Tag · concept

Third-Party Risk

Managing risk from suppliers and vendors.

NCA CCC Compliance Checklist (Free Template)

A free NCA CCC-2:2024 compliance checklist — the provider and tenant control sets, all four classification levels, and the evidence each subdomain needs.

2026-08-26 · 6 min
NCA CCC: Cloud Cybersecurity Controls Explained

A guide to NCA Cloud Cybersecurity Controls (CCC-2:2024) — the CSP and CST control sets, four classification levels, and the data localisation change.

2026-08-26 · 12 min
NCA CGIoT: Internet of Things Security Guidelines

A guide to the NCA Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024) — four domains, 81 guidelines, and eleven principles for IoT manufacturers.

2026-08-26 · 10 min
NCA CSCC Compliance Checklist (Free Template)

A free NCA CSCC compliance checklist — the seven criticality criteria, all 21 subdomains, and the review, patching and testing cadences inspectors ask for.

2026-08-26 · 6 min
NCA CSCC: Critical Systems Cybersecurity Controls

A guide to NCA Critical Systems Cybersecurity Controls (CSCC) — the seven identification criteria, 32 controls, and the in-Kingdom access and hosting rules.

2026-08-26 · 11 min
NCA DCC Compliance Checklist (Free Template)

A free NCA DCC-1:2022 compliance checklist — the four classification levels, every control by data lifecycle stage, and the third-party sharing rules.

2026-08-26 · 6 min
NCA DCC: Data Cybersecurity Controls Explained

A guide to NCA Data Cybersecurity Controls (DCC-1:2022) — four classification levels, 19 controls across the data lifecycle, and third-party sharing rules.

2026-08-26 · 11 min
NCA MSOC: Saudi Managed SOC Policy and Licensing

A guide to the NCA National Policy for MSOC and the licensing framework — the Tier 1 requirement, the 90-day report, and what in-house SOCs must do next.

2026-08-26 · 13 min
NCA OSMACC: Social Media Account Security Controls

A guide to NCA OSMACC-1:2021 — the 15 controls protecting official Saudi social media accounts, from MFA and dedicated devices to impersonation monitoring.

2026-08-26 · 10 min
NCA OTCC: OT and ICS Cybersecurity Controls Guide

A guide to NCA Operational Technology Cybersecurity Controls (OTCC) — the three facility levels, 122 subcontrols, and the OT zone and remote access rules.

2026-08-26 · 11 min
SAMA BCM Compliance Checklist (Free Template)

A free SAMA BCM Framework compliance checklist — every lifecycle stage, evidence requirement and testing cadence Saudi banks need before an inspection.

2026-08-26 · 7 min
SAMA Counter-Fraud Framework: A Guide for Saudi Banks

A practitioner's guide to the SAMA Counter-Fraud Framework in 2026 — scope, the four domains, the maturity model, third-party due diligence and fraud reporting for Saudi banks.

2026-06-30 · 14 min
Third-Party Risk Assessment in Saudi Arabia: SAMA & PDPL

How Saudi organisations run third-party and vendor risk assessment in 2026 — tiering, due diligence, right-to-audit clauses and monitoring under SAMA, NCA ECC and PDPL.

2026-06-30 · 14 min
PDPL Cross-Border Transfers: Rules for Saudi Data

How to handle PDPL cross-border data transfers from Saudi Arabia — adequacy, safeguards, SaaS vendor flows, and data residency strategies explained.

2026-04-13 · 7 min