Saudi Arabia

Middle East

Telecom security in Saudi Arabia is jointly governed by CST (Communications, Space and Technology Commission) and the National Cybersecurity Authority (NCA). The NCA's Essential Cybersecurity Controls (ECC) and Critical Systems Cybersecurity Controls (CSCC) are binding on operators.

Regulator: CST + NCA

Primary frameworks: NCA ECC-1:2018, NCA CSCC-1:2019, CST licence conditions, CCC-1:2020 (Critical Systems)

NCA ECC controls

ECC-1:2018 sets 114 controls across 5 domains. Telecom operators map most controls into their ISMS; audit is by NCA-authorized bodies.

CSCC / critical systems

Core network functions, HLR/HSS, and signaling gateways are typically scoped as critical systems, invoking the stricter CSCC controls.

CST oversight

CST conducts periodic technical audits on operators, including signaling-firewall configuration reviews and roaming-security posture.

Key takeaways

  • The ECC + CSCC stack is more prescriptive than most Gulf frameworks.
  • Critical-system classification pulls in additional supply-chain and personnel controls.
  • CST technical audits are hands-on and expect implementation evidence.