Banks, insurers, and licensed fintechs in Saudi Arabia answer to two regulators on cybersecurity: SAMA (Cybersecurity Framework v1.0) and the NCA (ECC 2:2024). The frameworks overlap heavily but are not identical. A single integrated control set, mapped once, can satisfy both.
01
Origins and intent
- SAMA CSF, issued 2017, mandatory for all SAMA-regulated entities. Maturity-based (levels 1–5).
- NCA ECC 2:2024, issued 2018, refreshed 2024. Compliance-based (implemented or not).
02
Structural comparison
| Dimension | SAMA CSF | NCA ECC 2:2024 |
|---|---|---|
| Domains | 4 (Leadership, Risk, Operations, Third-Party) | 4 (Governance, Defence, Resilience, Third-Party/Cloud) |
| Subdomains | 30+ | 29 |
| Assessment model | Maturity 1–5 | Implemented / Not Implemented |
| Self-assessment cadence | Annual to SAMA | Annual internal, periodic NCA review |
| Audit model | Independent assurance | Internal + external + NCA review |
Dimension
Domains
SAMA CSF
4 (Leadership, Risk, Operations, Third-Party)
NCA ECC 2:2024
4 (Governance, Defence, Resilience, Third-Party/Cloud)
Dimension
Subdomains
SAMA CSF
30+
NCA ECC 2:2024
29
Dimension
Assessment model
SAMA CSF
Maturity 1–5
NCA ECC 2:2024
Implemented / Not Implemented
Dimension
Self-assessment cadence
SAMA CSF
Annual to SAMA
NCA ECC 2:2024
Annual internal, periodic NCA review
Dimension
Audit model
SAMA CSF
Independent assurance
NCA ECC 2:2024
Internal + external + NCA review
03
Where they align
Roughly 80% of controls overlap in spirit. Both require: board accountability, risk methodology, asset inventory, IAM with MFA, vulnerability and patch management, SOC monitoring, incident response, DR, and third-party assurance.
04
Where they diverge
Maturity expectation**, SAMA expects level 3 minimum (defined and measured). NCA expects implementation, not maturity.
Cybersecurity insurance**
Customer protection**
Cloud**
05
The dual-compliance playbook
Adopt one control library
typically NCA ECC plus SAMA-specific deltas.
Map every control to both frameworks in a single GRC tool.
Set the higher bar as the target
usually SAMA maturity level 3.
Run one annual self-assessment producing two regulator-ready reports.
Plan one external assurance per year covering both scopes.
06
Common audit gaps
Risk methodology exists but ratings are inconsistent across business units.
SIEM coverage stops at perimeter; cloud and SaaS not fully ingested.
Third-party risk programme covers IT vendors but misses fintech partners.
Incident response tested only at the SOC tier
Need Expert Guidance?
Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.
Schedule a ConsultationAllo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.
Frequently asked questions
Find answers to common questions about our services
Share this article
Related Reading
More insights from the Allo Technologies practice
SAMA vs. NCA: Navigating Saudi Cyber Compliance
Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.
Read moreNIST CSF 2.0 Mapped to NCA Requirements
Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.
Read moreWhich NCA Framework Applies to You: The Complete Map
The NCA publishes at least eight sets of controls. Most organisations need one or two. A decision path for ruling out the rest quickly.
Read moreTalk to an Expert
Get personalized guidance from our senior security and compliance practitioners