Quick answer
Saudi Arabia has two main cybersecurity rules. One is NCA ECC. The other is SAMA CSF. Two different groups made these rules. NCA ECC covers government bodies. It also covers key infrastructure and many businesses. SAMA CSF covers banks and other money firms. Some firms must follow both rules. Following one rule does not mean you follow the other. Pick the wrong rule, and you could waste months building the wrong controls. This guide helps you find the right one, fast.
Quick Comparison: NCA ECC vs SAMA CSF
Here is a simple side-by-side view of the two rulebooks.
| NCA ECC | SAMA CSF | |
|---|---|---|
| Who made it | National Cybersecurity Authority | Saudi Central Bank |
| Who must follow it | Government, key infrastructure, many businesses | Banks, insurers, fintechs, payment firms |
| Number of controls | 108 main controls + 92 sub-controls | 32 subdomains |
| Watch-your-systems rule | Control 2-12: SIEM plus steady log checks | Subdomain 3.14: SIEM plus a 24/7 SOC |
| How long to keep logs | 12 months (18 for key systems) | Based on your risk class, no fixed number |
| How you get graded | Pass or fail | 6-level scale, 0 to 5 |
| Need a special license? | Yes — Tier 1 or Tier 2 MSOC license | No, the firm carries the duty itself |
| Do the two rules link up? | No | No |
| One check for both? | No | No |
Two Rules. Two Regulators. Two Very Different Jobs.
Saudi Arabia has two main cybersecurity regulators.
- The National Cybersecurity Authority (NCA) watches cybersecurity across the whole country.
- The Saudi Central Bank (SAMA) watches banks and money firms only.
These two groups work independently. Their rules are not the same. Their checks are not the same. Passing one group's check does not satisfy the other.
What Is NCA ECC?
NCA ECC stands for Essential Cybersecurity Controls. It sets the base level of cyber safety for Saudi Arabia. The National Cybersecurity Authority built this rule. Government offices must follow it. So must key infrastructure sites. Many private firms must follow it too.
The current version is ECC-2:2024. It covers four main parts:
- Cybersecurity Governance covers who is in charge and how risk gets managed.
- Cyber Defense covers the tools that guard your systems.
- Cybersecurity Resilience covers staying up when something breaks.
- Third-Party and Cloud Security covers watching your vendors and cloud tools.
Other NCA Rules That May Apply
NCA ECC is just the start. More rules may stack on top, depending on what your firm does.
- CSCC applies to systems marked “critical.” It needs 18 months of logs, plus round-the-clock monitoring, file checks, and user-behavior checks.
- CCC applies to cloud services.
- OTCC applies to factory and plant systems.
- DCC applies to data protection.
- TCC applies to staff who work from home.
Think of ECC as the floor. Other rules stack on top when they fit your case.
What NCA ECC Says About Watching Your Systems
Control 2-12 is the big rule for security teams. It says you must:
- Use a SIEM tool to gather and check your security logs
- Watch your logs all the time, not just once a week
- Keep logs for at least 12 months. Keep them for 18 months for a "critical" system.
Not sure what a SIEM is? Not sure what one should cost? Our guide breaks it down in plain words.
What If You Run an MSSP?
An MSSP handles security for other firms. NCA has a special license track for this. It's called MSOC licensing. It splits into Tier 1 and Tier 2. NCA ECC is still your main rulebook.
Do you run many clients on one SIEM platform? Multi-Tenant SIEM for MSSPs: A Full Guide shows you how to keep each client's data apart. It also shows you how to keep your costs in check.
What Is SAMA CSF?
SAMA CSF stands for Cyber Security Framework. The Saudi Central Bank built it. It only applies to financial firms that SAMA watches. Think banks, insurers, and payment firms.
Who Must Follow SAMA CSF?
Your firm must follow SAMA CSF if it is any of these:
- A regular or Islamic bank
- An insurance or reinsurance firm
- A financing company
- A payment service firm
- A money exchange shop
- A credit bureau
- A fintech firm with a SAMA license
SAMA CSF covers your whole firm. That means your systems, your staff, and your steps. It even covers the outside vendors you use.
How SAMA CSF Is Built
SAMA CSF has 4 main domains. Those split into 32 smaller subdomains:
- Leadership and Governance (7 subdomains)
- Risk Management and Rule-Following (5 subdomains)
- Operations and Technology (17 subdomains, the biggest group)
- Third-Party Cyber Security (3 subdomains)
Subdomain 3.14, called Cyber Security Event Management, matters most for security teams. It asks for:
- A SIEM that gathers every security event in one place
- A SOC team. That's short for Security Operations Center. It checks alerts and reacts around the clock.
- Log storage that meets what the regulator expects
How SAMA Grades Your Cybersecurity
SAMA does not use a simple pass-or-fail test. It uses a 6-level scale.
| Level | Name | What It Means |
|---|---|---|
| 0 | Non-existent | No controls at all |
| 1 | Initial | Random, with no plan |
| 2 | Developing | Some controls, not steady |
| 3 | Defined | Written down and steady. This is SAMA's lowest pass. |
| 4 | Managed | Tracked and checked often |
| 5 | Optimizing | Always getting better |
Level 3 is the lowest pass. Subdomain 3.14 (Cyber Security Event Management) is a risky area. There, SAMA wants Level 4. That's the highest bar SAMA sets for most areas.
Note: Some old sources say SAMA CSF uses 4 levels. That's out of date. The real scale has 6 levels now. Always check SAMA's own papers before you use any numbers in an audit.
Who Needs to Follow Which Rule?
Here is the short version:
- NCA ECC applies to government offices, key infrastructure, most private Saudi firms, and licensed MSSPs
- SAMA CSF applies to banks, insurers, payment firms, SAMA-licensed fintechs, and their vendors
Run a bank? SAMA CSF is your main rule. Run key national infrastructure? NCA ECC is yours. Some firms need both.
When Do You Need to Follow Both Rules?
Two cases come up most often.
Case 1: A Money Firm With Key Infrastructure
A Saudi bank is still a Saudi firm. Say NCA marks one of its systems as “key infrastructure.” Then NCA ECC rules apply too. This sits on top of SAMA CSF.
Case 2: MSSPs That Serve Money Firms
Say you hold an NCA MSOC license. But you also serve SAMA-watched clients. Your platform must still meet SAMA's Subdomain 3.14. Your clients' duties become your platform's job too.
Plan for both rules from the start if:
- You are a money firm marked as key infrastructure
- You are an MSSP serving SAMA-watched clients
Starting with one rule and adding the other later costs more. Gaps almost always show up at check time.
How to Figure Out Which Rule Applies to You
Work through these three steps.
- Step 1: Does SAMA watch your firm? (Banks, insurers, payment firms, SAMA-licensed fintechs) Yes → SAMA CSF applies. Go to Step 2. No → Go to Step 3.
- Step 2: Does NCA mark any of your systems as “critical”? Yes → Both NCA ECC and SAMA CSF apply. Plan for both. No → SAMA CSF is your main rule.
- Step 3: Are you an MSSP or a security operations firm? Yes, with SAMA-watched clients → NCA MSOC licensing covers your own firm. But your platform must also meet SAMA's Subdomain 3.14. Yes, running a general MSOC → NCA ECC applies, with a Tier 1 or Tier 2 MSOC license. No → NCA ECC likely applies if you're a Saudi firm.
Key point: Does SAMA watch you? Are you marked as key infrastructure too? Then plan for both rules from day one. Fixing it later costs a lot more.
Key Differences Between the Two Rules
Different Goals
NCA ECC guards Saudi Arabia's national cyber safety. This spans government, infrastructure, and business as a whole. SAMA CSF guards the money system alone. Different goals mean different rules.
Different Grading Systems
NCA ECC is pass or fail. You either meet the control, or you don't. SAMA CSF grades you on a 0 to 5 scale, with Level 3 as the lowest pass. These are very different ways to measure your work.
Different Log Storage Rules
NCA ECC gives you a fixed number. That's 12 months, or 18 for key systems. SAMA CSF says storage must “meet regulatory expectations.” It gives no fixed number. SAMA checks this case by case.
Vendor Duty Stays With You
Both rules say the same thing here. You are on the hook for what your vendors do. Handing your SIEM or SOC to a third party does not move that duty. It just adds one more relationship to manage.
Common Mistakes to Dodge
Mistake 1: Thinking “close to finance” means SAMA-watched
Not every firm near money gets watched by SAMA. Payment gateways, buy-now-pay-later apps, and some lending platforms may sit outside SAMA's watch. That's true unless they hold a real SAMA license. Always check first.
Mistake 2: Thinking one rule covers both
There is no shortcut here. Passing NCA ECC does not mean you satisfy SAMA CSF. Passing SAMA CSF does not mean you satisfy NCA ECC. Each regulator checks its own rule, on its own.
Mistake 3: Thinking outsourcing removes your duty
Say you hand your SIEM or SOC to a vendor. You still carry the duty to follow the rule. The vendor just adds one more relationship to manage. Your duty stays the same.
What Both Rules Need From Your Security Tools
Both NCA ECC and SAMA CSF need the same core things from your setup:
- A SIEM that gathers and watches your logs
- A SOC that reacts fast and fixes alerts
- Log storage you can show a regulator on request
The fine print differs. NCA gives you a time limit. SAMA gives you a maturity score. But the core need is the same for both.
The most common cost problem: many firms rent a SIEM tool. It charges by how much data it stores. Every new client or system pushes the bill up. One MSSP fixed this. It moved to a platform it fully owned. The result? $270,000 saved over 24 months. Of that, $110,000 was saved in year one alone.
Own your SIEM, and there are no per-gigabyte fees. There's no vendor lock-in. You get full control of your log storage. Weighing your options? Open-Source vs. Custom-Built SIEM: The Real Trade-off walks through both paths honestly.
Frequently Asked Questions
Yes. This is most common for money firms marked as key infrastructure. It's also common for MSSPs that serve SAMA-watched clients. Each regulator checks on its own. There is no single combined check.
No. Two different regulators built these rules. They have different parts. They use different grading systems. Treat them as the same thing, and you'll leave real gaps.
No. There is no shared pass. There is no shared certificate. Need both? Then prove you meet both, one at a time.
114 controls belonged to the old version. That's ECC-1:2018. The current version is ECC-2:2024. It has 108 main controls, plus 92 smaller sub-controls. Always use the current version for audits.
NCA ECC is more exact. It's 12 months, or 18 for key systems. SAMA CSF gives no fixed number. It depends on your risk class. Neither one wins on "stricter" every time.
No. NCNICC is a lighter, separate NCA rule. It's for private firms not marked as key infrastructure. It covers a different group. It uses a different set of controls.
Both. Your NCA MSOC license covers your own firm. But your platform must also meet your clients' SAMA CSF rules. Subdomain 3.14 matters most here. That duty applies even if SAMA does not watch you directly.
For NCA ECC, check NCA's own published papers. For SAMA CSF, check SAMA's own framework notice. Always go to the primary source before you build a compliance plan.