Most enterprises in Saudi Arabia are not short on cybersecurity and data protection obligations — they are short on a single place that ties NCA ECC, the SAMA Cybersecurity Framework, and SDAIA's PDPL together into one practical checklist. Each governs a different layer of the same problem: how an organisation handles, secures, and is accountable for data and systems operating in the Kingdom.
NCA Essential Cybersecurity Controls (ECC)
The ECC remains the baseline cybersecurity standard for government, semi-government, and critical-sector entities operating in Saudi Arabia. It is organised around governance, defence, resilience, and third-party/cloud cybersecurity domains, with control-level requirements rather than abstract principles.
For most organisations the practical gap is not awareness of the ECC — it is evidence. NCA-aligned audits expect documented control implementation, not just a policy on paper. The most common shortfalls we see in assessments are around asset management, change management, and third-party risk controls, all of which require ongoing operational discipline rather than a one-time project.
If your organisation falls under NCA's regulated scope — government entities, critical infrastructure, or organisations handling sensitive national data — ECC compliance is not optional, and gaps surface quickly in formal audits or tender qualification stages.
SAMA Cybersecurity Framework
For banks, insurance companies, and finance companies regulated by the Saudi Central Bank, the SAMA Cybersecurity Framework sets out a more granular set of expectations, with maturity-level self-assessments and a strong emphasis on third-party and outsourcing risk — relevant given how much of the financial sector relies on external technology vendors and cloud providers.
The framework also expects continuous maturity improvement, not a static pass/fail. Organisations that treat their SAMA self-assessment as an annual compliance exercise, rather than an input into a roadmap, tend to plateau at the same maturity level year over year.
SDAIA's PDPL
The Personal Data Protection Law, administered by SDAIA, applies far more broadly than ECC or the SAMA framework — to any organisation processing the personal data of individuals in Saudi Arabia, regardless of sector. Core obligations include lawful basis for processing, data subject rights, breach notification, and restrictions on cross-border data transfer.
The cross-border transfer restrictions are the area generating the most operational questions, particularly for organisations using cloud AI services or SaaS platforms hosted outside the Kingdom. Before adopting any cloud-based tool that processes personal data — including most generative AI APIs — it is worth confirming where that data is processed and stored, and whether a data sovereignty exception or contractual safeguard applies.
Where these three frameworks overlap

In practice, the frameworks reinforce each other: NCA ECC's third-party cybersecurity controls, SAMA's outsourcing risk requirements, and PDPL's cross-border transfer rules all converge on the same question — what happens to your data and systems once a third party (often a cloud provider) is involved. Organisations that build a single vendor risk and data residency review process tend to satisfy all three with far less duplicated effort than treating them as separate compliance tracks.
If you are unsure which of these frameworks apply to your organisation, or where your current controls stand against them, that is usually the right starting point. Oasis Systems runs NCA ECC, SAMA CSF, and PDPL gap assessments for enterprises across the Kingdom — get in touch if you want a clear picture of where your organisation stands against all three.

