A guide to the private-sector cybersecurity controls (NCNICC) for small & medium organizations
Saudi Arabia's private-sector cybersecurity controls (NCNICC-1:2025), issued by the National Cybersecurity Authority, set the minimum protection requirements for private-sector organizations in the Kingdom. This SecurityRelief guide explains them for Category (B) small and medium organizations: who is in scope, the 26 controls they require, and how to measure your compliance — in practical terms, without jargon.
Do the NCNICC controls apply to you? Find your category ←
How to tell whether you're Category (A) or (B), and what's required of you.
The Category (B) controls checklist: what your organization needs ←
The 26 controls across 13 domains, in practical terms.
