Reference
Who regulates what in Saudi Arabia
Five authorities shape cybersecurity and data protection in the Kingdom. Knowing which one governs which question saves weeks.
The authorities
National Cybersecurity Authority (NCA)
The national cybersecurity regulator. Issues the Essential Cybersecurity Controls and the controls that extend them, and monitors compliance for the entities in their scope.
Applies to: Mandatory for government entities and their affiliated companies, and for private-sector organizations that own, operate or host critical national infrastructure; its extensions reach critical systems, cloud, telework and operational technology.
Saudi Data and Artificial Intelligence Authority (SDAIA)
The competent authority for the Personal Data Protection Law. Receives breach notifications, runs the National Register of Controllers and publishes the implementing rules.
Applies to: Every organization that processes personal data in the Kingdom, and parties outside the Kingdom that process personal data of people residing in it.
Saudi Central Bank (SAMA)
Regulates banks and other financial institutions and mandates the SAMA Cyber Security Framework for them. Its rules do not apply outside the institutions it regulates.
Applies to: Banks and other financial institutions SAMA regulates.
Communications, Space and Technology Commission (CST)
The regulator for communications, space and technology. For cloud, it registers service providers under the Regulations for the Provision of Cloud Computing Services and sets which provider categories may host which classes of government data.
Applies to: Telecom operators and other communications, space and technology providers; in cloud, service providers serving the Kingdom and their subscribers, with added obligations for subscribers holding government data.
Digital Government Authority (DGA)
Sets digital government platforms and standards for government entities.
Applies to: Government entities.
Quick answers
Who do I report a personal data breach to?
SDAIA, within 72 hours, under Article 24 of the Implementing Regulation. Read the breach guide.
Who decides where government data can be hosted in the cloud?
Several authorities share it. CST registers cloud providers by category, and subscribers holding government data must use a CST-registered provider. The classification levels come from the National Data Management Office (NDMO) at SDAIA, or from the sector regulator, and CCC-2:2024 refers data localization to the NDMO. The NCA sets the cloud and critical-systems controls. Read the residency guide.
Does SAMA regulate my fintech?
Only if SAMA licenses or regulates your business. SAMA's framework applies to the institutions it regulates, not to every company in financial services.
Last verified against official sources: 26 September 2026
Sources
- NCA, Essential Cybersecurity Controls (ECC-2:2024) (opens in a new tab)
- NCA, Cloud Cybersecurity Controls (CCC-2:2024) (opens in a new tab)
- SDAIA, Implementing Regulation of the Personal Data Protection Law (English translation for guidance) (opens in a new tab)
- SAMA Rulebook, Cyber Security Framework (opens in a new tab)
- CST, Regulations for the Provision of Cloud Computing Services (opens in a new tab)
Ten minutes to know exactly where you stand
Tell us what you do and who regulates you. We will show you which Saudi rules apply, where the gaps usually are, and the shortest route to ready. No slides, no pitch.