1. Home
  2. Cybersecurity rules your licence file must answer

Cybersecurity rules your licence file must answer

Three sets of rules shape a Saudi fintech's security set-up: the National Cybersecurity Authority's controls, the CST's cloud computing regulations and your financial regulator's own cyber framework. Which ones bind you depends on what you are and who you sell to.

Which framework applies to whom

FrameworkIssued byWho it bindsFintech relevance
Essential Cybersecurity Controls (ECC-2:2024)National Cybersecurity Authority (NCA)Government entities, and private entities that own or operate critical national infrastructureNot directly mandatory for most private fintechs; commonly used as the reference in bank and government procurement
Cloud Cybersecurity Controls (CCC-2:2024)NCACloud service providers and cloud tenants, extending the ECCA fintech hosted in the cloud should align with the tenant controls
Cloud Computing Services Provisioning Regulations (4th version)Communications, Space & Technology Commission (CST)Cloud service providers, in a tiered registration systemUse a CST-registered provider; a fintech selling SaaS may need to register itself
SAMA Cyber Security Framework; CMA cyber requirementsSAMA; CMATheir licenseesThe framework your regulator reads your application against

Who the ECC binds is taken from the NCA's own document. Its use in procurement, and the reach of the CST regime to providers abroad, come from secondary reporting.

The NCA Essential Cybersecurity Controls

The ECC is the NCA's baseline set of controls. The current edition, ECC-2:2024, is published on the NCA website with an English PDF. The English text sets out 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols. The Arabic edition is reported to count 110 main controls and 90 subcontrols, so when you build a control matrix, work from the edition your auditor or client will use and record the difference.

The ECC is mandatory for government entities and for private entities that own or operate critical national infrastructure. Most private fintechs fall outside that group and still end up meeting the ECC in practice. Banks and government clients tend to map their supplier security requirements to the ECC and CCC, and the frameworks of SAMA and the CMA cover overlapping ground. Building to the ECC structure early saves a second mapping exercise when your first enterprise client sends its security questionnaire.

Cloud: NCA tenant controls and CST registration

CCC-2:2024 extends the ECC to cloud computing, with controls for both cloud service providers and tenants. The NCA updated it for data-localisation changes. A fintech running on a public cloud is a tenant and should align with the tenant controls.

The CST regulates the providers. Its Cloud Computing Services Provisioning Regulations, in their fourth version, came into force on 10 October 2023, together with a Guide for Cloud Computing Service Providers and a Registration Guide for the Qualifying Category issued under Decision 506/1445. Providers register in tiers: a Qualifying Category and Classes A, B and C. Commentary on the regime says it also reaches providers serving Saudi subscribers from abroad.

Two things follow for a fintech. When you choose a provider, check that it is CST-registered, that its class fits the data you will host, and that its data location works for your PDPL transfer analysis and your regulator's outsourcing rules. If you sell software or hosting to Saudi customers yourself, check whether you fall within provider registration.

Your financial regulator's framework sits on top

SAMA has its own Cyber Security Framework for the firms it regulates, and the CMA has its own cyber requirements. Your licence application is read against your regulator's framework, and the detailed requirements are set in those texts, which this page does not summarise.

For planning, the useful point is the overlap. The NCA controls, the CST cloud rules and your regulator's framework ask many of the same questions about governance, access, cloud, third parties and incidents. One control set mapped to all of them is cheaper to run than three separate programmes, and it gives an examiner a single place to look.

What the licence file needs on cybersecurity

  • An information security policy set approved by the board, with named owners for each policy
  • A control matrix mapped to your regulator's framework and, where your clients or a CNI role require it, to ECC-2:2024
  • Cloud architecture and provider due diligence: CST registration and class, data location, and the CCC tenant controls
  • Outsourcing assessments for material technology vendors, consistent with your regulator's outsourcing rules
  • An incident response plan that covers regulator reporting and the 72-hour PDPL breach notice to SDAIA
  • A data map that supports the PDPL transfer analysis
  • Testing evidence, such as vulnerability scans, penetration tests and access reviews, or a dated plan to complete them before go-live

How we prepare the security section

  1. Scope the frameworks

    Your regulator's framework always applies. Add the ECC if you are CNI, serve government or sell to clients who demand it, and the CCC and CST checks if you use or provide cloud.

  2. Gap assessment

    Compare current controls with the combined control set and rank the gaps by whether they block the licence, a client contract or neither.

  3. Documents

    Policies, the control matrix, cloud and outsourcing assessments and the incident plan, in the form your regulator expects.

  4. Evidence

    Testing results a reviewer can check, or remediation plans with owners and dates.

  5. After licensing

    Keep the matrix current as the NCA, the CST or your regulator update their texts. See ongoing compliance.

Common questions

Are the NCA Essential Cybersecurity Controls mandatory for a private fintech?

Only for a fintech that owns or operates critical national infrastructure. Most private fintechs do not. Bank and government clients often expect ECC-aligned controls, though, and your financial regulator has its own framework.

How many controls are in ECC-2:2024?

The English PDF lists 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols. The Arabic edition is reported to count 110 main controls and 90 subcontrols.

Must our cloud provider be registered with the CST?

The CST's cloud regulations set up a tiered registration system for providers: a Qualifying Category and Classes A, B and C. Use a registered provider whose class and data location fit the data you host.

Could our own fintech need CST registration?

Possibly, if you provide cloud or SaaS services to customers in Saudi Arabia. Commentary on the regime says it can reach such a fintech, including one serving Saudi subscribers from abroad.

Primary sources

Last reviewed: 11 October 2026

General information, not legal advice. Saudi rules change; we confirm every requirement against the regulator's current text before you file.

Start with a 30-minute
licensing call

Tell us your model and where you are. We'll tell you which licence fits, what it takes and what we'd do first.

Book a consultation