.avif)

Saudi Arabia has one of the most developed cybersecurity regulatory landscapes in the Middle East. Six regulations matter most: the SAMA Cyber Security Framework (CSF) and SAMA Financial Entities Ethical Red Teaming (FEER) program for the financial sector; the NCA Essential Cybersecurity Controls (ECC) and Saudi Cybersecurity Workforce Framework (SCyWF); the NDMO Personal Data Protection Law (PDPL); and the CST Cybersecurity Regulatory Framework (CRF) for telecommunications. This guide explains each one and how Immersive helps organizations meet them.
Cybersecurity regulations are crucial in safeguarding sensitive information and maintaining trust in digital transactions of all types. This overview highlights critical cybersecurity regulations in Saudi Arabia and how Immersive can assist organizations in complying with them.
Key regulations include the SAMA Cyber Security Framework (CSF), SAMA Financial Entities Ethical Red Teaming Guidelines, NCA Essential Cybersecurity Controls (ECC), NCA Saudi Cybersecurity Workforce Framework (SCyWF), NDMO Personal Data Privacy Law (PDPL), and CST Cybersecurity Regulatory Framework (CRF).
Understanding these regulations and their regional influence is essential for organizations. By complying with these standards, organizations can enhance cybersecurity resilience and contribute to a more secure digital environment globally. Leveraging the Immersive platform, organizations can strengthen their cybersecurity posture, develop a skilled workforce, and comply with cybersecurity regulations in Saudi Arabia and beyond.
The SAMA Cyber Security Framework (CSF)
Issued by the Saudi Arabian Monetary Authority (SAMA), it sets the gold standard for cybersecurity practices in banking and financial institutions. Its influence extends beyond Saudi Arabia, serving as a benchmark for cybersecurity frameworks in the region, and is a critical regulation that organizations must be well-versed in.
Requirement
A set of minimum cybersecurity controls for banking, financial services, and insurance organizations (BFSI) that outlines the essential requirements that all BFSI sector organizations must meet. Of particular focus are elements related to upskilling and exercise, such as those outlined in sections 3.1.6 and 3.1.7.
How Immersive Helps
The Immersive platform covers CSF’s Awareness and Training elements and complements its focus on exercising and individual development plans requested by regulators. See the financial services solution.
The SAMA Financial Entities Ethical Red Teaming program
A globally recognized initiative designed to fortify financial entities’ cybersecurity posture. Its principles and methodologies are increasingly recognized and adopted by organizations worldwide, underscoring its effectiveness in strengthening security defenses.
Requirement
Implement a framework to guide organizations in preparing and conducting red-teaming activities while testing their detection and response capabilities against actual sophisticated and advanced attacks.
How Immersive Helps
Immersive empowers both defensive and offensive professionals through dynamic upskilling and evidencing cycles, fostering continuous improvement so your organization can identify and exploit vulnerabilities and detect and respond accordingly. Explore red team training.
NCA Essential Cybersecurity Controls (ECC)
Issued by the National Cybersecurity Authority (NCA) of Saudi Arabia, it outlines fundamental cybersecurity measures. These controls have influenced cybersecurity practices in the region and are considered a reference point for similar regulations globally.
Requirement
Comprehensive cybersecurity requirements covering Strategy, People, Processes, and Technology, in that order, emphasizing a holistic approach to cybersecurity.
How Immersive Helps
Immersive helps accelerate and ensure compliance with ECC by actively supporting the fulfillment of control sub-controls 1-9-3-2 and 1-9-4-1, and control sub-domain 1-10.
NCA Saudi Cybersecurity Workforce Framework (SCyWF)
This framework defines the skills and competencies required for cybersecurity professionals in Saudi Arabia. Its guidelines are shaping the development of cybersecurity workforce frameworks in neighboring countries.
Requirement
The Saudi Arabian Cybersecurity Workforce Framework defines the skills and roles needed for cybersecurity professionals in Saudi Arabia, tailored to the country’s specific context.
How Immersive Helps
Immersive helps customers map their workforce to SCyWF. Immersive content already aligns with the NIST NICE Framework, which provides the foundation for SCyWF. Building on NIST NICE, SCyWF offers a tailored, localized approach to Saudi Arabia’s specific workforce needs, with unique job roles, specialties, and categories. See workforce exercising.
The NDMO Personal Data Privacy Law (PDPL)
This comprehensive regulation issued by the National Data Management Office (NDMO) governs the collection and processing of personal data. Its principles align with global data protection standards, providing organizations with a clear roadmap for data protection compliance worldwide.
Requirement
The NDMO publishes and maintains compliance with the Data Management and Personal Data Protection Standards, of which several controls are relevant from a data protection, privacy, and management perspective.
How Immersive Helps
Immersive directly supports PDPL with several specifications under the Data Management and Personal Data Protection Standards, including PDP.2.1, PDP.3.1, and PDP.3.2. Immersive Cyber Crisis Simulations help organizations stress-test existing procedures and uncover data protection, data-breach management, and data-breach reporting gaps.
CST Cybersecurity Regulatory Framework (CRF)
Issued by the Communications and Information Technology Commission (CITC), the CRF provides guidelines for ensuring cybersecurity in Saudi Arabia’s telecommunications sector. Its principles influence cybersecurity regulations in other countries seeking to secure their telecommunications infrastructure.
Requirement
The CRF outlines several requirements across Strategy, People, Technology, and Processes that organizations operating in the relevant sectors should follow. The regulation now describes how these plans and programs must directly cater to the specifics of the user roles.
How Immersive Helps
The Immersive platform directly supports CRF with controls group 1.5 for Cybersecurity Awareness & Training, offering tailored programs, interactive learning modules, role-based pathways, measurable learning outcomes, and continuous improvement, plus support for mapping to the SCyWF framework.
Get the Human Edge While Building Cyber Resilience
Cutting-edge tools alone won’t guarantee resilience. Immersive’s approach, Cyber Workforce Resilience, helps organizations assess, benchmark, and prove their ability to respond effectively to cyber threats by focusing on people and teams making critical decisions.
“You’ve got to prove to different stakeholders — regulators, compliance teams, the board — that your people are ready. I don’t think you can stand behind tick-box compliance training done once a year for an hour. You need to show you took every reasonable step to reduce the risk of a cyber incident.”
— Dan Potter, Senior Director of Cyber Drills and Resilience, Immersive
Get a guided demo from an expert on how the Immersive platform helps with multiple Saudi Arabia regulations, or explore the compliance solution to see how labs, cyber drills, and crisis simulations map to SAMA, NCA, NDMO, and CST requirements.
Frequently Asked Questions
What Cybersecurity Regulations Apply in Saudi Arabia?
Saudi Arabia's main cybersecurity regulations are the SAMA Cyber Security Framework (CSF) and SAMA Financial Entities Ethical Red Teaming (FEER) program for the financial sector, the NCA Essential Cybersecurity Controls (ECC) and Saudi Cybersecurity Workforce Framework (SCyWF), the NDMO Personal Data Protection Law (PDPL), and the CST Cybersecurity Regulatory Framework (CRF) for telecommunications.
What Is the Sama Cyber Security Framework (CSF)?
The SAMA Cyber Security Framework is a set of minimum cybersecurity controls issued by the Saudi Central Bank (SAMA) for banking, financial services, and insurance (BFSI) organizations. It is widely treated as a regional benchmark, and its sections 3.1.6 and 3.1.7 place particular focus on upskilling and exercising.
What Are the NCA Essential Cybersecurity Controls (ECC)?
The Essential Cybersecurity Controls are baseline requirements issued by Saudi Arabia's National Cybersecurity Authority (NCA), covering Strategy, People, Processes, and Technology. They are widely used as a reference point for cybersecurity practice across the region.
What Is the SAMA Financial Entities Ethical Red Teaming (FEER) Program?
FEER is a SAMA initiative that guides financial entities in preparing and conducting red-teaming activities to test their detection and response capabilities against sophisticated, real-world attacks. Its methodologies are recognized and adopted internationally.
What Is Saudi Arabia's Personal Data Protection Law (PDPL)?
The PDPL, governed by the National Data Management Office (NDMO), regulates the collection and processing of personal data in Saudi Arabia through its Data Management and Personal Data Protection Standards. Its principles align with global data protection standards.
How Can Organizations Comply With Saudi Cybersecurity Regulations?
Beyond technology controls, these regulations increasingly require organizations to prove their people are ready. Immersive supports compliance by mapping content to frameworks such as SCyWF (built on NIST NICE), delivering hands-on labs and red-teaming upskilling for SAMA CSF and FEER, and using cyber drills and crisis simulations to stress-test incident response and data-breach procedures for ECC, CRF, and PDPL.

See how to prove readiness with one platform.
See how Immersive One helps technical teams and leaders prove readiness, close capability gaps, benchmark progress, and report cyber resilience with confidence.
