Insights · Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
The short answer

ECC-2:2024 requires in-scope entities to set cybersecurity requirements for third-party contracts, and to include as a minimum non-disclosure and secure data removal, incident communication and an obligation to apply your requirements. For IT and cybersecurity managed services you must assess the risk before signing, and monitoring and operations centres that use remote access must be fully located in Saudi Arabia. SAMA’s framework has a dedicated third-party domain.

Key points
  • Control 4-1-2 sets minimum contract terms: non-disclosure and secure removal of data, incident communication, and applying your cybersecurity requirements.
  • For IT or cybersecurity outsourcing and managed services, run a risk assessment before signing (4-1-3), and review third-party requirements periodically (4-1-4).
  • Managed cybersecurity monitoring and operations centres that use remote access must be fully located in the Kingdom (4-1-3-2). Ask where yours is.
  • SAMA’s framework has a dedicated third-party cyber security domain (3.4).
  • Ask any provider, including Cre8 IT, for its certificate and scope, and expect a straight answer about where services are delivered from.

What the rules say

SourceRequirement
ECC-2:2024 4-1-1Cybersecurity requirements for contracts and agreements with third parties are identified, documented and approved.
ECC-2:2024 4-1-2Contracts that could affect your data or services include, as a minimum: non-disclosure and secure removal of your data at the end of service; communication procedures for a cybersecurity incident; and an obligation on the third party to apply your cybersecurity requirements and policies and the relevant legislation.
ECC-2:2024 4-1-3For IT or cybersecurity outsourcing and managed services: a risk assessment and available mitigating controls before signing (4.1.3.1); and cybersecurity managed service centres for monitoring and operations that use remote access must be fully located in the Kingdom of Saudi Arabia (4.1.3.2).
ECC-2:2024 4-1-4Third-party cybersecurity requirements are reviewed periodically.
SAMA Cyber Security Framework 3.4A dedicated domain for third-party cyber security in the financial institutions the framework covers.

Questions to ask before you sign

  • Where is the service delivered from? In particular, where is any monitoring or operations centre that reaches your systems remotely?
  • Which certifications does it hold, and what is the scope? Ask for the certificate and the statement of scope, not a logo.
  • Who can reach your data? How are engineers vetted, and how is privileged access controlled and logged?
  • Which subcontractors are involved, and are your requirements passed down to them?
  • How will you hear about an incident, how fast, and in what form?
  • What happens at exit? How and when your data is returned in a usable format and then removed.

We expect these questions from our own customers and answer them. Ask us for our ISO 27001 certificate and scope, and for exactly where any service you buy from us is delivered.

Keep a provider register

A register turns a set of contracts into oversight. For each provider, record what they do for you, the data they touch, the criticality, the contract and its clauses, the owner on your side, the date of the last review and the date of the next. Review critical providers more often than minor ones. This is our recommended practice, not a regulator’s template.

Sources and further reading

Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Must our managed security provider’s SOC be in Saudi Arabia?

Control 4-1-3-2 of ECC-2:2024 says cybersecurity managed service centres for monitoring and operations that use remote access must be fully located in the Kingdom. It applies to entities within the ECC’s scope. Ask each provider where its centre is.

What must an IT provider contract include under ECC?

As a minimum: non-disclosure and secure data removal at the end of service, incident communication procedures, and an obligation to apply your cybersecurity requirements and the relevant legislation.

Does SAMA cover third parties?

Yes. The SAMA Cyber Security Framework has a dedicated domain, 3.4 Third Party Cyber Security.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
NCA ECC

NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence

A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
6 min read · Reviewed 20 September 2026
SAMA

SAMA Cyber Security Framework: what Saudi financial institutions need to evidence

Who the SAMA Cyber Security Framework applies to, its four domains, the maturity level SAMA expects and the IT evidence a member organisation keeps.
3 min read · Reviewed 20 September 2026
Audit readiness

Audit readiness for NCA and SAMA reviews: the IT evidence checklist

How the NCA assesses ECC compliance, what control 1-8 requires, the evidence pack to build and how ISO 27001:2022 fits alongside.
3 min read · Reviewed 20 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.