| NCA: Essential Cybersecurity Controls (ECC-2:2024) | SAMA: Cyber Security Framework | SDAIA: Personal Data Protection Law (PDPL) | |
|---|---|---|---|
| Who it applies to | Government agencies and their affiliated entities, and private entities that own, operate or host critical national infrastructure | Banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructure | Controllers and processors of personal data within the law’s scope |
| Structure | Four domains and 28 subdomains | Four domains (3.1 to 3.4) | The law plus Implementing Regulations |
| What it expects | Controls that are documented, implemented and periodically reviewed, assessed by self-assessment, compliance tool and audits | Maturity level 3 or higher: structured and formalized | Breach notice to SDAIA within 72 hours; fines up to SAR 5 million |
| Read the guide | NCA ECC-2:2024 guide | SAMA framework guide | PDPL IT checklist |
Summary for orientation, checked against the regulators’ published text on 20 September 2026. Confirm the current wording with the regulator. This is not legal advice.
