
NCA ECC Compliance in Saudi Arabia: A Practical Guide for 2026
Who the Essential Cybersecurity Controls apply to, how they are structured, the governance requirements that trip organisations up, and a phased route to demonstrable compliance.
The four domains, the six-level maturity model and why “level 3” is about formalisation, not technology — with a practical view of the evidence reviewers expect.

The SAMA Cyber Security Framework was issued by the Saudi Central Bank (SAMA) to strengthen cyber resilience across the financial sector. It applies to SAMA-regulated member organisations, including banks, insurance and reinsurance companies, finance companies, credit bureaus and financial market infrastructure.
The framework is principle-based. It sets out what must be achieved and how maturity will be judged, and leaves organisations to decide how to implement controls appropriate to their size and risk.
| Level | Name | What it means in practice |
|---|---|---|
| 0 | Non-existent | No documented or implemented control |
| 1 | Ad-hoc | Some activity exists, but it is informal and inconsistent |
| 2 | Repeatable but informal | Activity is repeated, but not formally documented or approved |
| 3 | Structured and formalised | Documented, approved and implemented consistently |
| 4 | Managed and measurable | Performance is measured, reviewed and improved |
| 5 | Adaptive | Continuously improved and adapted to a changing threat landscape |
Member organisations are expected to achieve at least level 3 across the framework. Higher levels are appropriate where risk, size or criticality demand it.
Level 3 is often misunderstood as a technology target. It is a formalisation target. For each control area, reviewers look for four things:
A control that works well but is undocumented is level 2. A beautifully documented control that is not implemented is also not level 3. Both halves are required.
SAMA-regulated organisations often also answer to the NCA, PDPL, PCI DSS and international standards. Designing one control framework mapped to all of them allows a single test to satisfy several requirements, and gives leadership one coherent view of cyber risk instead of several competing ones.
Level 3 is the expected minimum, not the finish line. Moving to level 4 — managed and measurable — means controls are measured, reviewed and improved on the basis of evidence. In practice that requires key performance and risk indicators for important control areas, regular reporting to the cybersecurity committee, and documented decisions taken as a result.
For larger or more critical institutions, reaching level 4 in areas such as identity and access management, vulnerability management, event monitoring and third-party security gives leadership a measurable view of risk and demonstrates to SAMA that the programme is actively managed rather than periodically documented.

Who the Essential Cybersecurity Controls apply to, how they are structured, the governance requirements that trip organisations up, and a phased route to demonstrable compliance.

The Personal Data Protection Law has been fully enforceable since September 2024. A practical checklist of what controllers must have in place — and evidence.

A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.