
Your Company Just Became Regulated: Understanding the New Private Sector Cybersecurity Controls
The NCA extended mandatory cybersecurity controls to private companies of almost every size. Who is in scope, what the controls require, and where to start.
The NCA extended mandatory cybersecurity controls to private companies of almost every size. Who is in scope, what the controls require, and where to start.

For most of the past decade, Saudi cybersecurity regulation had a clear boundary. Government entities and critical national infrastructure operators carried mandatory obligations. Everyone else watched from outside, borrowing frameworks voluntarily or ignoring them entirely.
That boundary is gone. The National Cybersecurity Authority issued the Non-CNI Private Sector Entities Cybersecurity Controls, establishing a mandatory baseline for private-sector entities that are not part of sensitive national critical infrastructure. Released in January 2026, the framework extends baseline mandatory controls to essentially every private-sector company operating in the Kingdom, regardless of whether it is formally designated as critical infrastructure.
Many organisations now in scope have not registered the change. Some assume the rules still apply to somebody larger. Others know a change occurred and have not worked out what it demands of them.
This article sets out who the controls cover, what they require, and how to approach the gap between where an organisation sits today and where the framework expects it to be.
Who falls in scope
The framework divides covered organisations into two categories by size.
Large entities are those with 250 or more full-time employees or annual revenue above SAR 200,000,000. Small and medium enterprises are those with between 6 and 249 full-time employees or annual revenue between SAR 3,000,000 and SAR 200,000,000.
Read that threshold carefully. A company of six people falls inside the framework. The obligations differ by category, and the lower band is deliberately proportionate, but the question of whether an organisation is covered has a much simpler answer than it did a year ago. For most companies operating commercially in the Kingdom, the answer is yes.
Previously, NCA controls applied primarily to government entities and CNI operators. The new framework represents a significant expansion of regulatory reach, targeting the SMEs and startups that previously considered NCA frameworks entirely optional.
The practical implication is that scope assessment now precedes everything. An organisation cannot plan remediation without first establishing which category it sits in and which controls attach to that category.
What the controls cover
The controls are tailored by entity size across three components: Governance, Cybersecurity Defense, and Third-party and Cloud Computing Cybersecurity. Core defense measures include endpoint protection, data classification, backup management and periodic penetration testing.
Each component tends to fail differently in practice.
Governance is where organisations without a security function struggle most, because the requirement is organisational rather than technical. Someone must own security. Policies must exist, be approved, and be current. Risk must be assessed and recorded rather than carried informally in the heads of the IT team. No product purchase satisfies this component.
Cybersecurity Defense is the technical layer, and it is the part most organisations assume they already have. Endpoint protection usually exists in some form. Backup usually runs. Data classification usually does not exist at all, and periodic penetration testing is frequently something the company has discussed rather than done. The gap here is less often absence than inconsistency: controls deployed across part of the estate and never extended to the rest.
Third-party and Cloud Computing Cybersecurity is the component that catches the most organisations off guard. Vendor risk is nobody's job in most companies. Cloud environments get provisioned by whoever needed them, configured to defaults, and never reviewed. An organisation with strong internal controls and no visibility over its suppliers and cloud tenancies fails this component regardless of how well the other two are covered.
The wider regulatory movement
The private sector controls did not arrive in isolation. ECC 2:2024 replaced the original 2018 version, refining the structure to four domains, 28 subdomains, and approximately 110 controls. Alongside it, the NCA introduced cybersecurity Saudization, requiring cybersecurity roles to be filled by qualified Saudi nationals, expanded from earlier versions that applied the requirement only to senior positions.
Organisations that supply government entities or critical infrastructure operators feel this twice. They must meet their own baseline obligations, and they must satisfy the third-party requirements their customers now carry. Supply chain scrutiny flows downward, and companies that cannot evidence their own controls will find procurement conversations getting harder.
Where organisations actually get stuck
The pattern across compliance programmes is consistent, and it is rarely about technology.
Evidence, not controls. Assessors ask organisations to demonstrate that a control operates, not that a product is installed. A company running endpoint protection with no reporting, no coverage records, and no exception log has the control and cannot prove it. Missing evidence is treated as a missing control.
Ownership vacuum. Security responsibility sits with whoever is available rather than with a named role carrying authority and budget. Programmes stall at the point where remediation requires money that nobody has authority to spend.
Partial coverage. Controls get implemented on the systems the IT team knows well and never reach the rest. The environment nobody has inventoried is the environment nobody has protected.
Documentation written once. Policies get drafted for the assessment, approved, filed, and never revisited. A policy that no longer matches operating practice is worse than no policy, because it demonstrates a governance failure rather than a gap.
A sensible sequence
Scope assessment comes first. Establish the category, confirm which controls apply, and record the reasoning. This takes days, not months, and everything downstream depends on it.
Asset inventory follows, because controls cannot be applied to systems nobody has listed. Most organisations discover unknown cloud tenancies, forgotten servers, and unsupported devices at this stage.
Gap analysis compares the current state against the applicable controls, control by control, with evidence noted where it exists. The output is a list, not a score.
Prioritised remediation then addresses gaps by risk and by effort, not in the order the framework lists them. Some gaps close in an afternoon. Others require procurement cycles and should start early precisely because they take longest.
Evidence and governance run continuously from that point, because the framework assumes an operating management system rather than a one-time project.
Frequently asked questions
Does a small company really fall in scope? Entities with as few as six full-time employees fall within the SME category. The obligations are proportionate to size, but the threshold for being covered at all is low.
Can compliance be purchased through products? No. The Governance component and much of the third-party component are organisational. Products support technical controls and cannot supply ownership, policy, risk assessment, or evidence.
What if the organisation already follows another framework? Existing work usually maps across substantially, which shortens the effort considerably. Mapping is still required, because overlap is not equivalence and the gaps sit precisely where the frameworks diverge.
How long does a first compliance cycle take? It depends on starting position far more than on company size. Organisations with an asset inventory, a named security owner, and functioning backup move quickly. Organisations starting from none of those spend most of their time on the foundations rather than on the controls themselves.
How ITBuilders supports compliance programmes
ITBuilders delivers scope assessment, gap analysis, and remediation for organisations working through NCA control frameworks, combining the advisory work with the technical implementation the gaps require. Because the same team designs and operates the underlying infrastructure, remediation reflects what the environment can actually sustain rather than what looks complete on paper.
To discuss your compliance position, contact ITBuilders at 920-020-750 or itbuilders.com.sa
Related services
Cybersecurity Services · Strategic IT Consulting · Managed Services
Turn this insight into a practical next step.
Discuss your environment with our team and get a clear recommendation grounded in your operational reality.


