Do Saudi Arabia's NCNICC cybersecurity controls apply to you? Find your category and what's required

If you run a private-sector organization in the Kingdom with 6 to 249 employees (or annual revenue between SAR 3 million and SAR 200 million), your organization is most likely Category (B) — and the NCNICC-1:2025 controls issued by the National Cybersecurity Authority (NCA) apply to you. This page explains, plainly and without jargon: what these controls are, how to find your category, and what is actually required of you as a small or medium organization.

What are the NCNICC-1:2025 controls?

They are the Cybersecurity Controls for Non-Critical-Infrastructure Private Sector Organizations, issued by the National Cybersecurity Authority to set a minimum baseline of cybersecurity requirements for organizations — small, medium, and large. The controls are organized into three main components:

  • Cybersecurity Governance — structure, policies, risk management, and awareness.
  • Cybersecurity Defense — the practical protection of systems, data, devices, and networks.
  • Third-Party and Cloud Cybersecurity — protecting what you share with service providers and cloud hosting.

Why did the NCA issue them?

Saudi Vision 2030 ties the economy's growth to a strong, secure private sector and a larger contribution from small and medium organizations to GDP. Because that growth depends on a trustworthy digital space, the NCNICC controls raise the minimum level of protection across private-sector organizations. Compliance here is not a regulatory burden — it is a contribution each of us makes, from our own position, to protecting our organization and our country.

How to find your category: (A) or (B)?

The Authority divides organizations into two categories by size, following the definitions of the General Authority for Small and Medium Enterprises (Monsha'at):

Category Organization size Mandatory controls
Category (A) — Large organizations More than 250 full-time employees, or annual revenue above SAR 200 million 3 main components · 22 sub-components · 65 controls
Category (B) — Small & medium 6 to 249 full-time employees, or annual revenue between SAR 3 million and SAR 200 million 1 main component · 13 sub-components · 26 controls

Put simply: count your full-time employees. If the number is between 6 and 249, you are Category (B) — the category SecurityRelief was built specifically to serve.

What do Category (B) controls cover in practice?

Category (B) controls are not complex requirements — they focus on the fundamentals that genuinely protect your organization. Among the most important things the Authority requires of you:

  • Asset management — an accurate, up-to-date inventory of your devices, systems, and information.
  • Identity and access management — including multi-factor authentication (MFA) for remote access (email and external applications), and the principle of least privilege.
  • Protection of systems, devices, and email from malware and intrusion.
  • Network security management, data protection, and encryption.
  • Regular backups, and vulnerability and patch management.
  • An awareness and training program for staff on threats such as phishing, ransomware, and strong passwords.
  • Third-party and cloud security for whatever you host or share outside the organization.

See the full Category (B) controls checklist →

What "mandatory" vs "recommended" means for you

The Authority distinguishes between a mandatory control (which your category must apply) and a recommended one (which is encouraged). For Category (B), the mandatory scope concentrates on practical defense and awareness — identity and asset management, device and email protection, and staff awareness — while some of the heavier governance items (such as establishing a dedicated cybersecurity unit) are recommended, not mandatory. That means your starting point is simpler than you might expect.

What should you do now?

  1. Find your category — count your employees and annual revenue, and determine whether you are (A) or (B).
  2. Assess your current state against your category's controls, so you know where you stand and where the gaps are.
  3. Close the gaps by priority, starting with the mandatory controls.

How to know where you stand today

The most practical step is to measure where you are right now. We built a free 8-minute assessment for exactly this: it measures your organization's readiness against the Category (B) controls and gives you an instant report showing where you stand and where the gaps are — no technical expertise needed, and without your data being shared.

Start by learning your compliance score — free

A free assessment mapped to the Category (B) controls, with an instant report showing where you stand and where the gaps are.

Assess your organization's compliance now (8 minutes)
The first 50 organizations to register receive an exclusive discount at platform launch.

Frequently asked questions

Are the NCNICC controls mandatory?

Yes. Category (B) controls are mandatory for small and medium organizations that the Authority notifies, and Category (A) controls are mandatory for large organizations.

Which category applies to my small business?

If you have between 6 and 249 full-time employees, or annual revenue between SAR 3 million and SAR 200 million, you are Category (B).

How many controls does Category (B) require?

26 controls, distributed across 13 sub-components, within a single main component.

Do I need a technical expert to get started?

Not to start. You can find out where you stand with SecurityRelief's free 8-minute assessment, then decide your next steps.

Source for the categories, control counts, and the "mandatory/recommended" classification: the National Cybersecurity Authority's NCNICC-1:2025 document (document classification: public).