Wadira: Find your way through Saudi data & privacy law.
Home › Frameworks › Cybersecurity › Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024)
| Type | Guideline |
|---|---|
| Issuing authority | National Cybersecurity Authority (NCA) |
| Framework | Cybersecurity |
| Tier | Guidelines & circulars |
| Legal status | Guidance |
The Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024) are National Cybersecurity Authority guidance on securing Internet of Things technologies, published as a public (TLP: White) document.
The guidelines follow the domain model familiar from the NCA's control sets, organised into four main domains (cybersecurity governance, cybersecurity defence, cybersecurity resilience, and third-party and cloud computing cybersecurity), each broken into subdomains containing individual guidelines, with a coding scheme identifying each guideline by main domain, subdomain and number. As guidance rather than binding controls, they help organisations adopting IoT devices and services address risks across governance arrangements, defensive measures, resilience, and dependencies on third parties and cloud services. They sit alongside the NCA's binding control sets, such as the Essential Cybersecurity Controls (ECC), which remain the compliance baseline for in-scope entities.
Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13