NCA-NCNICC 2025

Background
share close

The NCA NCNICC Framework (NCNICC-1:2025) is a cybersecurity regulatory standard issued by the National Cybersecurity Authority to strengthen cyber resilience across Saudi Arabia’s private sector. It specifically applies to non–critical national infrastructure (Non-CNI) organizations and establishes mandatory baseline cybersecurity controls to protect systems, data, and operations. The framework is structured around three key pillars—Cybersecurity Governance, Cybersecurity Defense, and Third-Party & Cloud Security—ensuring organizations implement risk management, technical safeguards, and secure external partnerships. As part of Saudi Arabia’s Vision 2030 digital transformation, NCNICC is a compliance-driven framework that promotes data protection, business continuity, and standardized cybersecurity practices across enterprises of all sizes.