SCyber-Edu: Saudi Cybersecurity Education Framework
A guide to the NCA SCyber-Edu framework — the seven cybersecurity degree programmes, their core knowledge units, and how employers can use it in hiring.
The Saudi Cybersecurity Higher Education Framework (SCyber-Edu) is the NCA document aimed at universities rather than at compliance teams — which is exactly why hiring managers should read it. It sets the minimum curriculum requirements for every cybersecurity degree offered in the Kingdom, which means it tells you, precisely, what a Saudi cybersecurity graduate has been taught.
For an employer trying to work out whether a bachelor's in cybersecurity from one institution means the same thing as one from another, that is a more useful document than any CV.
What SCyber-Edu is
Under Royal Order No. 6801 dated 31 October 2017, the NCA is mandated to build the national cybersecurity workforce, participate in developing education and training programmes, prepare professional standards and frameworks, and develop and run professional assessment tests. SCyber-Edu discharges the education half of that mandate.
It was developed in cooperation and coordination with the Ministry of Education and the Education and Training Evaluation Commission, and is designed to be a guide for developing, evaluating and accrediting cybersecurity higher education programmes. It aligns with the Unified Saudi Classification for Educational Levels and Specializations, the National Qualifications Framework (NQF) and the guidelines of the National Center for Academic Accreditation and Evaluation.
The framework draws its content from four international references — the US CAE-CD (National Centers of Academic Excellence in Cyber Defense) programme guidance, ABET criteria for accrediting computing programs, the IEEE/ACM Cybersecurity Curricula 2017, and the UK NCSC-certified Higher Education Program — with knowledge units derived specifically from CAE-CD 2019 guidance, IEEE/ACM Cybersecurity Curricula 2017 and IEEE/ACM Computer Science Curricula 2013, then modified to meet national needs.
Seven programmes
SCyber-Edu covers five degree levels, split into seven distinct programme definitions:
| Programme | Admission | Core KUs | Min. electives |
|---|---|---|---|
| Intermediate Diploma | High school diploma or equivalent | 10 | 3 |
| Bachelor (Cybersecurity Track) | High school diploma or equivalent | 12 | 4 |
| Bachelor (Cybersecurity Major) | High school diploma or equivalent | 16 | 8 |
| Higher Diploma (IT background) | IT-related qualification | Bachelor Track core KUs if not already held | 8 |
| Higher Diploma (non-IT background) | Non-IT qualification | Bachelor Track core KUs if not already held | — |
| Master | Relevant bachelor's degree | Bachelor Track core KUs if not already held, plus thesis or project | 7 |
| Doctoral | Master's in cybersecurity, computer science or related field; English proficiency | Bachelor Track core KUs if not already held, plus dissertation | 3 |
The distinction the framework works hardest to draw is between a cybersecurity major and an IT-related major with a cybersecurity track. Both are bachelor's degrees; the major carries 16 core knowledge units and 8 electives against the track's 12 and 4. For an employer, that is the difference between a graduate who has covered cryptography, algorithms, network security administration and OS hardening as core material and one who has not.
A "bachelor's degree in cybersecurity" is not one qualification in Saudi Arabia — it is two, with materially different curricula. SCyber-Edu is the document that tells you which one is in front of you.
Program Descriptors and Knowledge Units
Each programme is specified in two ways.
Program Descriptors (PDs) correspond to NQF level descriptors and are grouped under Knowledge, Skills, and Values/Autonomy/Responsibility. They give institutions the raw material for writing Program Learning Outcomes, and SCyber-Edu sets the minimum PDs that must be considered — institutions may add more.
Knowledge Units (KUs) are thematic groupings of related topics, each with its own set of learning outcomes specifying the minimum a student should know or be able to do on completion. Section 3 of the framework defines every KU in detail.
The framework sets three requirement types per programme: admission requirements, core KUs (mandatory for graduation) and elective KUs (a minimum number must be completed). It also notes that some KUs are prerequisites for others and that dependencies must be reflected in the programme of study, and requires institutions to include mathematics knowledge units appropriate to their programme's focus.
The Bachelor (Cybersecurity Major) core
The sixteen core knowledge units for the full cybersecurity major are the closest thing the Kingdom has to a definition of the discipline's foundations:
Cybersecurity Foundations (CSF) · Cybersecurity Design Principles (CDP) · IT Systems Components (ISC) · Basic Cryptography (BCY) · Basic Networking (BNW) · Basic Scripting and Programming (BSP) · Network Defense (NDF) · Operating Systems Concepts (OSC) · Cyber Threats (CTH) · Policy, Legal, Ethics and Compliance (PLE) · Security Risk Analysis (SRA) · Algorithms (ALG) · Data Structures (DST) · Databases (DAT) · Network Technology and Protocols (NTP) · Network Security Administration (NSA) · Operating Systems Hardening (OSH)
The Bachelor (Cybersecurity Track) core drops cryptography, algorithms, network technology and protocols, network security administration and OS hardening — keeping ten shared foundations plus Data Structures and Databases.
The Intermediate Diploma's ten core KUs are the foundational subset: CSF, CDP, ISC, BNW, BSP, NDF, OSC, CTH, PLE and SRA.
The elective catalogue
Section 3 defines roughly eighty knowledge units in total. Beyond the core, the catalogue spans the specialisms the profession actually recruits for — Advanced Cryptography (ACR), Digital Forensics (DFS), Penetration Testing (PTT), Malware-adjacent units such as Software Reverse Engineering (SRE) and Hardware Reverse Engineering (HRE), Industrial Control Systems (ICS), Embedded Systems and Internet of Things (ESI), Cloud Computing (CCO), Machine Learning (MLL) and Deep Learning (DLL), Privacy (PRI), Supply Chain Security (SCS), Business Continuity, Disaster Recovery and Incident Management (BDR), and Information Assurance Compliance (IAC) and Standards (IAS).
For the graduate programmes, the framework excludes eight KUs from the elective pool as too foundational for postgraduate credit: Awareness and Understanding (AUU), Basic Cryptography (BCY), Cyber Crime (CCR), Component Procurement (CPP), Cybersecurity Ethics (CSE), Database Management Systems (DMS), Linux System Administration (LSA) and Windows System Administration (WSA).
Why employers should use it
SCyber-Edu is an academic framework, but it solves three practical hiring problems.
It makes degrees comparable. Two candidates with cybersecurity bachelor's degrees may have covered materially different core content depending on whether their programme was a major or a track. Asking which one, and asking for the institution's KU coverage, turns a credential into information.
It pairs with the SCyWF. The Workforce Framework defines forty job roles by the Tasks, Knowledge and Skills each requires; SCyber-Edu defines what degree programmes teach. Mapping the two lets you say which programmes plausibly produce candidates for which roles, and where a graduate will need employer-side training regardless of the degree.
It shapes graduate development plans. Where a role's SCyWF knowledge requirements are not covered by the KUs in a candidate's programme, that gap is identifiable on day one rather than at the first performance review — and it maps directly to the training obligations the ECC and other NCA control sets already impose.
The NCA also publishes an Alignment Guide and an Alignment Form (an Excel workbook) alongside the main framework, intended for institutions demonstrating that their programme meets the requirements. Employers evaluating a university partnership, or a sponsored-degree programme for staff, can reasonably ask to see a completed alignment form.
For institutions
The framework applies to cybersecurity degree programmes offered by public and private post-secondary educational institutions in Saudi Arabia. Applying it means: mapping existing courses to KUs (many-to-many, since a KU is not a course); confirming every core KU for the programme level is fully covered; ensuring the elective catalogue offers enough breadth for students to meet the minimum elective count; reflecting KU prerequisite dependencies in the study plan; selecting mathematics KUs appropriate to the programme's focus; and writing Program Learning Outcomes from the PDs, adding institution-specific outcomes on top.
Because SCyber-Edu is aligned to the NQF and the National Center for Academic Accreditation and Evaluation guidelines, that mapping work feeds the accreditation submission rather than sitting alongside it.
How GRC Vantage supports workforce capability
GRC Vantage's platform holds SCyWF job role definitions against the people who own controls, and lets you record the knowledge units a team member's qualification covered — so the gap between a role's required knowledge and a person's demonstrated coverage becomes a training plan rather than an assumption. Training and awareness obligations under the ECC, DCC and OTCC are evidenced against that record.
For organisations running graduate schemes or university partnerships in the Kingdom, that mapping also makes the pipeline legible: which programmes feed which roles, and what employer-side development each intake needs.
See the Saudi Cybersecurity Workforce Framework guide for the job-role half of the picture, and the NCA frameworks pillar guide for the wider family. To discuss cyber workforce capability planning, talk to our team.
Book a demo with the GRC Vantage team in Riyadh or Dammam.
See Professional Services →Frequently asked questions
What is SCyber-Edu?
The Saudi Cybersecurity Higher Education Framework is the NCA's guide for developing, evaluating and accrediting cybersecurity higher education programmes in the Kingdom. It sets minimum curriculum requirements — Program Descriptors and Knowledge Units — for seven programme definitions across five degree levels, and was developed with the Ministry of Education and the Education and Training Evaluation Commission.
What degree programmes does SCyber-Edu cover?
Intermediate Diploma; Bachelor (Cybersecurity Track); Bachelor (Cybersecurity Major); Higher Diploma for IT background; Higher Diploma for non-IT background; Master; and Doctoral. Version 1.0 covers general cybersecurity programmes only.
What is the difference between a cybersecurity major and a cybersecurity track?
The Bachelor (Cybersecurity Major) requires 16 core knowledge units and at least 8 electives; the Bachelor (Cybersecurity Track) — an IT-related major with a cybersecurity track — requires 12 core knowledge units and at least 4 electives. The major additionally covers Basic Cryptography, Algorithms, Network Technology and Protocols, Network Security Administration and Operating Systems Hardening as core content.
Is a Knowledge Unit the same as a course?
No. A KU is a thematic grouping of related topics with its own learning outcomes. A KU may be covered by one or more credit courses, and a single credit course may cover one or more KUs partially or completely.
How does SCyber-Edu relate to the SCyWF?
They are complementary halves of the NCA's workforce mandate. SCyber-Edu defines what cybersecurity degree programmes must teach; the Saudi Cybersecurity Workforce Framework defines the forty cybersecurity job roles and the Tasks, Knowledge and Skills each requires. Mapping KUs to SCyWF knowledge and skill statements shows which programmes feed which roles.
- 1Primary Framework — NCANational Cybersecurity Authority (NCA), Kingdom of Saudi Arabia, 2020Source for the scope and methodology, the seven programme definitions with their admission requirements and core and elective Knowledge Unit counts in Section 2, and the full Knowledge Unit catalogue in Section 3. Version 1.0, October 2020.
- 2Primary Framework — NCANational Cybersecurity Authority (NCA), 2020Companion guide, published with an Excel alignment form, for institutions demonstrating that a programme meets the framework's requirements.
- 3Primary Framework — NCANational Cybersecurity Authority (NCA), 2022Published 02/06/2022, last updated 20/05/2025. Hosts the framework, the alignment guide and the alignment form.

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.
Related articles
A guide to the NCA Saudi Cybersecurity Workforce Framework (SCyWF v1.5) — five categories, twelve specialty areas, forty job roles and the new competency areas.
A guide to the NCA Cybersecurity Toolkits and Implementation Guides — around 90 free policy, standard and procedure templates, and how to use them properly.
A guide to NCA Cloud Cybersecurity Controls (CCC-2:2024) — the CSP and CST control sets, four classification levels, and the data localisation change.