Wadira — Find your way through Saudi data & privacy law.

HomeFrameworksCybersecurity › Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025)

Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025)

TypeFramework
CodeNCNICC
Issuing authorityNational Cybersecurity Authority (NCA)
FrameworkCybersecurity
TierRules, controls & standards
Legal statusBinding
DatesIssued by the NCA (NCNICC-1:2025), published January 2026

The Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025) are the National Cybersecurity Authority's cybersecurity baseline for private-sector entities that are not classified as Critical National Infrastructure. They extend the NCA's ECC-derived control model to these entities across governance, defence and third-party/cloud domains. The controls are split into Category A (65 controls, for larger entities) and Category B (26 controls, for smaller entities).

Documents

Updates for this instrument

In this framework


Content and register data licensed CC BY 4.0 — cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-07-27