Cybersecurity and data protection compliance in Saudi Arabia

Every Saudi rule that applies to you, mapped to one control set and kept current.

The NCA, SDAIA, SAMA and CST each publish their own requirements. AccuSights maps them to a single set of controls, collects the evidence once, and shows you where you stand before a regulator or auditor asks.

Built from the regulators' own documents. Every framework page on this site names its official source and the date we last checked it.

What the platform does

Three jobs, done continuously, so compliance becomes the by-product of running securely rather than a project you repeat every year.

Map

One control set, every framework

Your controls are mapped once to ECC-2:2024, the Personal Data Protection Law, the SAMA Cyber Security Framework where it applies, and international standards such as ISO/IEC 27001. A new requirement becomes a mapping, not a new project.

Evidence

Collected once, reused everywhere

Policies, configurations and records are gathered once and linked to every requirement they satisfy, so the same proof answers the NCA, SDAIA and your auditor.

Visibility

A read-only compliance agent

The agent observes your cloud and infrastructure configuration and reports drift against your control set. It cannot change your systems. Every fix stays in your hands.

One control, several rulebooks

An illustration at domain level. In an engagement we map your actual controls to the specific clauses that apply to you.

Your controlWhere it counts

A board-approved cybersecurity policy with named roles

  • NCA ECC-2:2024Cybersecurity Governance
  • SAMA framework, financial institutionsCyber Security Leadership and Governance
  • ISO/IEC 27001Organizational controls

Security requirements written into supplier contracts

  • NCA ECC-2:2024Third-Party and Cloud Computing Cybersecurity
  • SAMA framework, financial institutionsThird Party Cyber Security
  • ISO/IEC 27001Organizational controls

Personal data breaches reported to the regulator in time

  • Personal Data Protection LawNotify SDAIA within 72 hours, under Article 24 of the Implementing Regulation
  • EU GDPR, for clients in the EUArticle 33: notify the supervisory authority within 72 hours
How one control maps across Saudi and international frameworks

Key dates

  1. The Personal Data Protection Law is issued by Royal Decree No. M/19.

  2. The law and its Implementing Regulation come into force, followed by a one-year grace period.

  3. CST issues the fourth version of its Regulations for the Provision of Cloud Computing Services, under CST Decision 506/1445.

  4. The grace period ends and the Personal Data Protection Law becomes fully enforceable.

How we work with you

  1. Assess

    The Cybersecurity and Data Protection Assessment measures your controls against the Saudi frameworks that apply to you and ranks the gaps by risk.

  2. Get ready

    We map your controls to one set, prepare the evidence and close the gaps in the order that matters, so you are ready before anyone asks.

  3. Stay current

    The read-only compliance agent reports configuration drift, and we track rule changes, so your position does not quietly decay between reviews.

Why AccuSights

Founded in the United States by people who have done this work inside the institutions that spend the most on security.

More than two decades of assessments

Our founder has assessed banks, card networks, health insurers and technology companies on site, then presented the findings to their boards.

Clinical precision in healthcare

Our healthcare programs are led by a physician trained in medicine and surgery. Controls are designed with clinicians, not against them.

Sourced, dated and independent

Every rule on this site links to the regulator's own document and shows when we last verified it. We are not affiliated with any authority.

Common questions

Does the NCA ECC apply to private companies?

Yes, in some cases. The ECC is mandatory for government entities in the Kingdom and for their affiliated companies and entities, inside and outside the Kingdom. It is also mandatory for private-sector organizations that own, operate or host critical national infrastructure. The NCA strongly encourages all other organizations to apply it.

Many private companies outside that scope adopt it anyway, because it is the baseline their government and enterprise customers recognize. Read the ECC page.

When did the Saudi PDPL become enforceable?

The law and its Implementing Regulation came into force on 14 September 2023. After a one-year grace period, it became fully enforceable on 14 September 2024.

How fast must a personal data breach be reported?

The controller must notify SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the people it belongs to, under Article 24 of the Implementing Regulation. Affected individuals must be told without undue delay where the breach may harm them. Read the breach guide.

Is AccuSights approved by the NCA or SDAIA?

No. AccuSights is an independent firm and is not affiliated with, or endorsed by, any Saudi authority. The regulator decides whether you meet its requirements. We help you understand them, prepare, and stay ready.

Ten minutes to know exactly where you stand

Tell us what you do and who regulates you. We will show you which Saudi rules apply, where the gaps usually are, and the shortest route to ready. No slides, no pitch.