Back to Insights
Compliance

NCNICC-1:2025: The 26 Controls Saudi SMBs Must Meet

NCNICC-1:2025 makes 26 controls mandatory for Saudi SMEs of 6 to 249 staff. What each requires, the evidence a review expects, and a sensible order to close them.

By Al Rashdan
6 min read
#NCNICC-1:2025#NCNICC SME controls#Saudi SMB cybersecurity#NCA compliance#Haseen email security

If your Saudi company employs between 6 and 249 people, or turns over between SAR 3 million and SAR 200 million, NCNICC-1:2025 classifies you as a small or medium entity. That means 26 mandatory controls rather than the full 65, and they are not spread evenly across the framework.

This is a walkthrough of what those 26 actually ask for, what evidence satisfies each area, and the order to tackle them in.

01

Why the SME set looks the way it does

NCNICC-1:2025 organises into three components: Cybersecurity Governance, Cybersecurity Defence, and Third-Party and Cloud Computing Cybersecurity. Large entities implement all 22 sub-components. SMEs implement 13, and the mandatory controls are concentrated almost entirely in Cybersecurity Defence.

The logic is sound. A 40-person company does not have an internal audit function, a risk committee, or a dedicated CISO, and the NCA has not pretended otherwise. What it does have is laptops, email, a cloud tenancy and remote access, and those are where incidents actually begin. The remaining controls are marked recommended rather than mandatory, which means they are the roadmap for after you have closed the essentials.

Practically: if you are an SME, your compliance programme is a technical hardening programme with a governance wrapper, not a documentation project.

02

The mandatory areas, and the evidence each needs

01

Access control and multi-factor authentication

Multi-factor authentication on remote access is explicitly required, and this is the single most common gap. It applies to staff reaching systems from outside the office, not only to administrators.

Evidence that satisfies a review: your identity provider's configuration showing enforcement, a report of accounts in scope, and confirmation there is no bypass path. An MFA policy document proves nothing on its own. Screenshots of enforcement do.

02

Asset management

You cannot secure what you have not enumerated. Expect to show a maintained inventory of hardware, software and cloud services, with an owner for each.

Evidence: the inventory itself, and something that demonstrates it is maintained rather than written once. A dated review, or an automated feed from your endpoint tooling.

03

Endpoint and network hardening

Baseline configurations, endpoint protection deployed across the estate, and network segmentation appropriate to your size.

Evidence: the baseline standard, and coverage reporting that shows what percentage of assets actually conform. Coverage gaps are what reviewers look for.

04

Vulnerability management and penetration testing

Both are named in the framework. Scanning on a defined cycle, penetration testing that produces a report, and remediation tracked to closure with dates.

Evidence: scan output over time showing the trend, the most recent test report, and a remediation log. A single clean scan is weaker evidence than a documented cycle with findings being closed.

05

Event logging and monitoring

Logs generated, retained, and reviewed. For most SMEs the practical question is who watches them outside working hours. Where monitoring is outsourced, the arrangement may need to involve an NCA-licensed provider, so check the licensing position of any partner before signing.

Evidence: log sources in scope, retention configuration, and evidence of review or escalation. If you use a managed service, the contract and the provider's licensing status.

06

Backup and recovery

Backups that exist, are protected from the thing that would destroy the originals, and have been restored at least once.

Evidence: backup configuration, and a restore test with a date and an outcome. Untested backups are treated as absent, and reasonably so.

07

Email security and Haseen

Alignment with the NCA's Haseen platform. This is Saudi-specific and has no counterpart in ISO 27001 or NIST CSF, which is why organisations that adopted an international framework first almost always miss it.

Evidence: your email authentication records and your Haseen alignment status.

08

Cryptographic standards

Alignment with the National Cryptographic Standards. Strong encryption is not automatically compliant encryption; the standards specify what is acceptable in the Kingdom.

Evidence: where encryption is applied, and the algorithms and key management in use.

09

Incident response

A plan that names people, not roles in the abstract, and that has been exercised.

Evidence: the plan, and a record of a tabletop or a real incident with what was learned.

10

Physical security

Controls over the environments holding your systems, including any comms room or on-premises equipment.

Evidence: access control records and a description of the arrangements.

11

Third party and cloud

Contracts that address security, and cloud services configured deliberately rather than by default.

Evidence: vendor contract clauses, and configuration evidence for your main cloud tenancy.

12

The governance minimum

Even in the reduced SME set there is a governance floor: approved policy, assigned responsibility, and staff awareness.

Evidence: the approved policy with a date and an approver, a named owner for cybersecurity, and awareness completion records.

03

A sensible order

Sequence by how much risk each item removes for the effort, not by the order they appear in the framework.
1

MFA on all remote access. Highest risk reduction per hour spent, and the most likely single finding.

2

Backup, and a restore test. The control that decides whether a ransomware incident is a bad week or an extinction event.

3

Asset inventory. Everything downstream depends on knowing the estate.

4

Endpoint coverage and patching cadence.

5

Logging and monitoring, including the decision about who watches out of hours.

6

Email and Haseen alignment, plus cryptographic standards.

7

Policy, ownership and awareness, the governance floor.

8

Third

party and cloud**, then incident response exercising.

04

On timing

No compliance deadline for NCNICC-1:2025 has been publicly announced. The controls are mandatory now, the NCA can conduct unannounced reviews, and the penalty ceiling of SAR 25 million is already in force. The absence of a date is not an extension, it is the absence of the thing most organisations would have used to schedule the work.

05

Where to start

Score yourself against the SME control set before committing budget. That tells you which of the 26 are genuinely open, which are partially met, and where the evidence gaps are.

Our free assessment tools do this and email you the breakdown. If you would rather work through it with someone, Allo Technologies runs NCNICC and ECC readiness assessments for Saudi organisations and produces the prioritised remediation plan and evidence register.

06

References

National Cybersecurity Authority. Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (NCNICC-1:2025), published January 2026. National Cybersecurity Authority. Essential Cybersecurity Controls (ECC-2:2024). National Cybersecurity Authority. Haseen platform.

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Share this article

Related Reading

More insights from the Allo Technologies practice

Compliance

NCA ECC or NCNICC: Which Framework Applies to You

Most Saudi private companies are being told to comply with the wrong NCA framework. ECC-2:2024 is for government and CNI; NCNICC-1:2025 is for everyone else.

Read more
Compliance

NIST CSF 2.0 Mapped to NCA Requirements

Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.

Read more
Compliance

SAMA vs. NCA: Navigating Saudi Cyber Compliance

Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%