
Cybersecurity Saudization: Structuring Your Security Team Under the Updated Controls
ECC 2:2024 expanded the Saudi national staffing requirement across cybersecurity roles. What that means for team design, sourcing, and operating model.
ECC 2:2024 expanded the Saudi national staffing requirement across cybersecurity roles. What that means for team design, sourcing, and operating model.

Most regulatory changes alter what an organisation must do. This one alters who is permitted to do it, which is a considerably harder problem to solve on a deadline.
The Essential Cybersecurity Controls were updated, with ECC 2:2024 replacing the original 2018 version. Among the changes, cybersecurity Saudization now requires cybersecurity roles to be filled by qualified Saudi nationals, expanded from earlier versions that applied the requirement only to senior positions. The revised framework is structured across four domains, 28 subdomains, and approximately 110 controls.
Technical controls can be procured. Staffing cannot, at least not on the same timeline. An organisation that discovers a compliance gap in its security team faces a hiring market where every other organisation in the Kingdom is looking for the same people at the same time.
This article covers what the requirement changes structurally, the options available to organisations that cannot fill roles directly, and how to approach the problem without either breaching the requirement or leaving the function unstaffed.
What changes in practice
The narrower version of this requirement was manageable. An organisation appointed a Saudi national to lead the security function and continued operating as before beneath that appointment.
The expanded version reaches into the operating layer, which raises questions the earlier version did not.
Role definition becomes a compliance artefact. An organisation must be able to state which roles are cybersecurity roles. In practice, security responsibilities are frequently distributed across people whose job titles say something else — a network engineer managing firewall policy, a systems administrator handling identity, an infrastructure lead running vulnerability remediation. Whether those constitute cybersecurity roles is a question the organisation must answer deliberately rather than discover during assessment.
Qualification matters alongside nationality. The requirement specifies qualified Saudi nationals. Filling a seat does not satisfy a control that expects demonstrable competence, which means certification, experience, and development pathways form part of the evidence.
Outsourced arrangements need examination. Where a managed provider performs security functions, the question of how the requirement applies to that arrangement is one organisations should resolve deliberately and document, rather than assume in whichever direction is more convenient.
Evidence follows. Like every other element of these frameworks, the organisation should expect to demonstrate its position rather than state it. Role definitions, staffing records, qualifications held, and development plans constitute the artefact set.
The market reality
Every organisation in scope faces the same constraint at the same time, and the supply of experienced Saudi cybersecurity professionals is not elastic in the short term.
The consequences are predictable. Compensation for experienced practitioners rises. Retention becomes harder as competitors recruit actively. Organisations that cannot compete on salary lose people to those that can, which concentrates capability in larger institutions and leaves mid-sized organisations cycling through vacancies.
There is a second-order effect worth naming. An organisation that hires to fill a compliance requirement without building the conditions for people to stay solves the problem temporarily and repeats the exercise annually. The requirement is not satisfied by a hire. It is satisfied by a sustained staffing position.
The realistic options
Direct hiring works for organisations that can compete on compensation, offer meaningful technical work, and provide a development path. It is the cleanest answer to the requirement and the hardest to execute quickly.
Developing from adjacent functions is slower and more durable. Network and systems engineers already hold much of the foundation for security roles, and structured development pathways convert internal staff who already understand the environment. Organisations that take this route reduce their hiring exposure permanently rather than annually.
Graduate and early-career pipelines address the same problem further upstream. The investment takes years to return, which is exactly why organisations that start now hold an advantage over those that begin when the shortage bites hardest.
Managed services change the shape of the problem. Contracting continuous monitoring, first-line response, and routine security operations reduces the internal headcount required to hold coverage, allowing the organisation to concentrate its scarce internal capability in the roles where internal ownership matters most.
Hybrid models are what most organisations arrive at. Strategy, architecture, risk ownership, and regulatory accountability stay internal. Sustained operational execution — the twenty-four-hour coverage that is hardest to staff and most expensive to retain — moves to a contracted arrangement. The organisation retains direction and reduces the number of seats it must fill and refill.
Designing a team that satisfies the requirement and works
Start by mapping the actual functions the organisation needs performed rather than the roles it currently has. Governance and risk. Security architecture. Operations and monitoring. Incident response. Compliance and evidence. Vulnerability management. These are functions, not necessarily headcount, and small organisations combine several into one role legitimately.
Establish which functions require internal ownership on regulatory grounds and which can be contracted. Accountability cannot be outsourced, and neither can decisions about the organisation's own risk. Execution frequently can.
Define the roles precisely, because role definition is the artefact assessment examines and the foundation for everything else. Vague definitions produce vague compliance positions.
Then build a sourcing plan across all four routes rather than depending on one. Organisations relying entirely on external hiring compete in the tightest market. Organisations combining internal development, early-career pipeline, and contracted operations reduce their exposure to it substantially.
Frequently asked questions
Which roles count as cybersecurity roles? The organisation must define this and defend the definition. Roles whose primary purpose is security clearly qualify. Roles where security is a component of a broader technical remit require a deliberate determination, recorded with reasoning, rather than an assumption.
Does using a managed provider satisfy the requirement? It changes the internal staffing profile and does not remove accountability. How the requirement applies to contracted arrangements should be assessed against the organisation's specific position and documented, not assumed.
What if the organisation cannot fill a role? An unfilled role with a documented, active sourcing plan is a materially different position from an unfilled role with no plan. Interim arrangements, development pathways in progress, and contracted coverage all form part of a defensible position while recruitment continues.
Is certification sufficient evidence of qualification? It contributes and rarely stands alone. Demonstrable experience, continuing development, and the ability to perform the role are what the requirement is reaching for.
How ITBuilders supports security operating models
ITBuilders delivers managed security operations for organisations in the Kingdom, structured so that internal teams retain ownership of strategy, architecture, and risk while contracted delivery covers sustained operational execution. Engagements begin with a review of the current operating model and role structure, so the division reflects both the regulatory position and what the organisation can realistically staff.
To discuss security operating models, contact ITBuilders at 920-020-750 or itbuilders.com.sa
Related services
Turn this insight into a practical next step.
Discuss your environment with our team and get a clear recommendation grounded in your operational reality.


