NCA NCNICC compliance: key takeaways from the webinar

Yulia Kondrashova

Content and Community Manager at Axidian

Axidian recently hosted a webinar on how private-sector organizations in Saudi Arabia can approach compliance with the new NCA Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC – 1:2025).

The 40-minute session was led by Georgy Ovanesyan, CEO at Axidian and ISO/IEC 27001 ISMS Lead Auditor, and Mouadh Chaabani, Senior Presales Engineer at Axidian.

Together, they turned the regulation into a practical compliance roadmap: how to organize the required documentation, distinguish mandatory controls from recommended measures, build a cybersecurity calendar, and choose the technologies that can support implementation and audit readiness.

Why NCNICC matters for Saudi private-sector organizations

Over the years, Saudi Arabia’s National Cybersecurity Authority (NCA) has developed a broad set of cybersecurity regulations. The Essential Cybersecurity Controls (ECC) established the main baseline, followed by more focused controls for critical systems, cloud computing, operational technology, telework, and other environments.

Published in December 2025, NCNICC – 1:2025 extends this regulatory landscape to private-sector entities that do not operate Critical National Infrastructure. This makes it relevant to a large and diverse group of Saudi businesses.

The framework covers three main areas:

  • cybersecurity governance
  • cybersecurity defense
  • third-party and cloud computing cybersecurity

For large entities, the framework includes 65 mandatory controls across all three areas. Small and medium-sized entities follow a more focused baseline of 26 mandatory controls under cybersecurity defense. The exact compliance scope therefore depends on the organization’s category, and that determination should come before implementation begins.

How Axidian identity security solutions support NCNICC compliance

Identity and access security appears across several NCNICC requirements because organizations need to control who can access their systems, how that access is granted, and whether privileged activity can be traced.

During the webinar, the speakers showed how Axidian solutions can support these capabilities:

  • Axidian Access helps organizations apply centralized authentication and multi-factor authentication policies across corporate resources.
  • Axidian Privilege supports privileged account management, controlled third-party and remote access, credential protection, and session monitoring.
  • Axidian CertiFlow centralizes certificate, smart card, and PKI lifecycle management.

These platforms do not replace governance, documentation, or internal accountability. They help security teams turn policy requirements into consistent technical controls and produce traceable evidence for audits.

A practical route to NCNICC audit readiness

The webinar was designed for IT and security professionals, internal auditors in NCNICC-regulated private-sector organizations, and system integrators supporting Saudi businesses with cybersecurity compliance.

The main takeaway is simple: NCNICC compliance becomes more manageable when it is treated as an operating model rather than a one-time audit project. Define the scope, assign ownership, connect controls to evidence, schedule recurring activities, and use technology where it creates reliable and measurable enforcement.

About the Author

Yulia Kondrashova

Content and Community Manager at Axidian

Over three years of experience in cybersecurity and content creation, with expertise in identity security. Focused on developing educational content that makes complex security topics clear, relevant, and practical for professionals.