Security HubCompliance in Saudi Arabia and the UAE: NCA ECC and the IA Standards

Compliance in Saudi Arabia and the UAE: NCA ECC and the IA Standards

Netru Compliance7 min read

Gulf compliance is often described as opaque by people who have not looked. It is actually quite legible, with one structural difference from Europe that explains most of the confusion: the controls are set and assessed by national authorities rather than by commercial certification bodies, and they bind government and critical infrastructure directly while reaching everyone else through the supply chain.

Saudi Arabia: NCA Essential Cybersecurity Controls

The National Cybersecurity Authority publishes the Essential Cybersecurity Controls, organised into domains covering governance, defence, resilience, third-party and cloud, and industrial control systems. They are mandatory for government bodies and critical national infrastructure.

For a foreign supplier the route in is almost always through a customer. Saudi entities push these obligations down contractually, so you are asked to demonstrate alignment rather than to obtain a certificate. There is no NCA certificate for a UK software vendor to hold; there is an expectation that you can evidence the controls your customer is accountable for.

Financial services sit under the Saudi Central Bank framework instead, which is a separate and more prescriptive regime. If your customer is a bank or insurer, ask which applies before assuming.

The practical work for an ISO 27001 organisation is mapping rather than building. The control coverage overlaps heavily. What differs is the emphasis on data residency expectations, on cloud controls, and on being able to answer at control level rather than pointing at a certificate.

United Arab Emirates: Information Assurance Standards and the sector variants

The UAE Information Assurance Standards, often still referred to by the older NESA name, define a large control set applied at a priority tier the entity itself determines based on its risk. That tiering is the piece overseas suppliers most often miss: two customers can both be compliant while requiring materially different things of you.

Sector and emirate variants sit on top. Abu Dhabi healthcare has its own standard, and Dubai government entities have their own information security regulation. Asking which regime applies is not pedantry, it changes the answer.

The federal data protection law adds a privacy layer that will feel broadly familiar from GDPR: lawful basis, individual rights, breach notification, and controls on cross-border transfer. It is newer and less tested, so the practical expectation from customers is currently more about demonstrable capability than about case law.

What ISO 27001 buys you here

More than in most markets. Both regimes are recognisably built on the same lineage, and an organisation with a mature management system will find the majority of controls already operating. Gulf procurement also treats ISO 27001 as a strong baseline credential in its own right, more so than the United States does.

What it does not do is answer at the granularity these frameworks are assessed at. A certificate says a management system works. A Saudi or UAE customer will send a control matrix and expect a response per line, and the evidence to support it. The gap is documentation and traceability rather than security.

Data residency deserves separate thought. Both markets have expectations, in some sectors requirements, about where data is stored and processed. This is the single item most likely to require an architectural change rather than a documentation exercise, and it is worth establishing early because it can affect pricing.

A realistic sequence

Get ISO 27001 first if you do not hold it. It is the common denominator across both markets and it makes every subsequent conversation an exercise in mapping.

Ask each customer which regime and which tier applies to them, in writing. The answer determines the control set, and guessing is expensive.

Resolve the data residency question before contracting, because retrofitting a regional deployment after signing is the most common source of overrun in Gulf projects.

Then prepare a control-level response pack rather than a certificate. What wins these engagements is the ability to answer line by line, quickly, with evidence.

Related services

Talk to an engineer

We respond to every enquiry within one business day, and return a scoped proposal with fixed pricing within 48 hours.

Book a discovery call