THE SAUDI PICTURE
The most prescriptive control environment in the region — and the one where evidence is expected, not requested.
Vision 2030 has made cyber a condition of participation rather than a maturity ambition. Organisations delivering giga-projects, entering regulated sectors or bidding into national programmes are assessed on control compliance before commercial terms are discussed.
What is different here
- Control-by-control evidence. The NCA model expects demonstrated implementation per control, at a stated compliance level. An assertion of alignment is not a position; a populated evidence set is.
- Two supervisors, minimum, for most regulated firms. NCA scope and a sector supervisor — SAMA for financial institutions, CMA for market participants, CST for telecom and cloud — each with its own cycle and its own reporting format.
- Hosting is a gating question. In-Kingdom hosting is the working assumption for regulated and government workloads. Classification under the NCA data controls and the NDMO standards has to be settled before tenant design, not discovered during it.
- Localisation extends to the supply chain. Major national operators run their own third-party cyber certification schemes. A supplier without one does not bid, which makes compliance a revenue question rather than a cost one.
- Arabic matters. Regulatory correspondence, examination interaction and awareness content land differently when they are produced in Arabic by people who work in it daily.