CYBER · PRIVACY · DIGITAL TRUSTPowered by Falconry360 Book a working session

Home/Markets/Saudi Arabia

Market pack

Saudi Arabia

The most prescriptive control environment in the region, and the one where control-by-control evidence is expected rather than requested. Also the market where hosting location is a gating question, not a technical detail.

PRIMARY AUTHORITIES
NCA, SAMA, SDAIA, CST
INSTRUMENTS IN THIS PACK
10 national and sector, plus 13 international standards
CONTRACTING
Registered Saudi entity. Kingdom clients contract in-Kingdom, with in-Kingdom hosting.

Regulatory register

What applies, to whom, and what the platform does about it. Indicative and maintained as the instruments change — applicability is confirmed per client during scoping.

Saudi Arabia — national and sector regulation
Authority or instrumentWhat it isWho it applies toWhat the platform does
National Cybersecurity AuthorityECC-2:2024 Essential Cybersecurity ControlsGovernment entities, CNI and organisations within NCA scopeFull domain and subdomain mapping, control ownership, compliance level tracking and evidence per control
National Cybersecurity AuthorityCSCC Critical Systems Cybersecurity ControlsOperators of designated critical systemsApplied as an overlay on the ECC baseline, with the additional controls tracked separately
National Cybersecurity AuthorityCCC Cloud Cybersecurity ControlsCloud service providers and cloud tenantsClassification-driven control set for both provider and tenant responsibilities
National Cybersecurity AuthorityDCC Data Cybersecurity Controls; TCC Telework ControlsOrganisations within NCA scopeData-lifecycle and remote-working controls mapped into the same library
National Cybersecurity AuthorityOTCC-1:2022 Operational Technology Cybersecurity ControlsIndustrial and utility operatorsOT control compliance and evidence, run alongside IEC 62443 where the client uses it
Saudi Central BankCyber Security Framework; Business Continuity Management Framework; IT Governance, outsourcing and cloud rulesBanks, insurers, finance companies and payment firmsMaturity-level tracking against the SAMA model, continuity programme evidence and outsourcing registers
SDAIAPersonal Data Protection Law, Implementing Regulations and Data Transfer RegulationsControllers and processors in the KingdomProcessing records, lawful basis, rights handling, transfer risk assessment and breach workflow
National Data Management OfficeData management and personal data protection standardsGovernment and government-related entitiesData governance controls mapped alongside the privacy pack
Communications, Space and Technology CommissionCloud Computing Regulatory Framework and sector rulesCloud providers and telecom operatorsSector obligations tracked in the same regulatory register
Capital Market AuthorityCybersecurity and technology requirements for market institutionsLicensed capital markets firmsFolded into the unified control set rather than run as a separate programme
International standards operating alongside the national regimes
StandardScopeHow it is used
ISO/IEC 27001:2022 and 27002Information security management system and control setCertification readiness, live Statement of Applicability, continuous gap position
ISO/IEC 27701Privacy information managementExtends the ISMS control set with privacy-specific controls and DPO workflow
ISO/IEC 27017 and 27018Cloud security and cloud personal dataApplied where the estate is cloud-hosted or cloud-delivered
ISO 22301Business continuity managementBIA, recovery objectives, plan currency and exercise evidence
ISO/IEC 42001:2023AI management systemAI inventory, impact assessment and model governance
NIST CSF 2.0Cybersecurity frameworkUsed as the neutral spine when several national regimes apply at once
NIST SP 800-53 Rev. 5Control catalogueDepth mapping where a client's control set is US-derived
CIS Controls v8Prioritised technical control setCommon baseline for technology teams
COBIT 2019Technology governanceUsed in the Govern pillar for IT and digital governance structures
SOC 2Service organisation controlsTrust services criteria for clients who serve enterprise customers
PCI DSS 4.0Payment card securityApplied where card data is in scope
IEC 62443Industrial automation and control systemsApplied to OT estates alongside the national OT controls
Open FAIRRisk quantification taxonomyThe quantification method used throughout the Anticipate pillar

Hosting and contracting

Settle residency before tenant design. It is the item most often left until too late.

Data residency

In-Kingdom hosting is the working assumption for regulated and government clients. Data classification under the NCA data controls and the National Data Management Office standards should be settled before tenant design, not after.

Contracting entity

Falconry holds a registered Saudi entity. Kingdom clients contract in-Kingdom. In-Kingdom hosting is the working assumption for regulated and government workloads, and data classification under the NCA data controls and the NDMO standards should be settled before tenant design.

How Falconry360 is hosted and secured

THE SAUDI PICTURE

The most prescriptive control environment in the region — and the one where evidence is expected, not requested.

Vision 2030 has made cyber a condition of participation rather than a maturity ambition. Organisations delivering giga-projects, entering regulated sectors or bidding into national programmes are assessed on control compliance before commercial terms are discussed.

What is different here

  • Control-by-control evidence. The NCA model expects demonstrated implementation per control, at a stated compliance level. An assertion of alignment is not a position; a populated evidence set is.
  • Two supervisors, minimum, for most regulated firms. NCA scope and a sector supervisor — SAMA for financial institutions, CMA for market participants, CST for telecom and cloud — each with its own cycle and its own reporting format.
  • Hosting is a gating question. In-Kingdom hosting is the working assumption for regulated and government workloads. Classification under the NCA data controls and the NDMO standards has to be settled before tenant design, not discovered during it.
  • Localisation extends to the supply chain. Major national operators run their own third-party cyber certification schemes. A supplier without one does not bid, which makes compliance a revenue question rather than a cost one.
  • Arabic matters. Regulatory correspondence, examination interaction and awareness content land differently when they are produced in Arabic by people who work in it daily.

What a first engagement usually looks like

Indicative. Scope, estate size and the number of regimes in play move the dates.

  • Weeks 1–3 · Perimeter

    Establish which NCA control set applies — ECC baseline, and whether CSCC, CCC, DCC, TCC or OTCC overlay it — alongside the sector supervisor's framework. Confirm data classification and the hosting position that follows from it.

  • Weeks 4–8 · Control library

    Normalise the control set so one control satisfies NCA and SAMA where the wording genuinely permits it, and flag where it does not. Populate asset and supplier masters from source systems rather than from a spreadsheet exercise.

  • Weeks 9–14 · Evidence and ownership

    Named owner against every control. Evidence routines scheduled from the systems that produce the evidence. Compliance level tracked per control rather than asserted at domain level.

  • Ongoing · Examination posture

    Regulatory change tracked and routed. Examination workspaces assembled to the supervisor's request structure. The position is current on any given day, not reconstructed before a visit.

Falconry holds a registered Saudi entity. Kingdom clients contract in-Kingdom, with in-Kingdom hosting and Arabic-capable delivery.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.