sure sensitive actions such as exports, price and payroll changes, refunds and permission changes are logged and reviewed.
- Backups: confirm what is backed up, how often, where, and when you last restored something successfully.
- Vendors: collect your key providers' security terms, and add incident-notification and confidentiality clauses at renewal.
Cicada Solutions view
NCNICC-1:2025 is a sensible baseline, and much of it overlaps with what the Personal Data Protection Law already expects for personal data. The cheapest time to meet it is when you choose or build a system, not after. When we build operational software, role-based access, audit logging and clean data export are part of the first release, because adding them later means reworking every screen.
If you are a Class B company, start with the inventory and the sign-in, permissions and logging questions above; they cover a large share of the practical risk. Then classify yourself properly against the thresholds and read the controls that apply to you from the NCA directly. This is not legal or regulatory advice. Confirm your classification and obligations with the NCA or a qualified adviser. If you want help reviewing your POS, CRM or HR setup against these questions, talk to us.
Sources
- Baker McKenzie: Saudi Arabia, cybersecurity controls for private entities - published 2026-07-27, accessed 2026-10-01.
- CMS: Kingdom of Saudi Arabia issues new Cybersecurity Controls for the Private Sector - published 2026-03-27, accessed 2026-10-01.
- SDAIA: Laws and Regulations (Personal Data Protection Law) - accessed 2026-10-01.