Back to Insights
Compliance

SAMA vs. NCA: Navigating Saudi Cyber Compliance

SAMA CSF applies to financial institutions, NCA ECC to government and critical national infrastructure. How the two differ and where their evidence overlaps.

By Al Rashdan
5 min read
#SAMA CSF#NCA ECC#Saudi compliance#Cybersecurity regulation#Regulatory guidance

SAMA CSF and NCA ECC are Saudi Arabia's two prominent cybersecurity frameworks, and they differ in scope: SAMA CSF applies to financial institutions regulated by the Saudi Central Bank, while NCA ECC applies to government entities, public sector bodies, and critical national infrastructure operators. Organisations that fall under both, or are unsure which applies, need to treat compliance as a layered mandate rather than a single checkbox.

01

Understanding SAMA CSF

SAMA CSF is a prescriptive framework designed for entities regulated by SAMA, including banks, insurance companies, and fintechs. It is comprehensive, structured as principles, objectives and control considerations across four domains, reflecting the high-stakes nature of financial data. Non-compliance can result in significant penalties and operational disruptions, directly impacting financial stability and customer trust. The framework mandates rigorous security practices, from incident response to third-party risk management, due to the critical infrastructure financial institutions represent.

"For financial entities, SAMA CSF is not just a recommendation; it's the bedrock of operational integrity and customer trust." Financial institutions often require a deep dive into specific control implementations. Our SAMA compliance assessment can help identify gaps and provide a clear roadmap for achieving full adherence. This assessment is critical for understanding where your current security posture stands against SAMA's stringent requirements.

02

Deciphering NCA ECC 2:2024

NCA ECC 2:2024 is the foundational cybersecurity framework for Saudi government entities, public sector bodies and critical national infrastructure operators. Private sector entities that are not CNI are covered by NCNICC-1:2025, published in January 2026. With 108 controls spanning Cybersecurity Governance, Defense, Resilience, and Third-Party/Cloud Computing Cybersecurity, it sets a baseline for national cybersecurity posture. The 2024 update streamlined the framework, moving ICS/OT controls to a separate framework, making it more focused on traditional IT environments. Every organization must meet these controls to operate legally and securely within the Kingdom.

Failing to meet NCA ECC requirements can lead to operational disruption, reputational damage, and potential legal ramifications. It's not just about protecting your assets; it's about contributing to the Kingdom's overall cybersecurity resilience. Organizations should regularly conduct an NCA ECC gap assessment to ensure continuous compliance and adapt to evolving threats.

03

Overlap and Divergence: Where They Meet and Differ

While SAMA CSF and NCA ECC share common objectives, protecting information assets and ensuring business continuity, their approaches and specificity differ. NCA ECC provides essential, broad controls applicable to all. SAMA CSF, however, builds upon these foundational principles with more granular, sector-specific requirements, especially concerning financial transaction security, customer data protection, and resilience against sophisticated cyber threats targeting financial systems.

For instance, both frameworks require incident response plans, but SAMA CSF often demands more stringent reporting timelines and detailed forensic capabilities tailored to financial fraud. Similarly, third-party risk management is present in both, but SAMA CSF will likely have stricter due diligence and continuous monitoring requirements for vendors handling sensitive financial data. A robust GRC platform for Saudi businesses can help manage the overlapping and unique controls efficiently across both frameworks.

04

Strategic Approach to Dual Compliance

Organizations subject to both SAMA CSF and NCA ECC should adopt a unified, risk-based compliance strategy. Start by identifying the common controls and implement them rigorously. Then, layer on the more specific SAMA CSF requirements. This approach avoids redundant efforts and builds a stronger, more integrated security posture. A good starting point is to establish a strong cybersecurity governance framework that can support both sets of regulations.

Consider leveraging external expertise. For many SMBs and even larger firms without dedicated in-house compliance teams, navigating these frameworks can be overwhelming. Our cybersecurity services offer tailored solutions, helping you develop and implement a compliance program that meets the demands of both SAMA and NCA. This ensures you're not just compliant on paper, but truly secure in practice.

05

The Role of PDPL

Beyond SAMA and NCA, the Personal Data Protection Law (PDPL) introduces another critical layer, applicable to any entity processing personal data of Saudi residents. PDPL mandates strict data handling, storage, and breach notification requirements. While SAMA CSF and NCA ECC address data protection broadly, PDPL provides the legal framework for individual data rights and organizational obligations. Organizations must notify the NCA within 45 days of a personal data breach, a key compliance point. Understanding how PDPL intersects with your SAMA or NCA compliance efforts is crucial. For a deeper dive into this, refer to our PDPL compliance guide for Saudi SMBs.

06

Conclusion

Navigating Saudi Arabia's cybersecurity landscape requires a clear understanding of frameworks like SAMA CSF and NCA ECC. While distinct in their primary audience, they contribute to a cohesive national cybersecurity posture. Financial institutions must meet both, prioritizing SAMA's stringent demands while ensuring NCA ECC's foundational controls are robust. Proactive assessment, strategic planning, and expert guidance are essential to achieve and maintain compliance, safeguarding your operations and contributing to the Kingdom's digital security ambitions.

07

References

National Cybersecurity Authority - Essential Cybersecurity Controls 2:2024 Saudi Arabian Monetary Authority - Cyber Security Framework Saudi Arabia Personal Data Protection Law

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Frequently asked questions

Find answers to common questions about our services

Share this article

Related Reading

More insights from the Allo Technologies practice

Compliance

NIST CSF 2.0 Mapped to NCA Requirements

Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.

Read more
Compliance

Which NCA Framework Applies to You: The Complete Map

The NCA publishes at least eight sets of controls. Most organisations need one or two. A decision path for ruling out the rest quickly.

Read more
Compliance

NCA MSOC Licensing: Tier 1 and Tier 2 Explained

The tiers are defined by who you may serve, not by capability. What separates them, what RFMSOC requires, and why the licence is not a control framework.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%