ECC-2:2024 requires in-scope entities to set cybersecurity requirements for third-party contracts, and to include as a minimum non-disclosure and secure data removal, incident communication and an obligation to apply your requirements. For IT and cybersecurity managed services you must assess the risk before signing, and monitoring and operations centres that use remote access must be fully located in Saudi Arabia. SAMA’s framework has a dedicated third-party domain.
| Source | Requirement |
|---|---|
| ECC-2:2024 4-1-1 | Cybersecurity requirements for contracts and agreements with third parties are identified, documented and approved. |
| ECC-2:2024 4-1-2 | Contracts that could affect your data or services include, as a minimum: non-disclosure and secure removal of your data at the end of service; communication procedures for a cybersecurity incident; and an obligation on the third party to apply your cybersecurity requirements and policies and the relevant legislation. |
| ECC-2:2024 4-1-3 | For IT or cybersecurity outsourcing and managed services: a risk assessment and available mitigating controls before signing (4.1.3.1); and cybersecurity managed service centres for monitoring and operations that use remote access must be fully located in the Kingdom of Saudi Arabia (4.1.3.2). |
| ECC-2:2024 4-1-4 | Third-party cybersecurity requirements are reviewed periodically. |
| SAMA Cyber Security Framework 3.4 | A dedicated domain for third-party cyber security in the financial institutions the framework covers. |
We expect these questions from our own customers and answer them. Ask us for our ISO 27001 certificate and scope, and for exactly where any service you buy from us is delivered.
A register turns a set of contracts into oversight. For each provider, record what they do for you, the data they touch, the criticality, the contract and its clauses, the owner on your side, the date of the last review and the date of the next. Review critical providers more often than minor ones. This is our recommended practice, not a regulator’s template.
Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
