NCA MSOC: Saudi Managed SOC Policy and Licensing
A guide to the NCA National Policy for MSOC and the licensing framework — the Tier 1 requirement, the 90-day report, and what in-house SOCs must do next.
In July 2024 the NCA published two documents that, read together, change how security monitoring works in Saudi Arabia: the National Policy for Managed Security Operations Centers and the Regulatory Framework for Licensing MSOC Services.
The policy's central clause is short and consequential. Organisations in scope must carry out their SOC work through a Tier 1 licensed MSOC service provider — and where they currently run an in-house SOC, they must submit a corrective plan to move off it. This is not guidance on how to procure managed detection. It is a national policy that reassigns where SOC capability is allowed to live.
Two documents, one regime
| Document | Applies to | What it sets |
|---|---|---|
| National Policy for MSOC | Beneficiary organisations — government entities and CNI operators | The obligation to obtain SOC work from a Tier 1 licensed provider, prior NCA approval for SOC initiatives, and the 90-day reporting duty. |
| Regulatory Framework for Licensing MSOC Services | Service providers and MSOC analysts | The two licence tiers, their capital, staffing and technical requirements, the licence lifecycle, and provider obligations. |
Both were published on 3 July 2024 and last updated 16 May 2025. The Arabic version of the licensing framework is the official and approved text, and the framework's appendices plus a separate "Technical Requirements for MSOC Service Providers" document are an integral part of it, read and enforced as a single unit.
Who the policy applies to
The National Policy applies to:
- Government organisations — ministries, authorities, establishments, centres, councils, committees, secretariats and others, plus their companies and entities.
- Private sector organisations owning, operating or hosting Critical National Infrastructure.
- Any other organisation the NCA requires to implement the policy, at its absolute discretion, to achieve relevant national targets.
Everyone else is encouraged — not required — to contract a service provider for MSOC services based on their own cybersecurity needs.
The three policy clauses
Section 5 sets out what in-scope organisations must do:
- 5.1 — adhere to all regulatory provisions, decisions and directions issued by the NCA as the national authority and reference for cybersecurity in the Kingdom.
- 5.2 — obtain the NCA's prior approval for any initiative, project or service related to the Security Operations Center, whether at organisational, sectoral or any other level.
- 5.3 — carry out the organisation's SOC work through a Tier 1 licensed MSOC service provider, in accordance with the framework, for all MSOC services set out in the Appendix.
Clause 5.2 is the one that catches programmes mid-flight. A SOC upgrade, a SIEM replacement, a sector-level shared SOC initiative — each now needs the NCA's prior approval, not a post-hoc notification.
The 90-day report
Section 6 turns the policy into a deadline. Every obligated organisation must give the NCA a report, on the specified form, containing:
- 6.1.1 — the current status of all the organisation's SOC work, including technologies, procedures, staffing and so on.
- 6.1.2 — a plan to comply, which as the case may be is either a corrective plan to move from contractual obligations with a current MSOC provider to a Tier 1 licensed provider, or a corrective plan to move from the organisation's in-house SOC to a Tier 1 licensed provider.
That report is due within a maximum of 90 days from the effective date of the policy, through NCA-specified channels. The NCA must then be immediately informed once the SOC transfer to a provider completes (6.3), and will review each report and respond with approval, a request for amendment, or additional requirements (6.4).
The general provisions add that the policy's provisions are enforced from the date it was published on the NCA website, that the NCA may impose additional conditions or cancel existing ones at its absolute discretion, that organisations must comply with any policy update, and that they must adhere to all NCA templates and deadlines.
What counts as MSOC services
The Appendix defines the minimum MSOC services an organisation can obtain, and it is worth reading as a scope boundary rather than a service catalogue:
| Service | What it includes |
|---|---|
| 1. Threat Monitoring and Detection | Continuous monitoring of the beneficiary's networks and systems; early detection using pre-defined use cases, indicators of compromise and detection rules; alert severity classification; immediate alerts to the beneficiary; periodic technical and executive reports; managing and operating the monitoring and detection tooling. |
| 2. Threat Analysis and Investigation | Analysing and investigating alerts in the context of the beneficiary's ecosystem; separating true from false alerts systematically; initial and in-depth analysis including root causes; sweeping and threat hunting exercises; investigating cases the beneficiary reports to the provider. |
| 3. Threat Containment Recommendations | Integrated, effective recommendations on how to contain and neutralise threats — to be applied by the beneficiary. |
The division of labour in service 3 matters. The provider recommends; the beneficiary applies. Outsourcing the SOC does not outsource response, and the organisation still needs the capability — and the incident management process — to act on what arrives.
The two licence tiers
The licensing framework creates two tiers, distinguished entirely by who the provider may serve:
| Tier | May serve | Minimum capital | Application fee |
|---|---|---|---|
| Tier 1 | All organisations, including government organisations and CNI owners, operators and hosts | SAR 50,000,000 | SAR 50,000 |
| Tier 2 | All organisations excluding government organisations and CNI owners, operators and hosts | SAR 500,000 | SAR 15,000 |
Fees are non-refundable, and the NCA reserves the right to modify them or impose others. Licences are valid for five years from issuance.
The hundred-fold capital gap between the tiers is the policy's market design in a single number. Tier 1 — the only tier that may serve the organisations the National Policy obligates — is deliberately restricted to well-capitalised providers.
Tier 1 requirements
Beyond capital, a Tier 1 applicant must be a legally established entity in the Kingdom, submit ownership data (direct and indirect, including articles of association, incorporation contract, commercial registration, controlling persons and their ownership percentages), an organisational structure, and the percentage of Saudisation for leadership positions, with Saudi citizens' shareholding at a percentage approved by the NCA. It must also:
- Provide all of the MSOC services in Appendix (a) — not a subset. (Tier 2 need provide only one.)
- Pass an NCA assessment against the "Technical Requirements for MSOC Service Provider" document, with a compliance report submitted.
- Employ full-time MSOC analysts who are Saudi citizens, to the minimums in Appendix (e).
- Submit a five-year business plan including vision and strategy, pro forma financial statements, a knowledge transfer plan for MSOC services, and a human capital and technical capacity investment roadmap with targets.
- Submit a cybersecurity programme report covering data storage, transfer, use and access monitoring; network and physical security including encryption; breach notification and investigation procedures; incident containment teams and capabilities; backup and business continuity; data recovery or destruction on termination at no charge to the beneficiary; and service agreements with beneficiaries.
- Contract a CSP licensed by the relevant authority in KSA where cloud services are needed.
Analyst staffing
Appendix (e) sets minimum full-time Saudi national analyst numbers for a Tier 1 provider, scaling with the number of beneficiaries served and split across three categories:
| Beneficiaries | Cat. A | Cat. B | Cat. C | Total FTE |
|---|---|---|---|---|
| 1–30 | 20 | 10 | 2 | 32 |
| 31–40 | 25 | 12 | 3 | 40 |
| 41–50 | 30 | 15 | 4 | 49 |
| 51–60 | 35 | 17 | 4 | 56 |
| 61–70 | 40 | 20 | 5 | 65 |
| 71–80 | 45 | 22 | 5 | 72 |
| 81–90 | 50 | 25 | 6 | 81 |
| 91+ | Provider must request the NCA to determine the minimum |
Providers must additionally assess whether more analysts are needed given the size and complexity of each beneficiary's systems. The NCA may reduce the minimum where a provider proves it uses appropriate solutions, including automation, that lower the need for headcount — an explicit incentive for engineering over staffing.
Individual analysts hold a Qualification Certificate issued by the NCA determining their eligibility to work as an MSOC analyst, and must complete required annual professional development hours including courses, conference participation and other learning activity.
Provider obligations that beneficiaries should read
Section 6 of the licensing framework binds the provider, but several obligations are directly relevant to a beneficiary evaluating one:
- 6.2 — begin providing licensed services within three months of licence issuance.
- 6.3 — connect to the NCA's National Security Operations Center per NCA instructions, at the provider's own cost throughout the licence period.
- 6.4 / 6.5 / 6.7 — adhere to localisation requirements, keeping all facilities and data within the Kingdom; implement and operate MSOC services and serve beneficiaries from within the Kingdom; and ensure data processing and storage related to MSOC services is within the Kingdom.
- 6.8 — implement NCA-shared security recommendations, cyber alerts, threat detection rules and indicators of compromise, and report results to the NCA within the specified period.
- 6.9 — provide the NCA with periodic reports on threats, IOCs, vulnerabilities, alerts and the actions taken, plus contained threats and measures.
- 6.10 / 6.11 — no publishing of cybersecurity data, and no publishing or sharing of beneficiary data or any data related to Saudi cyberspace with any party, inside or outside the Kingdom, without the NCA's written approval.
- 6.12 / 6.13 — contracts must address licence expiry, non-renewal or cancellation, and the provider must implement defined procedures when the relationship ends.
The framework also gives the NCA the right to cancel or suspend a licence where a provider fails to comply with the framework or NCA regulatory documents, or repeatedly fails its obligations — and a provider whose licence expires, is cancelled or is suspended may not provide services within its scope in any way or form (5.3.5). For a beneficiary, that is a continuity risk to price into the contract: clause 6.12 requires the provider's contracts to address it, and the beneficiary should confirm what those provisions actually say.
What in-scope organisations should do
- Confirm scope, including whether the NCA has designated you under category (C).
- Document current SOC state — technologies, procedures, staffing, contracts — in the form the report under 6.1.1 requires.
- Decide the corrective path: from an existing non-Tier-1 provider, or from an in-house SOC. Both require a plan; the in-house transition is the harder one, since it involves people as well as tooling.
- Verify your provider's tier. A provider serving a government entity or CNI operator needs Tier 1. Ask for the licence, its tier and its expiry date, and check the five-year clock.
- Freeze unapproved SOC initiatives. Clause 5.2 requires NCA prior approval; a project already underway needs that approval retrospectively secured, not assumed.
- Keep response capability in-house. The provider recommends containment; you apply it. Your incident response plan and the people who execute it stay yours.
- Contract for the licence risk — expiry, non-renewal, suspension and the data recovery or destruction obligations on termination.
How GRC Vantage supports MSOC compliance
GRC Vantage's compliance module holds the National Policy's clauses and compliance procedures as tracked obligations — the 90-day report, the corrective plan, the immediate notification on transfer completion, and the standing requirement for NCA prior approval of SOC initiatives — each with an owner, a due date and the evidence attached.
MSOC providers sit in the vendor and third-party workflow with their licence tier, licence number and five-year expiry recorded, so a lapse surfaces as a task rather than a surprise, and the provider obligations you depend on — in-Kingdom data processing, NSOC connectivity, periodic reporting, termination data handling — are tracked against the contract that carries them. Risks arising from a SOC transition run through the register scored on the NFCRM matrix.
For the full family, see the NCA frameworks pillar guide. To plan a SOC transition against the policy, talk to our team.
Book a demo with the GRC Vantage team in Riyadh or Dammam.
See Compliance Management →Frequently asked questions
What is the NCA MSOC policy?
The National Policy for Managed Security Operations Centers requires in-scope organisations to carry out their SOC work through a Tier 1 licensed MSOC service provider, to obtain the NCA's prior approval for any SOC-related initiative, project or service, and to report their current SOC status and compliance plan to the NCA within 90 days of the policy's effective date.
Who must comply with the MSOC policy?
Government organisations — ministries, authorities, establishments, centres, councils, committees, secretariats and others, plus their companies and entities — private sector organisations owning, operating or hosting Critical National Infrastructure, and any other organisation the NCA requires to implement the policy at its absolute discretion.
Can we keep our in-house SOC?
The policy requires in-scope organisations to carry out SOC work through a Tier 1 licensed MSOC provider, and the 90-day report must include a corrective plan to move from an in-house SOC to such a provider where one exists. Organisations outside the policy's scope are encouraged, not required, to use a licensed provider.
What is the difference between a Tier 1 and Tier 2 MSOC licence?
Tier 1 permits service to all organisations, including government entities and CNI owners, operators and hosts; Tier 2 excludes those. Tier 1 requires capital of at least SAR 50 million, provision of all MSOC services, an NCA technical assessment, and minimum numbers of full-time Saudi national MSOC analysts. Tier 2 requires capital of at least SAR 500,000 and at least one MSOC service.
Must MSOC data stay inside Saudi Arabia?
Yes. Provider obligations 6.4, 6.5 and 6.7 require adherence to localisation requirements with all facilities and data kept within the Kingdom, implementation and operation of MSOC services from within the Kingdom, and data processing and storage related to MSOC services within the Kingdom.
- 1Primary Regulation — NCANational Cybersecurity Authority (NCA), Kingdom of Saudi Arabia, 2024Source for the policy objectives, scope categories (A), (B) and (C), policy clauses 5.1 to 5.3, compliance procedures 6.1 to 6.4 including the 90-day report, general provisions 7.1 to 7.4, and the Appendix defining the three minimum MSOC services. Published 03/07/2024.
- 2Primary Regulation — NCANational Cybersecurity Authority (NCA), 2024Source for the definitions including Qualification Certificate and MSOC Analyst, framework objectives and scope, licence provisions 5.1 to 5.3, service provider obligations in Section 6, general provisions in Section 9, and Appendices (a), (b), (d) and (e) covering MSOC services, the two licence tiers and their requirements, the fee schedule, and the minimum analyst staffing table.
- 3Primary Regulation — NCANational Cybersecurity Authority (NCA), 2024Both documents published 03/07/2024, last updated 16/05/2025.

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.
Related articles
A guide to NCA Cloud Cybersecurity Controls (CCC-2:2024) — the CSP and CST control sets, four classification levels, and the data localisation change.
A guide to NCA Critical Systems Cybersecurity Controls (CSCC) — the seven identification criteria, 32 controls, and the in-Kingdom access and hosting rules.
A guide to NCA Data Cybersecurity Controls (DCC-1:2022) — four classification levels, 19 controls across the data lifecycle, and third-party sharing rules.