Wadira: Find your way through Saudi data & privacy law.

HomeFrameworksCybersecurity › Cybersecurity Guidelines for E-commerce Service Providers (CGESP-1:2019)

Cybersecurity Guidelines for E-commerce Service Providers (CGESP-1:2019)

TypeGuideline
Issuing authorityNational Cybersecurity Authority (NCA)
FrameworkCybersecurity
TierGuidelines & circulars
Legal statusGuidance

The Cybersecurity Guidelines for E-commerce Service Providers (CGESP-1:2019) are National Cybersecurity Authority guidance to educate and assist small and medium enterprises (SMEs) and small office/home office (SoHo) e-commerce providers in the Kingdom in securing their business, devices, data, customer accounts and payment processes, issued as the E-commerce Law sought to strengthen trust in a fast-growing market.

The guidelines were developed from a study of national and international e-commerce cybersecurity guidance, cybersecurity best practices and analysis of previous incidents targeting e-commerce providers. They are organised into seven categories: using strong authentication; protecting e-commerce systems; minimising the impact of data breaches; guarding social media accounts used in e-commerce; defending the network; continuously educating and training employees; and strengthening the internal e-commerce infrastructure. A companion instrument, the Cybersecurity Guidelines for E-commerce Consumers (CGEC-1:2019), addresses the buyer side.

Documents

In this framework


Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13