If your company has six employees and does not think of itself as a technology business, the National Cybersecurity Authority now has a file open on you anyway. In January 2026, the NCA published NCNICC-1:2025, and it quietly erased the assumption that its rules only apply to government entities and critical infrastructure operators. They now apply to almost every private company in the Kingdom.
Most coverage of this framework reads like a press release. A new standard exists, it is mandatory, here is a checklist. What gets skipped is the part that actually matters to a business owner in Jeddah or Dammam: which class you fall into, what that class actually has to do, and how ISO 27001, a standard you may already be circling for a tender, fits into an evidence trail the NCA can ask to see.
What changed, and why it caught so many businesses off guard
Contents
- 1 What changed, and why it caught so many businesses off guard
- 2 Class A and Class B: the split that decides your workload
- 3 Where NCNICC-1:2025 actually sits next to ISO 27001
- 4 Who this actually affects, beyond the obvious IT crowd
- 5 A practical first move, not a compliance essay
- 6 Frequently Asked Questions
- 7 Where to start if this applies to you
For years, the NCA’s flagship framework, the Essential Cybersecurity Controls, applied to two groups: government entities and organizations operating Critical National Infrastructure. Everyone else assumed the NCA was someone else’s regulator.
NCNICC-1:2025, formally the Cybersecurity Controls for Non-CNI Private Sector Entities, closed that gap. It is the NCA’s first framework built specifically for ordinary private companies that are not CNI operators, and the NCA has been explicit that it is binding regulation, not guidance. If your business operates digital systems, handles data, or provides online services, and you are not already under ECC-2:2024 as a CNI operator, you are very likely in scope.
That description covers a wide slice of the Saudi economy: SaaS providers, e-commerce platforms, manufacturers, retailers, logistics and supply chain operators, professional services firms, and startups. It also, notably, covers many of the same businesses currently pursuing ISO 9001 for Etimad tenders or ISO 45001 for Aramco vendor status, who assumed cybersecurity regulation was a problem for banks and telecoms.
Class A and Class B: the split that decides your workload
NCNICC-1:2025 sets 65 main controls across 22 sub-components, organized under three domains: Cybersecurity Governance, Cybersecurity Defense, and Third-Party and Cloud Computing Cybersecurity. Which of those 65 controls are mandatory for you depends on which class your business falls into.
| Classification | Size threshold | Mandatory controls | Recommended controls |
|---|---|---|---|
| Class A, Large entities | More than 250 employees, or more than SAR 200 million annual revenue | All 65 main controls (100 percent) | None, all mandatory |
| Class B, Small and Medium | 6 to 249 employees, or SAR 3 million to SAR 200 million annual revenue | 26 main controls, concentrated in Cybersecurity Defense | 39 controls |
A few details matter more than the headline numbers:
Class B is not a lighter version of the same requirement, it is a different scope. All 26 mandatory controls sit inside the Cybersecurity Defense domain, across 13 of its 15 sub-components. Governance and Third-Party/Cloud requirements are largely recommended rather than mandatory for Class B, which means a small business’s real, enforceable obligation is technical: things like multi-factor authentication, encryption, backups, and endpoint protection, not board-level policy architecture.
Class A brings a structural requirement most companies have never had to meet. Large entities must establish a cybersecurity unit independent of IT, define a formal risk management methodology, and undergo regular independent audits. That is a governance and staffing decision, not a software purchase.
There is genuinely no published compliance deadline yet. That is often read as breathing room. It is closer to the opposite. NCA inspectors can conduct unannounced reviews under existing enforcement powers, and penalties for NCA non-compliance already run up to SAR 25 million, a ceiling in effect since December 2024. Organizations that wait for a deadline to be announced before starting a gap assessment risk finding themselves short on time once one is, since several Class A controls, particularly around segmentation and monitoring infrastructure, require procurement and vendor lead time that cannot be compressed.
Micro-enterprises below the six-employee or SAR 3 million threshold are outside mandatory scope for now. The NCA still encourages voluntary adoption, and given how the framework has already expanded once, treating that threshold as permanent would be optimistic.
Where NCNICC-1:2025 actually sits next to ISO 27001
This is the part almost every article on this topic skips, and it is the part that matters most if you are already an ISO consultancy client or considering becoming one.
NCNICC-1:2025 does not replace ISO 27001. It is a Saudi national baseline, issued by a government regulator, with enforcement teeth. ISO 27001 is an international management system standard, issued by a certification body, that gives you the governance structure to run an information security program in the first place.
Here is the practical relationship:
- ISO 27001 gives you the system. NCNICC-1:2025 gives you the specific controls that system has to produce evidence for. An ISO 27001-certified organization already runs risk assessments, maintains a Statement of Applicability, and holds internal audits and management reviews. That is precisely the structure the NCA expects to see backing up a Class A or Class B control set.
- Organizations already running ISO 27001 or a NIST-based program typically find NCNICC-1:2025 easier to map, not harder to build from scratch. The control mapping exercise, matching your existing Annex A controls against NCNICC-1:2025’s Governance, Defense, and Third-Party domains, is a gap analysis a certified organization can run in weeks, not months.
- NCNICC-1:2025 is not itself a certification you can be awarded. There is no NCNICC certificate to frame. The NCA expects organizations to self-assess, maintain evidence, and be ready to demonstrate compliance through self-assessment, NCA-approved third-party audit, or direct NCA inspection. ISO 27001 certification is the closest thing to independent, third-party proof that your security program is real, which is exactly the kind of evidence a customer, partner, or NCA inspector will ask for when NCNICC-1:2025 compliance is reviewed.
For a Class B business specifically, this changes the order of operations. Instead of building 26 mandatory technical controls in isolation and hoping they hold together, wrapping them inside an ISO 27001-aligned Information Security Management System gives you the documentation, risk register, and internal audit cadence that turns a control checklist into something defensible under review.
Who this actually affects, beyond the obvious IT crowd
SaaS and technology companies. The most exposed group, and the one already assumed to be in scope. If you have not run a Class A versus Class B classification exercise yet, this is overdue.
E-commerce and retail platforms handling customer payment and personal data. Digital services and data handling are named applicability triggers, independent of whether the business considers itself a tech company.
Manufacturers and industrial operators, including Aramco and SABIC vendor networks. Many of these organizations are simultaneously working through ISO 9001 and ISO 45001 for vendor prequalification. Their IT and OT environments, particularly anything cloud-connected or third-party managed, fall inside NCNICC-1:2025’s Third-Party and Cloud Computing Cybersecurity domain.
Professional services and logistics firms with 6 or more employees. The lower Class B threshold is easy to clear. A firm with 15 employees and SAR 8 million in revenue is squarely inside mandatory scope, whether or not anyone in the business has thought about it yet.
Financial institutions. These face an additional layer entirely. SAMA-regulated banks and insurers must meet the SAMA Cybersecurity Framework on top of the NCA baseline. SAMA’s framework does not replace NCNICC-1:2025, it sits alongside it.
A practical first move, not a compliance essay
The organizations that avoid a scramble later are the ones that classify themselves now, before a deadline forces the question. In practice that means:
- Confirm your Class A or Class B status against the employee count and revenue thresholds above. Groups with multiple subsidiaries may find some entities land in Class A and others in Class B.
- Run a control-level gap assessment, mapped against your mandatory control set specifically, not the full 65 if you are Class B.
- Check what you already have. If you hold, or are pursuing, ISO 27001 certification, most of the governance and risk assessment groundwork already exists. The gap is usually narrower than businesses expect.
- Treat this alongside PDPL, not instead of it. Saudi Arabia’s Personal Data Protection Law, enforced by SDAIA, runs on its own track and covers personal data handling specifically. A business that handles customer data is very likely managing both obligations at once.
Frequently Asked Questions
What is NCNICC-1:2025?
NCNICC-1:2025, the Cybersecurity Controls for Non-CNI Private Sector Entities, is a framework published by Saudi Arabia’s National Cybersecurity Authority in January 2026. It sets mandatory baseline cybersecurity requirements for private sector organizations that do not operate Critical National Infrastructure, a group that previously fell outside NCA’s mandatory scope entirely.
Who does NCNICC-1:2025 apply to?
Any non-CNI private sector entity in Saudi Arabia with 6 or more employees, or SAR 3 million or more in annual revenue, falls into mandatory scope as either Class A or Class B. This covers technology companies, e-commerce platforms, manufacturers, retailers, logistics operators, professional services firms, and startups, essentially any business handling data or operating digital systems above the micro-enterprise threshold.
What is the difference between Class A and Class B under NCNICC-1:2025?
Class A applies to large entities with more than 250 employees or more than SAR 200 million in annual revenue, and requires all 65 main controls, including an independent cybersecurity unit and regular independent audits. Class B applies to small and medium entities with 6 to 249 employees or SAR 3 million to SAR 200 million in revenue, and requires 26 mandatory controls concentrated in the Cybersecurity Defense domain, with the remaining 39 controls recommended rather than mandatory.
Does ISO 27001 satisfy NCNICC-1:2025 requirements?
Not automatically, but ISO 27001 does not replace NCNICC-1:2025 either. NCNICC-1:2025 is a Saudi national regulatory framework with its own control set, while ISO 27001 is an international management system standard. Organizations already certified to ISO 27001 typically find it significantly faster to map their existing controls against NCNICC-1:2025’s requirements than to build a compliance program from nothing, since the risk assessment, documentation, and audit structure ISO 27001 requires is the same structure NCA compliance evidence relies on.
Is there a compliance deadline for NCNICC-1:2025?
No official deadline has been publicly announced as of mid-2026. This is not a grace period. NCA inspectors can conduct unannounced reviews under existing enforcement authority, and penalties for NCA non-compliance already carry a ceiling of SAR 25 million. Businesses that delay a gap assessment risk running short on the procurement and implementation time some technical controls require once a deadline is eventually set.
Where to start if this applies to you
Intellitech has certified 200+ organizations across Saudi Arabia over 7+ years, with a 45+ consultant bench, from our Al Jubail headquarters in the Eastern Province. If you are pursuing ISO 27001 certification for a tender, an Aramco or SABIC vendor requirement, or simply to get ahead of NCNICC-1:2025 before a deadline is set, we build the ISMS with your NCA classification and control mapping in mind from the first gap analysis, not as an afterthought.
Book a free gap analysis or call +966 59 731 4200. If your business also touches financial services, healthcare data, or Aramco vendor networks, our full range of ISO standards covers the adjacent ground too, including ISO 22301 for business continuity and ISO 9001 for Etimad and Aramco vendor scoring.



