NCA E-Commerce Cybersecurity Guidelines Explained

A guide to the NCA e-commerce cybersecurity guidelines — the seven CGESP categories for SME and SoHo sellers, and the consumer-facing CGEC companion document.

GRC Vantage TeamGRC Vantage Team2026-08-269 min read

The NCA's e-commerce guidance is the outlier in its catalogue: two documents that are advisory, not mandatory, written for small businesses and consumers rather than for CISOs. They are also the NCA's clearest statement of what it expects from the long tail of the Saudi digital economy — the sellers who are too small for the Essential Cybersecurity Controls but large enough to hold customer payment data.

There are two: the Cybersecurity Guidelines for E-commerce Service Providers (CGESP – 1: 2019) and the Cybersecurity Guidelines for E-commerce Consumers (CGEC – 1: 2019), issued in collaboration with the Saudi e-Commerce Council.

Who they are for

The CGESP targets two segments defined by the Small and Medium Enterprises General Authority (Monsha'at):

  • SME — Small and Medium Enterprises
  • SoHo — Small Office / Home Office sellers, also described as online sellers, C2C, micro enterprises or sole proprietorships

They cover e-commerce conducted through any channel — social media, websites, apps — using any computing device, including personal computers, tablets, smartphones and TVs. Individual guidelines are marked as applying to SMEs only, or to both SMEs and SoHo sellers.

The guidelines are for awareness purposes, but the NCA strongly encourages every e-commerce service provider in the Kingdom to use them, and notes that because threats change, providers should research whether additional measures are needed.

They also position themselves within a wider regulatory picture, complementing instruments overseen by the Ministry of Commerce and Investment (the E-Commerce Act), the NCA itself, and SAMA (the Cyber Security Framework and Banking Consumer Protection Principles).

The seven CGESP categories

#CategoryCovers
1Use Strong AuthenticationAvoiding predictable, shared or old passwords; changing all default passwords; considering multi-factor authentication.
2Protect Your E-commerce SystemsKnowing your technology assets; controlling the number of admin accounts; anti-malware; regular application updates on all devices; staying current on threats; avoiding non-secure Wi-Fi; website encryption; using trusted sites to display ads.
3Minimize Impact of Data BreachesBacking up data; protecting data with encryption; protecting customers' financial data; changing default security settings; enabling remote wiping on mobile devices.
4Guard Your Social Media AccountsSafe behaviour on social media; getting accounts verified.
5Defend Your NetworkDisabling unnecessary services; network segmentation and segregation; defending the perimeter; testing systems regularly.
6Continuously Educate and Train EmployeesDeveloping and implementing cybersecurity and privacy policies; protecting against phishing and social engineering; restricting downloads of unknown applications; recognising signs of compromise and handling incidents.
7Strengthen Internal E-commerce InfrastructureSecure backup location; reviewing audit trails and security logs; email activation and CAPTCHA for user registration; fraud prevention software; choosing a secure e-commerce platform; customised user registration; protecting against denial of inventory.

The specific password guidance under 1-1 is worth quoting because small sellers ask for it constantly: a random sequence of upper and lower case letters, numbers and special characters; not common words, simple number sequences or personal information; at least 8 characters; changed at least every 3 months; and never disclosed to others. Guideline 1-2 adds that default admin passwords must be changed immediately on installation and before use, with a different password for each system, application and account.

Category 7's "protect against denial of inventory" is the one guideline you will not find in a generic small-business security checklist — an attack that locks up stock by filling carts it never intends to buy, hitting revenue without ever touching a system.

Two other items in category 7 are specifically e-commerce controls rather than general IT hygiene: email activation and CAPTCHA at user registration (7-4) and customised user registration (7-7), both aimed at automated account creation and the fraud that follows it. Fraud prevention software (7-5) and choosing a secure e-commerce platform (7-6) push the smallest sellers toward buying capability rather than building it — realistic advice for a segment with no security staff.

The social media category

Category 4 is short but consequential for the SoHo segment. The NCA's own introduction notes that 26% of Saudi SMEs use social media to promote products, and that almost all SoHo sellers generate sales by leveraging social platforms to reach customers. For that segment, the social media account is the storefront.

The two guidelines — exercise safe behaviour, and get accounts verified — are the consumer-scale version of what the OSMACC requires of government entities and CNI operators. Verification serves the same purpose in both documents: making the official account recognisable so impersonation is detectable.

The consumer companion: CGEC

The Cybersecurity Guidelines for E-commerce Consumers (CGEC – 1: 2019) targets all consumers in Saudi Arabia shopping through any channel on any device, and is organised into three categories:

  1. Protect Your E-commerce Accounts and Devices
  2. Secure Your E-commerce Transactions
  3. Exercise Caution When Communicating Online for E-commerce

The NCA's framing data is instructive: around 58% of the Kingdom's population had shopped online at least once every three months at the time of writing, spending an average of SAR 4,000 annually, with only 7% buying exclusively from Saudi-based providers. A large share of Saudi consumer transactions crosses a border — which is why consumer-side caution carries as much weight in the NCA's model as seller-side controls.

For a seller, the CGEC is useful as a customer communications resource. The behaviours it asks consumers to adopt — verifying the merchant, checking the connection, being wary of unsolicited contact — are the same behaviours that reduce a seller's fraud and chargeback exposure. Pointing customers at the NCA's own consumer guidance is more credible than writing your own.

How these fit the wider regime

If you are…The applicable instrument
A SoHo or SME online sellerCGESP — advisory, strongly encouraged. Plus the E-Commerce Act and, if you hold personal data, the PDPL.
A large e-commerce enterpriseThe ECC — for guidance and, in some cases, mandatory compliance. The CGESP is not your document.
A payment service provider or fintechSAMA's regime — the Cyber Security Framework, Banking Consumer Protection Principles, and the Counter-Fraud Fundamental Requirements.
A CNI operator running an e-commerce channelECC plus the applicable NCA extensions — CSCC, CCC, DCC, OSMACC as relevant.

The PDPL point deserves emphasis, because it changed the picture after these guidelines were written. The CGESP was published in 2019 and refers to a "Data Protection Act – under development". That law now exists and is enforced. An SME seller handling customer personal data has mandatory obligations under the PDPL regardless of the CGESP's advisory status — including data subject rights and breach handling. Category 3's advice on protecting customer financial data is good practice; the PDPL's requirements around the same data are law.

Practical sequencing for a small seller

  1. Fix authentication first. Unique passwords per system, all defaults changed, MFA wherever the platform offers it. This is free and closes the most common route in.
  2. Get the social media accounts verified and separate the business account from personal use.
  3. Know what you have. Guideline 2-1's asset inventory is the precondition for everything in categories 2, 5 and 7 — you cannot patch or segment what you have not listed.
  4. Move payment data off your own systems where the platform allows it. The best protection for customers' financial data is not holding it.
  5. Back up, encrypt, and store the backup somewhere else (3-1, 3-2, 7-1). This is the difference between a ransomware incident and a ransomware closure.
  6. Turn on the anti-fraud basics — email activation and CAPTCHA at registration, and the platform's fraud prevention features.
  7. Check your PDPL position separately. The CGESP will not tell you whether you are compliant with the law.

How GRC Vantage helps

Most organisations reading this are on the other side of the CGESP boundary — large enough for the ECC, with an SME and SoHo supply chain that is not. GRC Vantage's compliance module carries the ECC and its extensions for your own estate, and the vendor and third-party workflow lets you set proportionate expectations for small suppliers and marketplace sellers, using the CGESP categories as the baseline questionnaire rather than sending a 100-control assessment to a sole trader.

Where those relationships involve customer personal data, the same register carries the PDPL processor obligations that sit alongside the guidance.

For the full NCA picture, see the NCA frameworks pillar guide. To design a proportionate supplier assurance approach for small sellers, talk to our team.

Want to see this in the platform?

Book a demo with the GRC Vantage team in Riyadh or Dammam.

See Compliance Management

Frequently asked questions

What are the NCA e-commerce cybersecurity guidelines?

Two advisory documents issued by the NCA in collaboration with the Saudi e-Commerce Council: the Cybersecurity Guidelines for E-commerce Service Providers (CGESP – 1: 2019), aimed at SME and SoHo sellers, and the Cybersecurity Guidelines for E-commerce Consumers (CGEC – 1: 2019), aimed at shoppers.

Are the CGESP guidelines mandatory?

No. They are for awareness purposes, although the NCA strongly encourages every e-commerce service provider in the Kingdom to apply them. Large enterprises should refer to the Essential Cybersecurity Controls instead, which carry mandatory compliance in some cases.

What are the seven CGESP categories?

Use Strong Authentication; Protect Your E-commerce Systems; Minimize Impact of Data Breaches; Guard Your Social Media Accounts Used in E-commerce; Defend Your Network; Continuously Educate and Train Your Employees; and Strengthen Your Internal E-commerce Infrastructure.

Do the guidelines cover selling through social media?

Yes. The guidelines cover e-commerce conducted through any channel including social media, websites and apps, on any computing device, and category 4 addresses social media accounts specifically — safe behaviour and getting accounts verified.

Does following the CGESP make me PDPL compliant?

No. The CGESP predates the Personal Data Protection Law's enforcement and refers to it as under development. Its advice on protecting customer data is good practice, but PDPL obligations — including data subject rights and breach handling — apply independently and are mandatory.


Sources & References
Primary regulatory documents, international standards and guidance cited in this article
GRC Vantage Team
GRC Vantage Team
Saudi GRC Practitioners

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.