National Cybersecurity Authority
The National Cybersecurity Authority (NCA) is Saudi Arabia's government cybersecurity regulator, established by Royal Order in 2017. It sets national cyber policy, licenses MSOC providers, operates Saudi CERT, and serves 1,600+ national entities via the Haseen portal.
- Company typePrivate
- Founded2017
- HeadquartersRiyadh, Saudi Arabia
- Headcount1–10
- GTM typeB2B
- OfferingServices
What National Cybersecurity Authority does
The National Cybersecurity Authority (NCA) is the government of Saudi Arabia's national authority on cybersecurity, established by Royal Order in 2017 and reporting directly to the King. It is the sole national regulator responsible for setting and enforcing cybersecurity policy, licensing Managed Security Operations Center (MSOC) providers, operating the Saudi Computer Emergency Response Team (Saudi CERT), and serving as the Kingdom's international point of contact on cyber matters. Its mandate spans critical infrastructure protection, national-level incident response, and capability development across the public and private sectors.
NCA's operational platform is anchored by the Haseen portal, which serves more than 1,600 national entities with compliance, reporting, and threat-information services. It also operates the recently launched Tahqaq service for individuals to verify online link legitimacy, and runs the MSOC licensing program — Tier 1 of which went live in August 2024 — which is the de facto market-access gate for managed security providers in Saudi Arabia. The authority hosts the annual Global Cybersecurity Forum and is a signatory to bilateral cyber cooperation MoUs with countries including Togo and Mozambique, while partnering domestically with NEOM on the CyberIC innovation initiative.
As a government entity, NCA does not operate a commercial revenue model. It is funded through the state budget and derives its authority from Royal Decree, including a December 2024 Royal Decree that formalized its legal powers to identify violations and pursue enforcement procedures. Its economic significance lies in shaping and gatekeeping the broader Saudi cybersecurity market — SAR 15.2 billion in 2024 — rather than in capturing that spending directly.
National Cybersecurity Authority firmographics
Firmographics- Name
- National Cybersecurity Authority
- Legal name
- National Cybersecurity Authority
- Website
- https://nca.gov.sa
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- The National Cybersecurity Authority (NCA) is Saudi Arabia's government cybersecurity regulator, established by Royal Order in 2017. It sets national cyber policy, licenses MSOC providers, operates Saudi CERT, and serves 1,600+ national entities via the Haseen portal.
- Ownership category
- akta.pro rank
National Cybersecurity Authority industry classification
Industry- Product category
- Government Cybersecurity Regulation
- NAICS
- Regulation and Administration of Communications, Electric, Gas, and Other Utilities (92613), Executive, Legislative, and Other General Government Support (921), Public Administration (92), Justice, Public Order, and Safety Activities (9221)
- akta.pro primary industry
- Regulatory Change Management (RCM) (HDADAIAG)
- akta.pro secondary industries
- Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC), Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF), Information Technology (IT) & Cybersecurity Certifications (EDAAANAA)
Keywords
Where National Cybersecurity Authority is headquartered
LocationHeadquarters
- HQ city
- Riyadh
- HQ country
- Saudi Arabia
- HQ region
- Middle East
Offices1 record
Markets served
National Cybersecurity Authority business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Regulatory and Licensing Services: NCA operates as a government regulatory authority. It generates revenue through licensing fees for Managed Security Operations Center (MSOC) service providers. The cybersecurity market in Saudi Arabia reached SAR 15.2 billion in 2024, with government entities accounting for SAR 4.8 billion (32%) and private sector SAR 10.3 billion (68%).
- Cybersecurity Services: NCA provides cybersecurity enablement programs, training, and awareness services to national entities through the Haseen portal. Services include Managed Detection and Response (MDR), penetration testing, vulnerability assessments, cybersecurity architecture, risk management, and governance advisory.
Go-to-market motion1 record
Distribution channels4 records
Marketing channels7 records
National Cybersecurity Authority product offering
Product offeringCore offering
NCA is Saudi Arabia's national cybersecurity regulatory authority that sets mandatory cybersecurity controls and frameworks, licenses Managed Security Operations Center (MSOC) providers, operates the Haseen national cybersecurity services portal delivering 24 services to over 1,600 entities, and provides cyber enablement programs, training, incident response through Saudi CERT, and public awareness services. The authority coordinates national cybersecurity governance, threat intelligence sharing, and workforce development for government entities, critical infrastructure operators, and private sector organizations in the Kingdom.
Product overview
The National Cybersecurity Authority (NCA) is Saudi Arabia's government regulatory body for cybersecurity, operating through a unified platform architecture centered on the Haseen Portal (National Cybersecurity Services Portal) which provides 24 services to over 1,600 national entities. The core offerings include cybersecurity compliance and assessment services (Essential Cybersecurity Controls, Cloud Cybersecurity Controls, Data Cybersecurity Controls, OT Cybersecurity Controls), incident response through Saudi CERT, and regulatory licensing for Managed Security Operations Center (MSOC) services with 16 licensed providers. Supporting services include training programs through the National Cybersecurity Academy, the Cyber Enablement Package offering 11 cyber services, Managed Detection and Response (MDR), and various awareness initiatives (Tahqaq link/file verification, Aamn awareness program, mobile exhibitions). The NCA also publishes regulatory documents including the National Framework for Cybersecurity Risk Management, Saudi Cybersecurity Workforce Framework, and Cybersecurity Toolkits with 50+ downloadable templates. Innovation programs include CyberIC, Cybersecurity Accelerator, and research grants under the National RDI Program.
Differentiator
Problem solved
Functional benefit
Brands
- Haseen: National Portal for Cybersecurity Services providing cybersecurity awareness, threat verification, file scanning, and training registration services
- National Cybersecurity Academy
- Saudi CERT
- Aamn
Quantifiable outcome
- Saudi Arabia ranked 1st globally in Cybersecurity Index (World Competitiveness Yearbook 2025)
- +4 more outcomes
Companies that use National Cybersecurity Authority
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles4 records
National Cybersecurity Authority technology and API
TechnologyAPI detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
National Cybersecurity Authority partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- Ministry of Education (MoE)coreNCA and MoE collaborate on cybersecurity awareness campaigns targeting students and parents. The partnership includes the 'A Secure Return to School' campaign covering topics like phishing, password security, parental control, and safe internet browsing.
- Carnegie Mellon UniversitycoreNCA collaborates with Carnegie Mellon University to launch the 'Global Summer Research in Cybersecurity' initiative, developing specialized national capabilities in cybersecurity research and innovation.
- Saudi Information Technology Company (SITE)coreSITE partnered with NCA to deliver the Tahqaq link verification service through WhatsApp and the Haseen portal, enabling public verification of suspicious links to reduce unauthorized data access risks.
- Togo and MozambiqueminorTogo and Mozambique signed an MoU for cybersecurity cooperation establishing framework for real-time information sharing, joint capacity building, and operational coordination between their Computer Security Incident Response Teams (CSIRTs).
- Saudi Information Technology Company (SITE)coreSITE serves as NCA's technical arm, delivering cybersecurity services through the Haseen portal, operating the National Cybersecurity Academy platform, and supporting MSOC services. Partnership involves technology development, service delivery, and national infrastructure protection.
- NEOMcoreNEOM partners with NCA on the CyberIC Innovation program to stimulate growth of the cybersecurity sector, encourage innovation, and support startups in the Kingdom. The initiative aims to attract local and global investment to the Saudi cybersecurity sector.
- Small and Medium Enterprises General Authority (Monsha'at)minorPartnership through the Cybersecurity Challenge program, represented by the Diligence Center, supporting the establishment of promising cybersecurity startups in collaboration with SITE.
- GCC CountriescoreNCA participates in the GCC Cybersecurity Executive Committee and coordinates with GCC countries on regional cybersecurity strategies, legislation, cross-border frameworks, and workforce development initiatives.
Scale indicators12 records
Recent moves7 records
Expansion highlights5 records
National Cybersecurity Authority competitors and assessment
Company assessmentDirect peers
- Bundesamt für Sicherheit in der Informationstechnik (BSI): Germany's federal cybersecurity authority responsible for IT security standards, certifications (similar to NCA's ECC framework), critical infrastructure protection, and national CERT operations. BSI's regulatory and standards-setting role closely parallels NCA's mandate across government and private sector entities.
- European Union Agency for Cybersecurity (ENISA): The EU's dedicated cybersecurity agency, responsible for EU-wide cybersecurity certifications, cross-border incident coordination, and capacity building. ENISA mirrors NCA's regulatory framework development (similar to ECC/CCC), workforce development programs, and pan-regional cooperation scope.
- Canadian Centre for Cyber Security (Cyber Centre): Canada's unified national cybersecurity authority providing incident response, threat intelligence, and cybersecurity guidance to government and critical infrastructure. Operates similarly to NCA in combining operational CERT, regulatory guidance, and national awareness functions under a single authority.
- Indian Computer Emergency Response Team (CERT-In): India's national CERT operating under the Ministry of Electronics and IT, providing incident response, threat intelligence, and cybersecurity coordination. While not a fully unified regulator, CERT-In's national incident handling, mandatory cyber incident reporting, and entity coordination functions parallel Saudi CERT's role within NCA.
- Agence nationale de la sécurité des systèmes d'information (ANSSI): France's national cybersecurity agency under the Secretariat-General for National Defence and Security. ANSSI issues binding cybersecurity regulations, operates the national CERT, certifies service providers (Qualification/PSP), and protects critical infrastructure — directly comparable to NCA's regulatory and operational functions.
- Cyber Security Agency of Singapore (CSA): Singapore's national cybersecurity authority overseeing cybersecurity policy, licensing of cybersecurity service providers, incident response, and workforce development. CSA's Cybersecurity Labelling Scheme and provider licensing closely resemble NCA's MSOC Tier 1/Tier 2 licensing model.
- National Cyber Security Centre (NCSC UK): UK's national cybersecurity authority under GCHQ, providing incident response, threat intelligence, regulatory guidance, and cybersecurity certifications. NCSC operates with comparable functions to NCA's Saudi CERT, control frameworks, and national cyber awareness programs.
- Cybersecurity and Infrastructure Security Agency (CISA): The US national cybersecurity and critical infrastructure protection agency. CISA is the closest functional peer to NCA: both are government-mandated national cybersecurity authorities with regulatory, incident response (via their CERT functions), and critical infrastructure protection mandates. Both operate nationwide portals for entity registration, compliance, and threat intelligence sharing.
- UAE Cyber Security Council: UAE's federal cybersecurity regulator established to develop and oversee national cybersecurity strategy, policies, and standards. Regional peer operating under similar Gulf state governance model with direct national mandate and equivalent focus on critical infrastructure and government entity compliance.
Emerging players
- National Cyber and Information Security Agency of the Czech Republic (NÚKIB): Czech Republic's national cybersecurity authority with regulatory and operational responsibilities over government, critical infrastructure, and national CERT functions. NÚKIB is a smaller-scale national cybersecurity regulator with comparable scope to NCA but at country-size scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
National Cybersecurity Authority social profiles
Digital presenceNational Cybersecurity Authority financial estimates
Financial estimateRevenue estimate
Valuation estimate
National Cybersecurity Authority leadership team
Management profileNumber of profiles
Profiles6 records
National Cybersecurity Authority subsidiaries and ownership
Company hierarchySubsidiaries3 records
National Cybersecurity Authority funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
National Cybersecurity Authority M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about National Cybersecurity Authority
What does National Cybersecurity Authority do?
NCA is Saudi Arabia's national cybersecurity regulatory authority that sets mandatory cybersecurity controls and frameworks, licenses Managed Security Operations Center (MSOC) providers, operates the Haseen national cybersecurity services portal delivering 24 services to over 1,600 entities, and provides cyber enablement programs, training, incident response through Saudi CERT, and public awareness services. The authority coordinates national cybersecurity governance, threat intelligence sharing, and workforce development for government entities, critical infrastructure operators, and private sector organizations in the Kingdom.
Is National Cybersecurity Authority a public or private company?
National Cybersecurity Authority is a private company. It is classified as state government owned and is currently operating.
When was National Cybersecurity Authority founded?
National Cybersecurity Authority was founded in 2017. It employs 1 to 10 people.
Where is National Cybersecurity Authority based?
National Cybersecurity Authority is headquartered in Riyadh, Saudi Arabia, in the Middle East region.
How does National Cybersecurity Authority make money?
Two revenue lines are on record. Regulatory and Licensing Services are the primary driver. The others are cybersecurity Services.
Who are National Cybersecurity Authority's main competitors?
Direct peers on record are Bundesamt für Sicherheit in der Informationstechnik (BSI), European Union Agency for Cybersecurity (ENISA), Canadian Centre for Cyber Security (Cyber Centre), Indian Computer Emergency Response Team (CERT-In), Agence nationale de la sécurité des systèmes d'information (ANSSI), Cyber Security Agency of Singapore (CSA), National Cyber Security Centre (NCSC UK), Cybersecurity and Infrastructure Security Agency (CISA) and UAE Cyber Security Council. National Cyber and Information Security Agency of the Czech Republic (NÚKIB) is listed as an emerging player.
Does National Cybersecurity Authority have an API?
No public API is recorded for National Cybersecurity Authority.
What industry is National Cybersecurity Authority in?
National Cybersecurity Authority's product category is Government Cybersecurity Regulation. Its primary akta.pro industry code is HDADAIAG, Regulatory Change Management (RCM), with a secondary code of HDADAJAC, Critical Infrastructure Protection (CIP) & NERC-CIP Compliance. Its NAICS code is 92613.