FAQ

Questions regulated organisations ask us.

Short, sourced answers on the NCA, SAMA and the PDPL, Microsoft 365, ISO 27001 and working with Cre8 IT.
Saudi regulators and frameworks

The rules behind the questions

What is the difference between the NCA, SAMA and SDAIA?

The National Cybersecurity Authority (NCA) sets national cybersecurity controls such as ECC-2:2024. The Saudi Central Bank (SAMA) regulates banks, insurers, financing companies and other financial institutions, and publishes the Cyber Security Framework. The Saudi Data and Artificial Intelligence Authority (SDAIA) oversees the Personal Data Protection Law. Which apply to you depends on your sector and licence.

Who must comply with the NCA’s ECC-2:2024?

Government agencies in the Kingdom and their affiliated companies and entities, and private-sector entities that own, operate or host critical national infrastructure. The NCA encourages all other entities to use the controls. See our ECC-2:2024 guide.

Who does the SAMA Cyber Security Framework apply to?

Banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructure operating in Saudi Arabia. See our SAMA framework guide.

How fast must a personal data breach be reported?

According to DLA Piper’s summary of the PDPL, to SDAIA within 72 hours of becoming aware of it, through the National Data Governance Platform, and to affected individuals without undue delay. See our PDPL IT checklist.

Does ECC-2:2024 require data to be hosted in Saudi Arabia?

ECC-2:2024 deleted the ECC-1:2018 sub-control that said so, and says data localisation controls moved to the NDMO at SDAIA. Check the NDMO’s requirements, your sector regulator and your contracts. See our cloud governance guide.

Are these pages legal advice?

No. They summarise what regulators publish and how organisations can meet it. Confirm the current rules and take advice from your compliance lead or legal adviser about your own obligations.
Microsoft 365 and security basics

Plain answers to common security questions

What is Microsoft 365 governance?

It is the set of decisions, settings and records that control who can reach your data, from which devices, how long it is kept and how you would prove it. It covers identity, devices, sharing, retention and logging. See the full guide.

What is multi-factor authentication and why do regulators expect it?

Multi-factor authentication (MFA) asks for a second proof of identity, such as an authenticator app, as well as a password. Stolen passwords are a common way in, and MFA stops most of those attacks. ECC-2:2024 includes MFA for remote access and privileged accounts (control 2.2.3.2).

Is ISO 27001 the same as the NCA’s ECC?

No. ISO 27001 certifies a management system. ECC is the NCA’s national set of controls, assessed by self-assessment, the compliance tool and field audits. ISO 27001 helps organise your evidence but does not replace either. See our audit readiness guide.

What does “audit ready” mean for IT?

It means you can produce, on request, evidence that your controls exist, operate and are reviewed: registers, dated reports and records with named owners.

What is SOC as a Service, and does location matter?

SOC as a Service is round-the-clock threat monitoring by a security operations centre, delivered as a managed service. For organisations in ECC’s scope, control 4-1-3-2 says managed monitoring and operations centres that use remote access must be fully located in the Kingdom, so always ask a provider, including us, where its centre is.
Working with Cre8 IT

About our service

Where is Cre8 IT based?

Our Riyadh office is at Building 3074, Level 29, Tower B, Olaya Towers, Prince Mohammed Bin Abdulaziz Road. Our head office is in Jumeirah Lake Towers, Dubai, and we have an office in the United Kingdom. We have supported businesses since 2012.

Which certifications does Cre8 IT hold?

We are certified to ISO 27001:2022 for information security and ISO 9001 for quality management, and we are a certified Microsoft Partner. We do not claim any registration or approval that we do not hold.

What does managed IT support include?

A helpdesk phone line and ticketing system, proactive monitoring of networks and devices, virus detection and removal, scheduled backups with tested recovery, on-site visits as often as you need, and 24/7 emergency support.

How is managed IT support priced?

A fixed monthly rate shaped around your requirements, your budget and how often you want us on site. Ask for a free estimate.

Do you offer 24/7 support?

Yes. We provide 24/7 emergency IT support, on site or remote.

Can start-ups and non-profits get a free consultation?

Yes. New start-ups and non-profits can book a complimentary 30-minute consultation.

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.