The “Regulatory Framework for Licensing Cybersecurity Compliance Assessment Services”

Overview
The National Cybersecurity Authority (NCA) is the national entity in charge of cybersecurity in Saudi Arabia and the national reference in all its affairs. The NCA’s mandate includes introducing cybersecurity policies, governance mechanisms, frameworks, standards, controls, and guidelines; as well as circulating them with relevant stakeholders, following up on their compliance, and updating them. In addition, the NCA mandate includes licensing individuals and non-governmental organizations to practice cybersecurity activities and operations determined by NCA, as well as developing and updating the necessary standards or controls for clearance and licensing the import, export, and use of highly sensitive hardware and software, as determined by NCA. The objective of the framework is to regulate activities related to organizations’ compliance assessment services with NCA’s cybersecurity controls and other regulations.
Framework Highlights
|
|
Classification of licensees into four types |
| Establishment of minimum requirements to qualify for licenses including service providers and their staff |
Target Groups
|
Governmental organizations
|
Private sector and non-profit organizations |
Cybersecurity service providers
|
Cybersecurity requirements compliance assessors |
Impact
|
Strengthen organizations’ cybersecurity in the Kingdom
|
Enable growth of specialized companies in cybersecurity sector
|
Localize highly skilled cybersecurity jobs
|
Support entrepreneurs and small and medium enterprises in cybersecurity sector |
Receiving date
The deadline for public consultation submission is November 20, 2022
Was this page useful?
0% of users said Yes from 0 Feedbacks