If your Saudi company employs between 6 and 249 people, or turns over between SAR 3 million and SAR 200 million, NCNICC-1:2025 classifies you as a small or medium entity. That means 26 mandatory controls rather than the full 65, and they are not spread evenly across the framework.
This is a walkthrough of what those 26 actually ask for, what evidence satisfies each area, and the order to tackle them in.
01
Why the SME set looks the way it does
NCNICC-1:2025 organises into three components: Cybersecurity Governance, Cybersecurity Defence, and Third-Party and Cloud Computing Cybersecurity. Large entities implement all 22 sub-components. SMEs implement 13, and the mandatory controls are concentrated almost entirely in Cybersecurity Defence.
The logic is sound. A 40-person company does not have an internal audit function, a risk committee, or a dedicated CISO, and the NCA has not pretended otherwise. What it does have is laptops, email, a cloud tenancy and remote access, and those are where incidents actually begin. The remaining controls are marked recommended rather than mandatory, which means they are the roadmap for after you have closed the essentials.
Practically: if you are an SME, your compliance programme is a technical hardening programme with a governance wrapper, not a documentation project.
02
The mandatory areas, and the evidence each needs
Access control and multi-factor authentication
Multi-factor authentication on remote access is explicitly required, and this is the single most common gap. It applies to staff reaching systems from outside the office, not only to administrators.
Evidence that satisfies a review: your identity provider's configuration showing enforcement, a report of accounts in scope, and confirmation there is no bypass path. An MFA policy document proves nothing on its own. Screenshots of enforcement do.
Asset management
You cannot secure what you have not enumerated. Expect to show a maintained inventory of hardware, software and cloud services, with an owner for each.
Evidence: the inventory itself, and something that demonstrates it is maintained rather than written once. A dated review, or an automated feed from your endpoint tooling.
Endpoint and network hardening
Baseline configurations, endpoint protection deployed across the estate, and network segmentation appropriate to your size.
Evidence: the baseline standard, and coverage reporting that shows what percentage of assets actually conform. Coverage gaps are what reviewers look for.
Vulnerability management and penetration testing
Both are named in the framework. Scanning on a defined cycle, penetration testing that produces a report, and remediation tracked to closure with dates.
Evidence: scan output over time showing the trend, the most recent test report, and a remediation log. A single clean scan is weaker evidence than a documented cycle with findings being closed.
Event logging and monitoring
Logs generated, retained, and reviewed. For most SMEs the practical question is who watches them outside working hours. Where monitoring is outsourced, the arrangement may need to involve an NCA-licensed provider, so check the licensing position of any partner before signing.
Evidence: log sources in scope, retention configuration, and evidence of review or escalation. If you use a managed service, the contract and the provider's licensing status.
Backup and recovery
Backups that exist, are protected from the thing that would destroy the originals, and have been restored at least once.
Evidence: backup configuration, and a restore test with a date and an outcome. Untested backups are treated as absent, and reasonably so.
Email security and Haseen
Alignment with the NCA's Haseen platform. This is Saudi-specific and has no counterpart in ISO 27001 or NIST CSF, which is why organisations that adopted an international framework first almost always miss it.
Evidence: your email authentication records and your Haseen alignment status.
Cryptographic standards
Alignment with the National Cryptographic Standards. Strong encryption is not automatically compliant encryption; the standards specify what is acceptable in the Kingdom.
Evidence: where encryption is applied, and the algorithms and key management in use.
Incident response
A plan that names people, not roles in the abstract, and that has been exercised.
Evidence: the plan, and a record of a tabletop or a real incident with what was learned.
Physical security
Controls over the environments holding your systems, including any comms room or on-premises equipment.
Evidence: access control records and a description of the arrangements.
Third party and cloud
Contracts that address security, and cloud services configured deliberately rather than by default.
Evidence: vendor contract clauses, and configuration evidence for your main cloud tenancy.
The governance minimum
Even in the reduced SME set there is a governance floor: approved policy, assigned responsibility, and staff awareness.
Evidence: the approved policy with a date and an approver, a named owner for cybersecurity, and awareness completion records.
03
A sensible order
MFA on all remote access. Highest risk reduction per hour spent, and the most likely single finding.
Backup, and a restore test. The control that decides whether a ransomware incident is a bad week or an extinction event.
Asset inventory. Everything downstream depends on knowing the estate.
Endpoint coverage and patching cadence.
Logging and monitoring, including the decision about who watches out of hours.
Email and Haseen alignment, plus cryptographic standards.
Policy, ownership and awareness, the governance floor.
Third
party and cloud**, then incident response exercising.
04
On timing
No compliance deadline for NCNICC-1:2025 has been publicly announced. The controls are mandatory now, the NCA can conduct unannounced reviews, and the penalty ceiling of SAR 25 million is already in force. The absence of a date is not an extension, it is the absence of the thing most organisations would have used to schedule the work.
05
Where to start
Score yourself against the SME control set before committing budget. That tells you which of the 26 are genuinely open, which are partially met, and where the evidence gaps are.
Our free assessment tools do this and email you the breakdown. If you would rather work through it with someone, Allo Technologies runs NCNICC and ECC readiness assessments for Saudi organisations and produces the prioritised remediation plan and evidence register.
06
References
National Cybersecurity Authority. Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (NCNICC-1:2025), published January 2026. National Cybersecurity Authority. Essential Cybersecurity Controls (ECC-2:2024). National Cybersecurity Authority. Haseen platform.
Need Expert Guidance?
Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.
Schedule a ConsultationAllo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.
Share this article
Related Reading
More insights from the Allo Technologies practice
NCA ECC or NCNICC: Which Framework Applies to You
Most Saudi private companies are being told to comply with the wrong NCA framework. ECC-2:2024 is for government and CNI; NCNICC-1:2025 is for everyone else.
Read moreNIST CSF 2.0 Mapped to NCA Requirements
Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.
Read moreSAMA vs. NCA: Navigating Saudi Cyber Compliance
Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.
Read moreTalk to an Expert
Get personalized guidance from our senior security and compliance practitioners