If you sell managed security operations centre services in Saudi Arabia, you need a licence from the National Cybersecurity Authority. If you buy them, you should be checking that your provider holds the right one.
This covers the two tiers, what separates them, and the confusion that causes most of the wasted effort: the licence and the control frameworks are different things.
01
The licence is not a control framework
The most common mistake, including among people who work in this field, is treating ECC-2:2024 as the qualifying framework for an MSOC licence. It is not.
Licensing is governed by the Regulatory Framework for Licensing the Provision of MSOC Services (RFMSOC). It sets out who may provide MSOC services, the tiers, and the minimum requirements a provider must meet. It has its own criteria, including staffing.
Your obligations as an organisation are separate. Whichever NCA control set applies to you by entity type, ECC-2:2024 if you are government or CNI, NCNICC-1:2025 if you are private sector and not CNI, still applies to you as a company. Being licensed does not discharge it. Being compliant does not license you.
Both matter, and they are assessed against different documents.
02
Tier 1 and Tier 2
The tiers are defined by who you are allowed to serve, not by service quality or capability.
Tier 1 permits the provision of MSOC services to all organisations, including government organisations and organisations that own, operate or host critical national infrastructure.
Tier 2 permits the provision of MSOC services to all organisations excluding government organisations and CNI operators.
Tier 1 is therefore a superset. A Tier 2 provider serving a purely commercial, non-CNI client base is operating exactly within its licence, and there is nothing second-rate about that. It simply cannot take on a government department or a CNI operator.
The NCA has published its Tier 1 licensees, which at time of writing include SITE, sirar by stc, Haboob, Cyberani by aramco digital, TCC and SAMI-AEC. That list is short, and it is worth understanding why: Tier 1 carries the government and CNI client base, and the bar reflects it.
03
What the requirements look like
RFMSOC sets minimum requirements for both tiers, detailed in its appendices. The one most often quoted, because it is the hardest to fake, is staffing: a minimum of five SOC Cybersecurity Defence Analysts at level III, who must pass a certification examination and hold a valid certification.
That is a meaningful bar for a small provider. Five certified level III analysts is most of a functioning 24x7 rota before you count leads, engineers or management, and it is the requirement that most often determines whether a firm applies for a licence or partners with someone who already holds one.
Read the framework itself rather than a summary, including this one. The detailed minimums are in the appendices and they are the part that decides an application.
04
The scope question that catches Tier 2 providers
A question worth getting right: does CCC-1:2020, the Cloud Cybersecurity Controls, apply to a Tier 2 MSOC provider delivering from cloud infrastructure?
CCC applies to Cloud Service Providers as well as Cloud Service Tenants, so the instinct that "CCC is a CNI framework" is not quite right. But the NCA explicitly excludes cloud service providers that serve only individuals or only non-CNI private-sector organisations.
A Tier 2 licence bars government and CNI clients by definition. So a Tier 2 provider's client base sits inside that exclusion, and CCC does not bite. The conclusion is the usual one, but the reason matters: it holds because of an express exclusion in CCC, not because CCC is only for CNI. If that provider later obtains Tier 1 and takes on a government tenant, the analysis changes.
DCC-1:2022 deserves a second look for the same reason. It is scoped by entity type: government organisations, private CNI operators, and consultancy firms working on high-sensitivity strategic projects. That last category is not about data classification obligations in general, and an advisory or managed services firm engaged on sensitive government programmes should test it properly rather than assume it is aimed elsewhere.
05
If you are buying, not selling
Three questions worth asking any provider, in this order:
- Which tier do you hold, and can you show it? If you are government or CNI, only Tier 1 will do. If you are neither, Tier 2 is entirely appropriate and often better value.
- Is the licence held by the entity that will actually deliver my service? Subcontracting and reseller arrangements are common. The licence needs to sit with whoever is doing the monitoring.
- Which control set applies to me, and how does your service evidence it? Monitoring is one control area. It should produce log source coverage, retention configuration and escalation records in a form your reviewer will accept.
A provider who answers these plainly is telling you something useful. So is one who does not.
06
How we work
Allo Technologies delivers managed detection and response together with an NCA-licensed MSOC partner rather than holding the licence ourselves. We say so directly because it is the first thing a buyer should establish, and because the alternative, being vague about it, tends to unravel at exactly the wrong moment.
If you are a provider weighing an application against a partnership, or a buyer trying to establish what you actually need, that is a conversation worth having properly.
07
References
National Cybersecurity Authority. Regulatory Framework for Licensing the Provision of Managed Security Operations Centre Services. National Cybersecurity Authority. National Policy for Managed Security Operations Centers. National Cybersecurity Authority. Cloud Cybersecurity Controls (CCC-1:2020). National Cybersecurity Authority. Data Cybersecurity Controls (DCC-1:2022). National Cybersecurity Authority. Essential Cybersecurity Controls (ECC-2:2024). National Cybersecurity Authority. Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (NCNICC-1:2025).
Need Expert Guidance?
Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.
Schedule a ConsultationAllo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.
Share this article
Related Reading
More insights from the Allo Technologies practice
NCNICC-1:2025: The 26 Controls Saudi SMBs Must Meet
If your Saudi company has 6 to 249 staff, NCNICC-1:2025 makes 26 controls mandatory. What each one asks for, the evidence that satisfies it, and the order to do them in.
Read moreNIST CSF 2.0 Mapped to NCA Requirements
Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.
Read moreSAMA vs. NCA: Navigating Saudi Cyber Compliance
Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.
Read moreTalk to an Expert
Get personalized guidance from our senior security and compliance practitioners