Regulated industries

The managed IT partner for regulated organisations in Saudi Arabia.

Banks, government-linked entities, healthcare providers and critical-facility operators answer to regulators, auditors and customers. Cre8 IT runs the IT and security controls they expect, keeps the evidence, and is itself certified to ISO 27001:2022.
Sectors

Built for organisations that answer to a regulator

Each sector has the same day-to-day IT needs as anyone, plus a regulator or a customer who will ask how it is run.

Banking and financial services

Banks, insurers, finance companies and other firms that answer to SAMA and need to evidence the Cyber Security Framework.

Government and critical infrastructure

Government-affiliated entities and operators of critical national infrastructure working to the NCA’s ECC-2:2024.

Healthcare

Hospitals, clinics and health-technology firms protecting sensitive patient data under the PDPL.

Energy, utilities and industrial

Operators of critical facilities, where the IT estate connects to operational technology.
Location

Firms in the King Abdullah Financial District

The district does not set its own rules, but firms there share the same questions.

IT for firms in KAFD

Managed IT and cyber security for financial firms and regional headquarters in Riyadh’s financial district, with evidence for the regulators that apply to you.
Three sets of rules

Saudi regulators and frameworks at a glance

They overlap, and each has its own scope. Which ones apply to you depends on your sector, your licence and whether you run critical national infrastructure.
NCA: Essential Cybersecurity Controls (ECC-2:2024)SAMA: Cyber Security FrameworkSDAIA: Personal Data Protection Law (PDPL)
Who it applies toGovernment agencies and their affiliated entities, and private entities that own, operate or host critical national infrastructureBanks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructureControllers and processors of personal data within the law’s scope
StructureFour domains and 28 subdomainsFour domains (3.1 to 3.4)The law plus Implementing Regulations
What it expectsControls that are documented, implemented and periodically reviewed, assessed by self-assessment, compliance tool and auditsMaturity level 3 or higher: structured and formalizedBreach notice to SDAIA within 72 hours; fines up to SAR 5 million
Read the guideNCA ECC-2:2024 guideSAMA framework guidePDPL IT checklist

Summary for orientation, checked against the regulators’ published text on 20 September 2026. Confirm the current wording with the regulator. This is not legal advice.

What we do

Six things regulated organisations need from an IT partner

A regulator-ready baseline

Identity, devices, patching, backup and logging configured to the expectations in the NCA’s ECC-2:2024 and the SAMA framework.

Microsoft 365 and cloud governance

Conditional Access, managed devices, controlled sharing, labels, retention and logging that you can evidence.

PDPL technical measures

Access control, encryption, logging and a rehearsed 72-hour breach process.

Audit readiness

A standing evidence pack, regular reports and a mock audit, so requests are answered in minutes.

Third-party oversight

A provider register, due diligence and contract terms, including where remote monitoring services are delivered from.

Incident readiness

A written, exercised plan, clear roles and a route to each regulator’s reporting requirements.
Why Cre8 IT

Certified, experienced and open to scrutiny

Cre8 IT was founded in Dubai in 2012 and now supports businesses in the UAE, Saudi Arabia and the UK, with an office in Riyadh. In Saudi Arabia we support Union Bancaire Privée KSA, which is licensed by the Capital Market Authority.
Regulated organisations should ask hard questions of their IT provider. Ask for our certificate and its scope, how we vet and supervise engineers, how we control privileged access and where each service is delivered from. We expect the questions and answer them.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Insights

Read the guides

Sourced to the regulators’ own text and dated, so you know how current they are.
NCA ECC

NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence

A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
6 min read · Reviewed 20 September 2026
SAMA

SAMA Cyber Security Framework: what Saudi financial institutions need to evidence

Who the SAMA Cyber Security Framework applies to, its four domains, the maturity level SAMA expects and the IT evidence a member organisation keeps.
3 min read · Reviewed 20 September 2026
PDPL

Saudi PDPL: an IT checklist for the Personal Data Protection Law

What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
4 min read · Reviewed 20 September 2026
Cloud and Microsoft 365

Microsoft 365 and cloud governance for Saudi organisations

What the NCA’s cloud controls say, where data localisation now sits, what Microsoft has announced for Saudi Arabia and the Microsoft 365 settings to keep.
3 min read · Reviewed 20 September 2026
Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026
Audit readiness

Audit readiness for NCA and SAMA reviews: the IT evidence checklist

How the NCA assesses ECC compliance, what control 1-8 requires, the evidence pack to build and how ISO 27001:2022 fits alongside.
3 min read · Reviewed 20 September 2026
FAQ

Common questions from regulated organisations

What is a managed service provider for regulated organisations?

A managed service provider (MSP) runs an organisation’s IT and security as an ongoing service. For a regulated organisation it should also produce the evidence regulators, auditors and customers expect. Because you remain accountable for outsourced services, contracts, reporting and certifications matter as much as response times.

Does using Cre8 IT make us compliant?

No provider can make you compliant. You remain responsible for your obligations. We run and evidence the technical controls, help you prepare for reviews, and expect you to oversee us as you would any provider.

Which Saudi frameworks might apply to us?

It depends on your sector and licence. The NCA’s ECC-2:2024 is binding on government agencies and their affiliated entities and on private entities running critical national infrastructure. The SAMA Cyber Security Framework covers banks, insurers, financing companies, credit bureaus and financial market infrastructure. The PDPL applies to organisations handling personal data within its scope. Your compliance lead should confirm which apply.

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.