Reference
Which Saudi rules apply to your sector
A starting map. Your exact obligations depend on what you do, who your customers are, if you are a government entity or affiliated with one, and if you own, operate or host critical national infrastructure.
Sector by sector
Banks and SAMA-regulated financial institutions
Banks, finance companies, payment providers and credit bureaus regulated by SAMA answer to SAMA for cybersecurity and to SDAIA for personal data.
What applies
- SAMA Cyber Security Framework: four domains and at least maturity level 3.
- The Personal Data Protection Law for customer and employee personal data.
- PCI DSS, the EMV standard and the SWIFT Customer Security Controls Framework for banks under the SAMA framework; other SAMA-regulated institutions apply PCI DSS and/or the SWIFT framework where they handle cardholder data or SWIFT services.
- The NCA Essential Cybersecurity Controls if the institution is a government entity or affiliated with one, or if it owns, operates or hosts critical national infrastructure.
Healthcare providers
Health data is sensitive personal data under the Personal Data Protection Law. Government hospitals, and private-sector organizations that own, operate or host critical national infrastructure, are also in the NCA's mandatory scope.
What applies
- The Personal Data Protection Law: if processing sensitive personal data is a core activity, you must appoint a data protection officer and register with SDAIA. See the DPO and registration guide.
- Breach notification to SDAIA within 72 hours where a breach may cause harm.
- The NCA Essential Cybersecurity Controls for government health entities and their affiliated companies, and for private healthcare organizations that own, operate or host critical national infrastructure.
- Cloud hosting of government health data follows the cloud and data residency rules.
Government entities and their affiliates
Government entities carry the NCA baseline as a mandatory requirement, and government data carries the strictest hosting rules.
What applies
- The NCA Essential Cybersecurity Controls, mandatory, plus the Critical Systems Cybersecurity Controls for critical systems.
- The NCA Cloud Cybersecurity Controls for cloud, and CST's provider categories for where government data may be hosted.
- The Personal Data Protection Law, including DPO appointment for public entities processing personal data on a large scale, and registration.
- Digital government standards from the DGA.
Cloud and technology providers
Providers serving the Kingdom are regulated as providers, and often also act as processors for their clients' personal data.
What applies
- CST's Regulations for the Provision of Cloud Computing Services: registration and the category that decides which data classes you may host.
- The NCA Cloud Cybersecurity Controls, CCC-2:2024, where you serve government entities or critical national infrastructure organizations. Providers that serve only individuals or other private organizations are outside its scope.
- The Personal Data Protection Law when you process personal data for clients.
Telecommunications
Telecom operators are regulated by CST and hold large volumes of personal data.
What applies
- CST licensing and regulatory requirements for operators.
- The NCA Essential Cybersecurity Controls, and the Critical Systems Cybersecurity Controls for critical systems, where the operator owns, operates or hosts critical national infrastructure.
- The Personal Data Protection Law for subscriber personal data, including breach notification within 72 hours.
Industry, energy and utilities
Industrial control systems in critical facilities have their own NCA control set, and organizations that own, operate or host critical national infrastructure are in the NCA's mandatory scope.
What applies
- The NCA Essential Cybersecurity Controls where you own, operate or host critical national infrastructure.
- The NCA Operational Technology Cybersecurity Controls, OTCC-1:2022, for industrial control systems in facilities deemed critical and owned or operated by government organizations or by private-sector organizations that own, operate or host critical national infrastructure. ECC compliance is a prerequisite.
- The Critical Systems Cybersecurity Controls where systems qualify as critical.
- The Personal Data Protection Law for employee and customer personal data.
Retail and e-commerce
The main obligations come from personal data and payment card data.
What applies
- The Personal Data Protection Law: privacy notice, lawful basis, rights requests and breach notification within 72 hours.
- PCI DSS for any storage, processing or transmission of cardholder data.
- Transfers of customer data outside the Kingdom follow the Regulation on Personal Data Transfer outside the Kingdom.
Last verified against official sources: 26 September 2026
Sources
- NCA, Essential Cybersecurity Controls (ECC-2:2024) (opens in a new tab)
- NCA, Critical Systems Cybersecurity Controls (opens in a new tab)
- SDAIA, Implementing Regulation of the Personal Data Protection Law (English translation for guidance) (opens in a new tab)
- SDAIA, Rules Governing the National Register of Controllers within the Kingdom (opens in a new tab)
- SAMA Rulebook, Cyber Security Framework (opens in a new tab)
- CST, Regulations for the Provision of Cloud Computing Services (opens in a new tab)
- NCA, Operational Technology Cybersecurity Controls (opens in a new tab)
- NCA, Cloud Cybersecurity Controls (CCC-2:2024) (opens in a new tab)
- PCI Security Standards Council, PCI DSS (opens in a new tab)
Ten minutes to know exactly where you stand
Tell us what you do and who regulates you. We will show you which Saudi rules apply, where the gaps usually are, and the shortest route to ready. No slides, no pitch.