SCyWF: The Saudi Cybersecurity Workforce Framework
A guide to the NCA Saudi Cybersecurity Workforce Framework (SCyWF v1.5) — five categories, twelve specialty areas, forty job roles and the new competency areas.
The Saudi Cybersecurity Workforce Framework (SCyWF) is the NCA document that most Saudi organisations should be using and mostly are not. It is not a control set and it is not assessed — but it answers a question every other NCA framework raises and none of them answer: who, exactly, is supposed to do this work?
Version 1.5 organises cybersecurity work in the Kingdom into five categories, twelve specialty areas and forty job roles, each with a defined set of Tasks, Knowledge and Skills. It is the national common vocabulary for job descriptions, recruitment, training design and career progression.
What the SCyWF is for
The NCA's mandate under Royal Order No. 6801 dated 31 October 2017 includes building national cybersecurity capacity, participating in the preparation of educational and training programmes, setting professional standards and frameworks, and developing standardised professional tests and measurements. The SCyWF is the foundational step towards that mandate.
Its stated purpose is to serve as a reference model and guideline for preparing, developing, recruiting, promoting and managing the cybersecurity workforce, providing a common lexicon that improves communication and content development for talent management, and helping map the learning outcomes of education and training programmes to the knowledge and skills each role requires.
The framework covers only job roles specific to cybersecurity. Non-cybersecurity roles that carry some cybersecurity responsibility — mostly IT roles — are explicitly out of scope, though the NCA notes that all employees and IT users are expected to have some awareness of cyber risk and good practice.
The taxonomy
The SCyWF is hierarchical: categories contain specialty areas, which contain job roles. Each level has an ID built from the first characters of its name, and job role IDs concatenate them — CARD-CA-001, PD-IR-004, ICSOT-ICSOT-003.
| Category | Specialty areas | What it covers |
|---|---|---|
| CARD Cybersecurity Architecture, Research and Development | Cybersecurity Architecture (CA) · Cybersecurity Research and Development (CRD) | Design, architecture, research and development activities. |
| LWD Leadership and Workforce Development | Leadership (L) · Workforce Development (WD) | Leading cybersecurity teams and work; developing cybersecurity human capital. |
| GRCL Governance, Risk, Compliance and Laws | Governance, Risk and Compliance (GRC) · Laws and Data Protection (LDP) | Policy development, governance structures and processes, cyber risk management, and compliance with cybersecurity, risk and legal requirements. |
| PD Protection and Defense | Defense (D) · Protection (P) · Vulnerability Assessment (VA) · Incident Response (IR) · Threat Management (TM) | Identifying, analysing, monitoring, mitigating and managing threats and vulnerabilities; defensive measures, event reporting and incident response. |
| ICS/OT Industrial Control Systems and Operational Technologies | ICS/OT | Governance, risk and compliance, design and development, operations and administration, and protection and defense for ICS and SCADA systems. |
The shape of the taxonomy is itself informative. Protection and Defense carries five of the twelve specialty areas — the operational half of the profession is where the NCA sees the most differentiation. And ICS/OT is a category in its own right rather than a specialty within defence, mirroring the OTCC's treatment of operational technology as a distinct discipline rather than an IT variant.
Tasks, Knowledge and Skills
Every job role is defined by a set of Tasks it performs and the Knowledge and Skills needed to perform them:
- Task — a set of activities that need to be completed as part of a particular job role.
- Knowledge — the set of data, facts, information, theories, concepts and issues related to a particular subject.
- Skill — the capability to apply knowledge and to use tools and methods to carry out a task.
Appendix B lists the complete TKS statement set, Appendix A gives the per-role detail, and Appendix C describes the competency areas introduced in this version.
A competency area is a group of related Knowledge and Skill statements reflecting the capability to perform tasks within a specific domain. The NCA positions them as a way to focus on specialised domains, align training and certifications with industry requirements, and support structured career development — while noting explicitly that professionals need not fully master every detail of every competency area linked to their role. They are a guide to relevant expertise, not a checklist.
Selected job roles
The forty roles cover the profession end to end. A representative sample:
| Role ID | Job role | Scope |
|---|---|---|
| LWD-L-001 | Chief Information Security Officer / Director | Directs cybersecurity work, sets vision and strategy, advises leadership on managing cyber risk. |
| GRCL-GRC-001 | Cybersecurity Risk Officer | Identifies, assesses and manages the organisation's cybersecurity risks. |
| GRCL-GRC-005 | Cybersecurity Auditor | Designs, performs and manages cybersecurity audits; prepares and communicates audit reports. |
| GRCL-LDP-002 | Data Protection Officer | Analyses data protection risks, ensures compliance with applicable laws, oversees data protection policies, supports incident response. |
| CARD-CRD-006 | Cybersecurity Artificial Intelligence Specialist | Uses AI and machine learning to design and implement algorithms and systems that automate and improve cybersecurity tasks. |
| PD-P-001 | Cryptography Specialist | Develops, evaluates and improves cryptography systems and algorithms, including quantum techniques. |
| PD-IR-004 | Malware Reverse Engineering Specialist | Disassembles and decompiles malicious software to establish behaviour, impact and intent. |
| PD-TM-002 | Threat Hunter | Proactively searches for undetected threats, identifies IOCs and recommends mitigation. |
| ICSOT-ICSOT-001 | ICS/OT Cybersecurity Architect | Designs and oversees cybersecurity systems and networks in ICS/OT environments. |
Two placements are worth noting for GRC teams. The Data Protection Officer sits in the Laws and Data Protection specialty alongside the Cybersecurity Legal Specialist — the NCA classifies data protection as a legal-and-compliance discipline, not a security-engineering one, which is the right read for a PDPL DPO appointment. And Cybersecurity Auditor sits under GRC rather than as an independent assurance role, so the independence requirements in CSCC control 1-4-2 still have to be arranged organisationally.
What changed in v1.5
Appendix D records seven updates:
- A new Career Progression companion document — the SCyWF-CP, defining structured pathways for professional growth, with progression routes, required qualifications and recommended experience levels for each job role.
- Abilities removed and replaced with Skills, aligning with global best practice.
- Competency Areas introduced in Appendix C.
- All TKS statements reviewed and rephrased, with some removed or split into more specific components.
- TKS-to-job-role mapping refined, with additions and removals per role.
- Skills classified as technical or non-technical, to support role-specific training and assessment design.
- Job role description updates for the Data Protection Officer, Cybersecurity Instructor and Cybersecurity Instructional Curriculum Developer roles.
The Career Progression document is the most practically useful addition. A framework that lists forty roles tells you what to hire for; a framework that maps the routes between them tells you how to keep the people you already have.
Why a GRC team should care
The SCyWF is not assessed, but it plugs a gap the assessed frameworks leave open. Several NCA control obligations are, in substance, workforce obligations:
- The ECC requires a cybersecurity function with defined roles and responsibilities, and a cybersecurity awareness and training programme with role-appropriate content. SCyWF role definitions and TKS statements are the natural source for both.
- The CSCC requires technical support and development positions for critical systems to be filled with experienced Saudi professionals — a requirement that needs a defensible definition of what those positions are and what "experienced" means for each. Role IDs and TKS statements provide it.
- The NFCRM requires a named liaison officer for cybersecurity risk management and engagement with the cybersecurity steering committee. Mapping those duties onto SCyWF roles makes the accountability explicit.
- The OTCC carries its own awareness and training subdomain for OT staff — and the SCyWF's four ICS/OT roles are where that training should be targeted.
Used well, the SCyWF turns "we have a cybersecurity team" into an evidenced org chart: named roles with IDs, TKS-based job descriptions, a training plan mapped to knowledge and skill gaps, and progression routes. That is materially easier to show an assessor than a headcount.
How to adopt it
- Map current staff onto SCyWF role IDs. Expect a messy first pass — real jobs usually span two or three framework roles. Record the spread rather than forcing a single match.
- Identify the roles you have no one in. Threat Hunter, Malware Reverse Engineering Specialist and the ICS/OT roles are the usual gaps, and they tell you what you are currently outsourcing whether or not you meant to.
- Rewrite job descriptions from the TKS statements, keeping the role ID visible so recruitment, training and assessment all reference the same anchor.
- Build the training plan from competency areas, and use the technical/non-technical skill classification to split technical training from leadership and communication development.
- Adopt the Career Progression document to define internal routes — this is what turns the framework from a hiring taxonomy into a retention tool.
- Keep the core structure intact while customising, so your workforce data stays comparable to the national picture.
How GRC Vantage supports SCyWF adoption
GRC Vantage's platform lets you attach SCyWF job role IDs to the people who own controls, so an assessment shows not only which control is covered but which defined role covers it — and where a control's owner sits in a role the organisation has not actually staffed. Awareness and training obligations under the ECC, OTCC and DCC are tracked against the competency areas and TKS statements behind each role, so the training record is evidence rather than an attendance list.
Where a control set imposes a workforce constraint — the CSCC's Saudi-professionals requirement, the NFCRM's liaison officer, the OTCC's OT-specific training — the platform holds that constraint against the named role and flags it when the role is vacant or reassigned.
For the full NCA family, see the NCA frameworks pillar guide and the related SCyber-Edu higher education framework. To align a cybersecurity org design to the SCyWF, talk to our team.
Book a demo with the GRC Vantage team in Riyadh or Dammam.
See Professional Services →Frequently asked questions
What is the SCyWF?
The Saudi Cybersecurity Workforce Framework is the NCA's reference model for cybersecurity work in the Kingdom. Version 1.5 organises the profession into five categories, twelve specialty areas and forty job roles, each defined by a set of Tasks, Knowledge and Skills, with competency areas grouping related knowledge and skills by domain.
Is SCyWF adoption mandatory?
No. The NCA recommends adoption so organisations can align their workforce structures with national frameworks, and permits customisation to meet organisational requirements — provided the core structure of the framework remains intact.
What are the five SCyWF categories?
Cybersecurity Architecture, Research and Development (CARD); Leadership and Workforce Development (LWD); Governance, Risk, Compliance and Laws (GRCL); Protection and Defense (PD); and Industrial Control Systems and Operational Technologies (ICS/OT).
Does the SCyWF cover IT roles?
No. It covers only job roles specific to cybersecurity. Non-cybersecurity roles that carry some cybersecurity responsibility — mostly IT roles — are outside its scope, although the NCA notes that all employees and IT users are expected to have cybersecurity awareness.
What changed in SCyWF v1.5?
Seven changes: a new Career Progression companion document (SCyWF-CP); Abilities removed and replaced with Skills; Competency Areas introduced; all TKS statements reviewed and rephrased; TKS-to-role mappings refined; skills classified as technical or non-technical; and updated descriptions for the Data Protection Officer, Cybersecurity Instructor and Cybersecurity Instructional Curriculum Developer roles.
- 1Primary Framework — NCANational Cybersecurity Authority (NCA), Kingdom of Saudi Arabia, 2026Source for the taxonomy (five categories, twelve specialty areas, forty job roles), the TKS and competency area definitions, the job role tables in sections 2.3 to 2.7, and the Appendix D list of v1.5 updates.
- 2Primary Framework — NCANational Cybersecurity Authority (NCA), 2026Supplementary document introduced in v1.5 defining progression routes, required qualifications and recommended experience levels for each job role.
- 3Primary Framework — NCANational Cybersecurity Authority (NCA), 2026Published 24/06/2026. Hosts the main framework document and the Career Progression guide.

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.
Related articles
A guide to the NCA SCyber-Edu framework — the seven cybersecurity degree programmes, their core knowledge units, and how employers can use it in hiring.
A guide to the NCA e-commerce cybersecurity guidelines — the seven CGESP categories for SME and SoHo sellers, and the consumer-facing CGEC companion document.
A guide to the NCA Cybersecurity Toolkits and Implementation Guides — around 90 free policy, standard and procedure templates, and how to use them properly.