Which framework applies to whom
| Framework | Issued by | Who it binds | Fintech relevance |
|---|---|---|---|
| Essential Cybersecurity Controls (ECC-2:2024) | National Cybersecurity Authority (NCA) | Government entities, and private entities that own or operate critical national infrastructure | Not directly mandatory for most private fintechs; commonly used as the reference in bank and government procurement |
| Cloud Cybersecurity Controls (CCC-2:2024) | NCA | Cloud service providers and cloud tenants, extending the ECC | A fintech hosted in the cloud should align with the tenant controls |
| Cloud Computing Services Provisioning Regulations (4th version) | Communications, Space & Technology Commission (CST) | Cloud service providers, in a tiered registration system | Use a CST-registered provider; a fintech selling SaaS may need to register itself |
| SAMA Cyber Security Framework; CMA cyber requirements | SAMA; CMA | Their licensees | The framework your regulator reads your application against |
Who the ECC binds is taken from the NCA's own document. Its use in procurement, and the reach of the CST regime to providers abroad, come from secondary reporting.
The NCA Essential Cybersecurity Controls
The ECC is the NCA's baseline set of controls. The current edition, ECC-2:2024, is published on the NCA website with an English PDF. The English text sets out 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols. The Arabic edition is reported to count 110 main controls and 90 subcontrols, so when you build a control matrix, work from the edition your auditor or client will use and record the difference.
The ECC is mandatory for government entities and for private entities that own or operate critical national infrastructure. Most private fintechs fall outside that group and still end up meeting the ECC in practice. Banks and government clients tend to map their supplier security requirements to the ECC and CCC, and the frameworks of SAMA and the CMA cover overlapping ground. Building to the ECC structure early saves a second mapping exercise when your first enterprise client sends its security questionnaire.
Cloud: NCA tenant controls and CST registration
CCC-2:2024 extends the ECC to cloud computing, with controls for both cloud service providers and tenants. The NCA updated it for data-localisation changes. A fintech running on a public cloud is a tenant and should align with the tenant controls.
The CST regulates the providers. Its Cloud Computing Services Provisioning Regulations, in their fourth version, came into force on 10 October 2023, together with a Guide for Cloud Computing Service Providers and a Registration Guide for the Qualifying Category issued under Decision 506/1445. Providers register in tiers: a Qualifying Category and Classes A, B and C. Commentary on the regime says it also reaches providers serving Saudi subscribers from abroad.
Two things follow for a fintech. When you choose a provider, check that it is CST-registered, that its class fits the data you will host, and that its data location works for your PDPL transfer analysis and your regulator's outsourcing rules. If you sell software or hosting to Saudi customers yourself, check whether you fall within provider registration.
Your financial regulator's framework sits on top
SAMA has its own Cyber Security Framework for the firms it regulates, and the CMA has its own cyber requirements. Your licence application is read against your regulator's framework, and the detailed requirements are set in those texts, which this page does not summarise.
For planning, the useful point is the overlap. The NCA controls, the CST cloud rules and your regulator's framework ask many of the same questions about governance, access, cloud, third parties and incidents. One control set mapped to all of them is cheaper to run than three separate programmes, and it gives an examiner a single place to look.
What the licence file needs on cybersecurity
- An information security policy set approved by the board, with named owners for each policy
- A control matrix mapped to your regulator's framework and, where your clients or a CNI role require it, to ECC-2:2024
- Cloud architecture and provider due diligence: CST registration and class, data location, and the CCC tenant controls
- Outsourcing assessments for material technology vendors, consistent with your regulator's outsourcing rules
- An incident response plan that covers regulator reporting and the 72-hour PDPL breach notice to SDAIA
- A data map that supports the PDPL transfer analysis
- Testing evidence, such as vulnerability scans, penetration tests and access reviews, or a dated plan to complete them before go-live
How we prepare the security section
Scope the frameworks
Your regulator's framework always applies. Add the ECC if you are CNI, serve government or sell to clients who demand it, and the CCC and CST checks if you use or provide cloud.
Gap assessment
Compare current controls with the combined control set and rank the gaps by whether they block the licence, a client contract or neither.
Documents
Policies, the control matrix, cloud and outsourcing assessments and the incident plan, in the form your regulator expects.
Evidence
Testing results a reviewer can check, or remediation plans with owners and dates.
After licensing
Keep the matrix current as the NCA, the CST or your regulator update their texts. See ongoing compliance.
Common questions
Are the NCA Essential Cybersecurity Controls mandatory for a private fintech?
Only for a fintech that owns or operates critical national infrastructure. Most private fintechs do not. Bank and government clients often expect ECC-aligned controls, though, and your financial regulator has its own framework.
How many controls are in ECC-2:2024?
The English PDF lists 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols. The Arabic edition is reported to count 110 main controls and 90 subcontrols.
Must our cloud provider be registered with the CST?
The CST's cloud regulations set up a tiered registration system for providers: a Qualifying Category and Classes A, B and C. Use a registered provider whose class and data location fit the data you host.
Could our own fintech need CST registration?
Possibly, if you provide cloud or SaaS services to customers in Saudi Arabia. Commentary on the regime says it can reach such a fintech, including one serving Saudi subscribers from abroad.
Primary sources
Last reviewed: 11 October 2026
General information, not legal advice. Saudi rules change; we confirm every requirement against the regulator's current text before you file.



