NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence
A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
6 min read · Reviewed 20 September 2026
SAMA Cyber Security Framework: what Saudi financial institutions need to evidence
Who the SAMA Cyber Security Framework applies to, its four domains, the maturity level SAMA expects and the IT evidence a member organisation keeps.
3 min read · Reviewed 20 September 2026
Saudi PDPL: an IT checklist for the Personal Data Protection Law
What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
4 min read · Reviewed 20 September 2026
Microsoft 365 and cloud governance for Saudi organisations
What the NCA’s cloud controls say, where data localisation now sits, what Microsoft has announced for Saudi Arabia and the Microsoft 365 settings to keep.
3 min read · Reviewed 20 September 2026
Choosing and overseeing an IT provider in Saudi Arabia: third-party risk
What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026
Audit readiness for NCA and SAMA reviews: the IT evidence checklist
How the NCA assesses ECC compliance, what control 1-8 requires, the evidence pack to build and how ISO 27001:2022 fits alongside.
3 min read · Reviewed 20 September 2026