Cybersecurity and data protection compliance in Saudi Arabia
Every Saudi rule that applies to you, mapped to one control set and kept current.
The NCA, SDAIA, SAMA and CST each publish their own requirements. AccuSights maps them to a single set of controls, collects the evidence once, and shows you where you stand before a regulator or auditor asks.
Built from the regulators' own documents. Every framework page on this site names its official source and the date we last checked it.
What the platform does
Three jobs, done continuously, so compliance becomes the by-product of running securely rather than a project you repeat every year.
One control set, every framework
Your controls are mapped once to ECC-2:2024, the Personal Data Protection Law, the SAMA Cyber Security Framework where it applies, and international standards such as ISO/IEC 27001. A new requirement becomes a mapping, not a new project.
Collected once, reused everywhere
Policies, configurations and records are gathered once and linked to every requirement they satisfy, so the same proof answers the NCA, SDAIA and your auditor.
A read-only compliance agent
The agent observes your cloud and infrastructure configuration and reports drift against your control set. It cannot change your systems. Every fix stays in your hands.
One control, several rulebooks
An illustration at domain level. In an engagement we map your actual controls to the specific clauses that apply to you.
A board-approved cybersecurity policy with named roles
- NCA ECC-2:2024Cybersecurity Governance
- SAMA framework, financial institutionsCyber Security Leadership and Governance
- ISO/IEC 27001Organizational controls
Security requirements written into supplier contracts
- NCA ECC-2:2024Third-Party and Cloud Computing Cybersecurity
- SAMA framework, financial institutionsThird Party Cyber Security
- ISO/IEC 27001Organizational controls
Personal data breaches reported to the regulator in time
- Personal Data Protection LawNotify SDAIA within 72 hours, under Article 24 of the Implementing Regulation
- EU GDPR, for clients in the EUArticle 33: notify the supervisory authority within 72 hours
The Saudi rulebook, simplified
Start here. Each page explains what the rule is, who it applies to and what to do first.
Essential Cybersecurity Controls
The national baseline: 4 domains, 28 subdomains and 108 main controls.
Read morePersonal Data Protection Law
What the law asks of every organization that processes personal data, in plain language.
Read moreSAMA Cyber Security Framework
Four domains and a maturity level 3 target for the institutions SAMA regulates.
Read moreThe NCA controls family
How the critical systems, cloud, telework, operational technology and data controls sit on top of the ECC.
Read moreCloud and data residency
How government data is classified, which cloud providers may hold it, and what applies to critical systems.
Read the guideBreach notification in 72 hours
What to report to SDAIA, when the clock starts, and how to tell the people affected.
Read the guideKey dates
The Personal Data Protection Law is issued by Royal Decree No. M/19.
The law and its Implementing Regulation come into force, followed by a one-year grace period.
CST issues the fourth version of its Regulations for the Provision of Cloud Computing Services, under CST Decision 506/1445.
The grace period ends and the Personal Data Protection Law becomes fully enforceable.
How we work with you
Assess
The Cybersecurity and Data Protection Assessment measures your controls against the Saudi frameworks that apply to you and ranks the gaps by risk.
Get ready
We map your controls to one set, prepare the evidence and close the gaps in the order that matters, so you are ready before anyone asks.
Stay current
The read-only compliance agent reports configuration drift, and we track rule changes, so your position does not quietly decay between reviews.
Why AccuSights
Founded in the United States by people who have done this work inside the institutions that spend the most on security.
More than two decades of assessments
Our founder has assessed banks, card networks, health insurers and technology companies on site, then presented the findings to their boards.
Clinical precision in healthcare
Our healthcare programs are led by a physician trained in medicine and surgery. Controls are designed with clinicians, not against them.
Sourced, dated and independent
Every rule on this site links to the regulator's own document and shows when we last verified it. We are not affiliated with any authority.
Common questions
Does the NCA ECC apply to private companies?
Yes, in some cases. The ECC is mandatory for government entities in the Kingdom and for their affiliated companies and entities, inside and outside the Kingdom. It is also mandatory for private-sector organizations that own, operate or host critical national infrastructure. The NCA strongly encourages all other organizations to apply it.
Many private companies outside that scope adopt it anyway, because it is the baseline their government and enterprise customers recognize. Read the ECC page.
When did the Saudi PDPL become enforceable?
The law and its Implementing Regulation came into force on 14 September 2023. After a one-year grace period, it became fully enforceable on 14 September 2024.
How fast must a personal data breach be reported?
The controller must notify SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the people it belongs to, under Article 24 of the Implementing Regulation. Affected individuals must be told without undue delay where the breach may harm them. Read the breach guide.
Is AccuSights approved by the NCA or SDAIA?
No. AccuSights is an independent firm and is not affiliated with, or endorsed by, any Saudi authority. The regulator decides whether you meet its requirements. We help you understand them, prepare, and stay ready.
Last verified against official sources: 26 September 2026
Sources
- NCA, Essential Cybersecurity Controls (ECC-2:2024) (opens in a new tab)
- SDAIA, Implementing Regulation of the Personal Data Protection Law (English translation for guidance) (opens in a new tab)
- SAMA Rulebook, Cyber Security Framework (opens in a new tab)
- CST, Regulations for the Provision of Cloud Computing Services (opens in a new tab)
Ten minutes to know exactly where you stand
Tell us what you do and who regulates you. We will show you which Saudi rules apply, where the gaps usually are, and the shortest route to ready. No slides, no pitch.