Back to Insights
Compliance

NCNICC-1:2025: The 26 Controls Saudi SMBs Must Meet

NCNICC-1:2025 Class B: 26 mandatory controls, all in Cybersecurity Defence. Which 13 sub-components apply, what each requires, and what is only recommended.

By Al Rashdan
8 min read
#NCNICC-1:2025#NCNICC SME controls#Saudi SMB cybersecurity#NCA compliance#Haseen email security

If the NCA has notified your company that NCNICC-1:2025 applies, and you employ between 6 and 249 people or turn over between SAR 3 million and SAR 200 million, you are Class B. That means 26 mandatory controls, and they are not spread across the framework the way most summaries suggest.

This is what the control document actually says, read directly rather than from commentary.

01

Class B is one component, not three

NCNICC-1:2025 has three main components: Cybersecurity Governance, Cybersecurity Defence, and Third-Party and Cloud Computing Cybersecurity. Twenty-two sub-components in total.

Class A entities (more than 250 staff, or revenue above SAR 200 million) implement all three components, all 22 sub-components, all 65 controls.

Class B implements one main component. In the NCA's own table: one main component, 13 sub-components, 26 essential controls. That component is Cybersecurity Defence.

Governance and Third-Party and Cloud are marked recommended for Class B, not mandatory. So is penetration testing, and so is web application protection. Those are the two Defence sub-components that fall outside the mandatory 13, which is how 15 becomes 13.

This matters because it inverts the usual compliance instinct. There is no mandatory policy set, no mandatory risk methodology, no mandatory internal audit, no mandatory awareness programme for a Class B entity. The NCA has not asked a 40-person company to build a governance function. It has asked it to have working technical controls.

02

The 13 mandatory sub-components

#

2-1

Sub-component

Asset management

#

2-2

Sub-component

Identity and access management

#

2-3

Sub-component

Systems and information processing device protection

#

2-4

Sub-component

Email protection

#

2-5

Sub-component

Network security management

#

2-6

Sub-component

Mobile device and BYOD security

#

2-7

Sub-component

Data and information protection

#

2-8

Sub-component

Cryptography

#

2-9

Sub-component

Backup management

#

2-10

Sub-component

Vulnerability management

#

2-12

Sub-component

Event logs and cybersecurity monitoring

#

2-13

Sub-component

Cybersecurity incident and threat management

#

2-14

Sub-component

Physical security

Not mandatory for Class B: 2-11 penetration testing, 2-15 web application protection, and all of components 1 and 3.

03

What each one actually asks for

Identity and access (2-2). Multi-factor authentication is explicitly required for remote access, and the control names email and external applications specifically. Also mandatory: secure username and password management, authorisation built on need-to-know, least privilege and segregation of duties, and periodic review of access rights. Privileged access management is recommended rather than mandatory at Class B.

Systems protection (2-3). Anti-malware across servers, user devices and mobile. Changing default settings, which the control spells out as disabling unnecessary services, changing default passwords, and restricting removable media. And central clock synchronisation from an accurate trusted source, with the NCA pointing at SASO as an example. That last one surprises people, but without synchronised time your logs cannot be correlated.

Email (2-4). Filtering for phishing and spam, and documenting your email domain through the Haseen platform using SPF, DKIM and DMARC. This is named in the control text. It has no equivalent in ISO 27001 or NIST CSF, so an organisation that adopted an international framework first will not have it. Advanced persistent threat protection is recommended, not mandatory, at Class B.

Network (2-5). Firewalls and secure access gateways, and wireless network security using secure authentication and encryption. Segmentation, browsing restrictions, port and protocol control, intrusion prevention and DDoS protection are all recommended at Class B.

Mobile and BYOD (2-6). If you allow personal devices onto the network, the requirements have to be defined, documented, approved and applied.

Data (2-7). Printer, scanner and copier security, and secure disposal and reuse of assets including paper and storage media. Data leakage prevention and brand protection are recommended, not mandatory.

Cryptography (2-8). Encryption of data at rest and in transit is mandatory. Alignment with the National Cryptographic Standards at basic level is recommended for Class B and mandatory for Class A. Worth knowing which side of that line you sit on before you spend money.

Backup (2-9). Periodic backup of sensitive business systems, and periodic testing that restoration actually works. Both mandatory. An untested backup does not satisfy this.

Vulnerabilities (2-10). Patch management, vulnerability scanning of external-facing applications, and remediation prioritised by classification including testing fixes before deployment. Periodic scanning of all assets is recommended rather than mandatory at Class B.

Logging and monitoring (2-12). Enabling cybersecurity event logs on sensitive information assets is mandatory. Subscribing to an NCA-licensed managed SOC provider is mandatory for Class A and recommended for Class B. If you are Class A, that is not a build-or-buy decision, the licence sits with the provider.

Incidents (2-13). Two obligations that apply to both classes and that many organisations miss: reporting cybersecurity incidents to the NCA, and sharing cybersecurity information with the NCA. Detailed response plans and escalation are recommended at Class B, but the reporting duty is not.

Physical (2-14). Protecting physical access to IT rooms and sensitive electronic equipment, and protecting CCTV records.

04

On scope and timing, precisely

Two points are worth taking directly from the document, because summaries tend to compress them.

The controls apply to entities the NCA notifies. The document says they apply to non-CNI private entities in the Kingdom that are circulated to by the Authority, and that Class A and Class B controls are binding on entities that are notified by the Authority. The NCA can also impose additional controls where it decides they are needed. Organisations outside scope are told they are responsible for benefiting from the controls as appropriate. So the trigger is notification by the Authority rather than publication date. Establishing whether you have been notified is the first question to settle.

Micro entities are out. The document's definition of "entity" excludes micro enterprises, non-governmental organisations, the government sector and critical national infrastructure. That is why the Class B band starts at 6 employees.

No deadline is published in the document, and the document itself sets out no penalty schedule. It states that compliance will be assessed by the Authority through whatever mechanism it deems appropriate, under Article 10(3) of the NCA's statute. Separately, the NCA holds general enforcement powers under Royal Decree M/117 of 22 December 2024, including fines of up to SAR 25 million, but those are the Authority's general powers rather than something NCNICC itself specifies.

05

A sensible order

Sequence by risk removed per hour spent, not by control number.
1

MFA on every remote access path. Named explicitly, and the most common finding anywhere.

2

Backup, and a tested restore. Both mandatory, and the second is what decides whether an incident is a bad week.

3

Asset inventory. Everything else depends on knowing the estate.

4

Anti-malware coverage, default-setting hardening, patching.

5

Haseen with SPF, DKIM and DMARC. Saudi-specific, quick, and invisible to international frameworks.

6

Logging on sensitive assets, and a decision about monitoring.

7

Incident reporting path to the NCA, agreed before you need it.

8

Physical access and CCTV, then mobile and BYOD.

06

Where to start

Score yourself against the Class B set before committing budget. Our free assessment tools do this and email you the breakdown. If you are unsure whether NCNICC or ECC applies to you at all, start with the framework map.

07

References

National Cybersecurity Authority. Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC-1:2025), Arabic edition, document classification: public. Tables 1, 2, 3 and 5, and the control tables for components 1, 2 and 3. National Cybersecurity Authority. Essential Cybersecurity Controls (ECC-2:2024). Royal Decree M/117, 22 December 2024, legal powers of the National Cybersecurity Authority.

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Frequently asked questions

Find answers to common questions about our services

Share this article

Stay up to date

Get notified when new compliance guides and cybersecurity articles are published.

By submitting, you consent to Allo Technologies using these details to email you when a new guide is published, after you confirm your address. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

Related Reading

More insights from the Allo Technologies practice

Compliance

NIST CSF 2.0 Mapped to NCA Requirements

Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.

Read more
Compliance

Which NCA Framework Applies to You: The Complete Map

The NCA publishes at least eight sets of controls. Most organisations need one or two. A decision path for ruling out the rest quickly.

Read more
Compliance

NCA ECC or NCNICC: Which Framework Applies to You

Most Saudi private companies are being told to comply with the wrong NCA framework. ECC-2:2024 is for government and CNI; NCNICC-1:2025 is for everyone else.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%