Developer docs
API playgroundTry for free, no card

Search company profiles

National Cybersecurity Authority

Full company profile

uuid006f5y2

Namestring
National Cybersecurity Authority
Legal namestring
National Cybersecurity Authority
Websiteurl
nca.gov.sa
Company typeenum
Private
Founded yearint
2017
Descriptiontext

The National Cybersecurity Authority (NCA) is the government of Saudi Arabia's national authority on cybersecurity, established by Royal Order in 2017 and reporting directly to the King. It is the sole national regulator responsible for setting and enforcing cybersecurity policy, licensing Managed Security Operations Center (MSOC) providers, operating the Saudi Computer Emergency Response Team (Saudi CERT), and serving as the Kingdom's international point of contact on cyber matters. Its mandate spans critical infrastructure protection, national-level incident response, and capability development across the public and private sectors.

NCA's operational platform is anchored by the Haseen portal, which serves more than 1,600 national entities with compliance, reporting, and threat-information services. It also operates the recently launched Tahqaq service for individuals to verify online link legitimacy, and runs the MSOC licensing program — Tier 1 of which went live in August 2024 — which is the de facto market-access gate for managed security providers in Saudi Arabia. The authority hosts the annual Global Cybersecurity Forum and is a signatory to bilateral cyber cooperation MoUs with countries including Togo and Mozambique, while partnering domestically with NEOM on the CyberIC innovation initiative.

As a government entity, NCA does not operate a commercial revenue model. It is funded through the state budget and derives its authority from Royal Decree, including a December 2024 Royal Decree that formalized its legal powers to identify violations and pursue enforcement procedures. Its economic significance lies in shaping and gatekeeping the broader Saudi cybersecurity market — SAR 15.2 billion in 2024 — rather than in capturing that spending directly.

Short descriptiontext

The National Cybersecurity Authority (NCA) is Saudi Arabia's government cybersecurity regulator, established by Royal Order in 2017. It sets national cyber policy, licenses MSOC providers, operates Saudi CERT, and serves 1,600+ national entities via the Haseen portal.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersRiyadh, Saudi Arabia
HQ citystring
Riyadh
HQ countrystring
Saudi Arabia
HQ regionstring
Middle East
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
national cybersecurity regulation, government cyber authority, cybersecurity compliance controls, managed security operations licensing, cyber threat intelligence
Industry4 codes
1Regulatory Change Management (RCM)
CodeHDADAIAGPrimaryYes
2Critical Infrastructure Protection (CIP) & NERC-CIP Compliance
CodeHDADAJACPrimaryNo
3Privacy, Data Protection & Cyber Governance (GRC)
CodeBPAHAFAFPrimaryNo
4Information Technology (IT) & Cybersecurity Certifications
CodeEDAAANAAPrimaryNo
NAICS code4 codes
  • Regulation and Administration of Communications, Electric, Gas, and Other Utilities92613
  • Executive, Legislative, and Other General Government Support921
  • Public Administration92
  • Justice, Public Order, and Safety Activities9221
Product category
Government Cybersecurity Regulation
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model2 records
1Regulatory and Licensing Services
TypeLicensing Royalties
Description

NCA operates as a government regulatory authority. It generates revenue through licensing fees for Managed Security Operations Center (MSOC) service providers. The cybersecurity market in Saudi Arabia reached SAR 15.2 billion in 2024, with government entities accounting for SAR 4.8 billion (32%) and private sector SAR 10.3 billion (68%).

nca.gov.sa
2Cybersecurity Services
TypeManaged Services
Description

NCA provides cybersecurity enablement programs, training, and awareness services to national entities through the Haseen portal. Services include Managed Detection and Response (MDR), penetration testing, vulnerability assessments, cybersecurity architecture, risk management, and governance advisory.

nca.gov.sa
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels4 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
GTM typeB2B
B2B
Offering typeServices
Services
Brand1 of 4 records shown
1Haseen
Description

National Portal for Cybersecurity Services providing cybersecurity awareness, threat verification, file scanning, and training registration services

saudigazette.com.sa
+3 more records
Core offering1 text field

NCA is Saudi Arabia's national cybersecurity regulatory authority that sets mandatory cybersecurity controls and frameworks, licenses Managed Security Operations Center (MSOC) providers, operates the Haseen national cybersecurity services portal delivering 24 services to over 1,600 entities, and provides cyber enablement programs, training, incident response through Saudi CERT, and public awareness services. The authority coordinates national cybersecurity governance, threat intelligence sharing, and workforce development for government entities, critical infrastructure operators, and private sector organizations in the Kingdom.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 5 values shown
  • Saudi Arabia ranked 1st globally in Cybersecurity Index (World Competitiveness Yearbook 2025)
+4 more records
Product overview1 text field

The National Cybersecurity Authority (NCA) is Saudi Arabia's government regulatory body for cybersecurity, operating through a unified platform architecture centered on the Haseen Portal (National Cybersecurity Services Portal) which provides 24 services to over 1,600 national entities. The core offerings include cybersecurity compliance and assessment services (Essential Cybersecurity Controls, Cloud Cybersecurity Controls, Data Cybersecurity Controls, OT Cybersecurity Controls), incident response through Saudi CERT, and regulatory licensing for Managed Security Operations Center (MSOC) services with 16 licensed providers. Supporting services include training programs through the National Cybersecurity Academy, the Cyber Enablement Package offering 11 cyber services, Managed Detection and Response (MDR), and various awareness initiatives (Tahqaq link/file verification, Aamn awareness program, mobile exhibitions). The NCA also publishes regulatory documents including the National Framework for Cybersecurity Risk Management, Saudi Cybersecurity Workforce Framework, and Cybersecurity Toolkits with 50+ downloadable templates. Innovation programs include CyberIC, Cybersecurity Accelerator, and research grants under the National RDI Program.

Scale indicator12 records

Each record includes

Type, Value, Description, Source

Partnership8 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-08-24
Description

NCA and MoE collaborate on cybersecurity awareness campaigns targeting students and parents. The partnership includes the 'A Secure Return to School' campaign covering topics like phishing, password security, parental control, and safe internet browsing.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-07-06
Description

NCA collaborates with Carnegie Mellon University to launch the 'Global Summer Research in Cybersecurity' initiative, developing specialized national capabilities in cybersecurity research and innovation.

3Saudi Information Technology Company (SITE)
Strategic tierCoreTypeTechnology or IntegrationAnnounced on2025-12-28
Description

SITE partnered with NCA to deliver the Tahqaq link verification service through WhatsApp and the Haseen portal, enabling public verification of suspicious links to reduce unauthorized data access risks.

saudigazette.com.sa
4Togo and Mozambique
Strategic tierMinorTypeStrategic or Co-development PartnerAnnounced on2025-11-21
Description

Togo and Mozambique signed an MoU for cybersecurity cooperation establishing framework for real-time information sharing, joint capacity building, and operational coordination between their Computer Security Incident Response Teams (CSIRTs).

telecomreviewafrica.com
5Saudi Information Technology Company (SITE)
Strategic tierCoreTypeTechnology or Integration
Description

SITE serves as NCA's technical arm, delivering cybersecurity services through the Haseen portal, operating the National Cybersecurity Academy platform, and supporting MSOC services. Partnership involves technology development, service delivery, and national infrastructure protection.

nca.gov.sa
Strategic tierCoreTypeStrategic or Co-development Partner
Description

NEOM partners with NCA on the CyberIC Innovation program to stimulate growth of the cybersecurity sector, encourage innovation, and support startups in the Kingdom. The initiative aims to attract local and global investment to the Saudi cybersecurity sector.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

Partnership through the Cybersecurity Challenge program, represented by the Diligence Center, supporting the establishment of promising cybersecurity startups in collaboration with SITE.

8GCC Countries
Strategic tierCoreTypeStrategic or Co-development Partner
Description

NCA participates in the GCC Cybersecurity Executive Committee and coordinates with GCC countries on regional cybersecurity strategies, legislation, cross-border frameworks, and workforce development initiatives.

weforum.org
Recent move7 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Peers10 records
1Bundesamt für Sicherheit in der Informationstechnik (BSI)
TypeDirect peer
Description

Germany's federal cybersecurity authority responsible for IT security standards, certifications (similar to NCA's ECC framework), critical infrastructure protection, and national CERT operations. BSI's regulatory and standards-setting role closely parallels NCA's mandate across government and private sector entities.

2European Union Agency for Cybersecurity (ENISA)
TypeDirect peer
Description

The EU's dedicated cybersecurity agency, responsible for EU-wide cybersecurity certifications, cross-border incident coordination, and capacity building. ENISA mirrors NCA's regulatory framework development (similar to ECC/CCC), workforce development programs, and pan-regional cooperation scope.

TypeDirect peer
Description

Canada's unified national cybersecurity authority providing incident response, threat intelligence, and cybersecurity guidance to government and critical infrastructure. Operates similarly to NCA in combining operational CERT, regulatory guidance, and national awareness functions under a single authority.

4Indian Computer Emergency Response Team (CERT-In)
TypeDirect peer
Description

India's national CERT operating under the Ministry of Electronics and IT, providing incident response, threat intelligence, and cybersecurity coordination. While not a fully unified regulator, CERT-In's national incident handling, mandatory cyber incident reporting, and entity coordination functions parallel Saudi CERT's role within NCA.

TypeDirect peer
Description

France's national cybersecurity agency under the Secretariat-General for National Defence and Security. ANSSI issues binding cybersecurity regulations, operates the national CERT, certifies service providers (Qualification/PSP), and protects critical infrastructure — directly comparable to NCA's regulatory and operational functions.

TypeDirect peer
Description

Singapore's national cybersecurity authority overseeing cybersecurity policy, licensing of cybersecurity service providers, incident response, and workforce development. CSA's Cybersecurity Labelling Scheme and provider licensing closely resemble NCA's MSOC Tier 1/Tier 2 licensing model.

TypeDirect peer
Description

UK's national cybersecurity authority under GCHQ, providing incident response, threat intelligence, regulatory guidance, and cybersecurity certifications. NCSC operates with comparable functions to NCA's Saudi CERT, control frameworks, and national cyber awareness programs.

TypeDirect peer
Description

The US national cybersecurity and critical infrastructure protection agency. CISA is the closest functional peer to NCA: both are government-mandated national cybersecurity authorities with regulatory, incident response (via their CERT functions), and critical infrastructure protection mandates. Both operate nationwide portals for entity registration, compliance, and threat intelligence sharing.

9National Cyber and Information Security Agency of the Czech Republic (NÚKIB)
TypeEmerging player
Description

Czech Republic's national cybersecurity authority with regulatory and operational responsibilities over government, critical infrastructure, and national CERT functions. NÚKIB is a smaller-scale national cybersecurity regulator with comparable scope to NCA but at country-size scale.

TypeDirect peer
Description

UAE's federal cybersecurity regulator established to develop and oversee national cybersecurity strategy, policies, and standards. Regional peer operating under similar Gulf state governance model with direct national mandate and equivalent focus on critical infrastructure and government entity compliance.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers4 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature4 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles6 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries3 records

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

National Cybersecurity Authority

Government Cybersecurity Regulationnca.gov.sa

The National Cybersecurity Authority (NCA) is Saudi Arabia's government cybersecurity regulator, established by Royal Order in 2017. It sets national cyber policy, licenses MSOC providers, operates Saudi CERT, and serves 1,600+ national entities via the Haseen portal.

What National Cybersecurity Authority does

The National Cybersecurity Authority (NCA) is the government of Saudi Arabia's national authority on cybersecurity, established by Royal Order in 2017 and reporting directly to the King. It is the sole national regulator responsible for setting and enforcing cybersecurity policy, licensing Managed Security Operations Center (MSOC) providers, operating the Saudi Computer Emergency Response Team (Saudi CERT), and serving as the Kingdom's international point of contact on cyber matters. Its mandate spans critical infrastructure protection, national-level incident response, and capability development across the public and private sectors.

NCA's operational platform is anchored by the Haseen portal, which serves more than 1,600 national entities with compliance, reporting, and threat-information services. It also operates the recently launched Tahqaq service for individuals to verify online link legitimacy, and runs the MSOC licensing program — Tier 1 of which went live in August 2024 — which is the de facto market-access gate for managed security providers in Saudi Arabia. The authority hosts the annual Global Cybersecurity Forum and is a signatory to bilateral cyber cooperation MoUs with countries including Togo and Mozambique, while partnering domestically with NEOM on the CyberIC innovation initiative.

As a government entity, NCA does not operate a commercial revenue model. It is funded through the state budget and derives its authority from Royal Decree, including a December 2024 Royal Decree that formalized its legal powers to identify violations and pursue enforcement procedures. Its economic significance lies in shaping and gatekeeping the broader Saudi cybersecurity market — SAR 15.2 billion in 2024 — rather than in capturing that spending directly.

National Cybersecurity Authority firmographics

Firmographics
Name
National Cybersecurity Authority
Legal name
National Cybersecurity Authority
Website
https://nca.gov.sa
Company type
Private
Founded year
2017
Operating status
Operating
Headcount range
1–10 employees
Short description
The National Cybersecurity Authority (NCA) is Saudi Arabia's government cybersecurity regulator, established by Royal Order in 2017. It sets national cyber policy, licenses MSOC providers, operates Saudi CERT, and serves 1,600+ national entities via the Haseen portal.
Ownership category
akta.pro rank

National Cybersecurity Authority industry classification

Industry
Product category
Government Cybersecurity Regulation
NAICS
Regulation and Administration of Communications, Electric, Gas, and Other Utilities (92613), Executive, Legislative, and Other General Government Support (921), Public Administration (92), Justice, Public Order, and Safety Activities (9221)
akta.pro primary industry
Regulatory Change Management (RCM) (HDADAIAG)
akta.pro secondary industries
Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC), Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF), Information Technology (IT) & Cybersecurity Certifications (EDAAANAA)

Keywords

  • National cybersecurity regulation
  • Government cyber authority
  • Cybersecurity compliance controls
  • Managed security operations licensing
  • Cyber threat intelligence

Where National Cybersecurity Authority is headquartered

Location

Headquarters

HQ city
Riyadh
HQ country
Saudi Arabia
HQ region
Middle East

Offices1 record

Markets served

National Cybersecurity Authority business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure

Revenue model

  1. Regulatory and Licensing Services: NCA operates as a government regulatory authority. It generates revenue through licensing fees for Managed Security Operations Center (MSOC) service providers. The cybersecurity market in Saudi Arabia reached SAR 15.2 billion in 2024, with government entities accounting for SAR 4.8 billion (32%) and private sector SAR 10.3 billion (68%).
  2. Cybersecurity Services: NCA provides cybersecurity enablement programs, training, and awareness services to national entities through the Haseen portal. Services include Managed Detection and Response (MDR), penetration testing, vulnerability assessments, cybersecurity architecture, risk management, and governance advisory.

Go-to-market motion1 record

Distribution channels4 records

Marketing channels7 records

National Cybersecurity Authority product offering

Product offering

Core offering

NCA is Saudi Arabia's national cybersecurity regulatory authority that sets mandatory cybersecurity controls and frameworks, licenses Managed Security Operations Center (MSOC) providers, operates the Haseen national cybersecurity services portal delivering 24 services to over 1,600 entities, and provides cyber enablement programs, training, incident response through Saudi CERT, and public awareness services. The authority coordinates national cybersecurity governance, threat intelligence sharing, and workforce development for government entities, critical infrastructure operators, and private sector organizations in the Kingdom.

Product overview

The National Cybersecurity Authority (NCA) is Saudi Arabia's government regulatory body for cybersecurity, operating through a unified platform architecture centered on the Haseen Portal (National Cybersecurity Services Portal) which provides 24 services to over 1,600 national entities. The core offerings include cybersecurity compliance and assessment services (Essential Cybersecurity Controls, Cloud Cybersecurity Controls, Data Cybersecurity Controls, OT Cybersecurity Controls), incident response through Saudi CERT, and regulatory licensing for Managed Security Operations Center (MSOC) services with 16 licensed providers. Supporting services include training programs through the National Cybersecurity Academy, the Cyber Enablement Package offering 11 cyber services, Managed Detection and Response (MDR), and various awareness initiatives (Tahqaq link/file verification, Aamn awareness program, mobile exhibitions). The NCA also publishes regulatory documents including the National Framework for Cybersecurity Risk Management, Saudi Cybersecurity Workforce Framework, and Cybersecurity Toolkits with 50+ downloadable templates. Innovation programs include CyberIC, Cybersecurity Accelerator, and research grants under the National RDI Program.

Differentiator

Problem solved

Functional benefit

Brands

  • Haseen: National Portal for Cybersecurity Services providing cybersecurity awareness, threat verification, file scanning, and training registration services
  • National Cybersecurity Academy
  • Saudi CERT
  • Aamn

Quantifiable outcome

  • Saudi Arabia ranked 1st globally in Cybersecurity Index (World Competitiveness Yearbook 2025)
  • +4 more outcomes

Companies that use National Cybersecurity Authority

Customer profile

Named customers4 records

Segments4 records

Ideal customer profiles4 records

National Cybersecurity Authority technology and API

Technology

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature4 records

National Cybersecurity Authority partnerships and signals

Strategic signal

Partnerships

Eight partnerships are on record, tiered core and minor.

  • Ministry of Education (MoE)coreStrategic or Co-development Partner · 24 August 2026NCA and MoE collaborate on cybersecurity awareness campaigns targeting students and parents. The partnership includes the 'A Secure Return to School' campaign covering topics like phishing, password security, parental control, and safe internet browsing.
  • Carnegie Mellon UniversitycoreStrategic or Co-development Partner · 6 July 2026NCA collaborates with Carnegie Mellon University to launch the 'Global Summer Research in Cybersecurity' initiative, developing specialized national capabilities in cybersecurity research and innovation.
  • Saudi Information Technology Company (SITE)coreTechnology or Integration · 28 December 2025SITE partnered with NCA to deliver the Tahqaq link verification service through WhatsApp and the Haseen portal, enabling public verification of suspicious links to reduce unauthorized data access risks.
  • Togo and MozambiqueminorStrategic or Co-development Partner · 21 November 2025Togo and Mozambique signed an MoU for cybersecurity cooperation establishing framework for real-time information sharing, joint capacity building, and operational coordination between their Computer Security Incident Response Teams (CSIRTs).
  • Saudi Information Technology Company (SITE)coreTechnology or IntegrationSITE serves as NCA's technical arm, delivering cybersecurity services through the Haseen portal, operating the National Cybersecurity Academy platform, and supporting MSOC services. Partnership involves technology development, service delivery, and national infrastructure protection.
  • NEOMcoreStrategic or Co-development PartnerNEOM partners with NCA on the CyberIC Innovation program to stimulate growth of the cybersecurity sector, encourage innovation, and support startups in the Kingdom. The initiative aims to attract local and global investment to the Saudi cybersecurity sector.
  • Small and Medium Enterprises General Authority (Monsha'at)minorStrategic or Co-development PartnerPartnership through the Cybersecurity Challenge program, represented by the Diligence Center, supporting the establishment of promising cybersecurity startups in collaboration with SITE.
  • GCC CountriescoreStrategic or Co-development PartnerNCA participates in the GCC Cybersecurity Executive Committee and coordinates with GCC countries on regional cybersecurity strategies, legislation, cross-border frameworks, and workforce development initiatives.

Scale indicators12 records

Recent moves7 records

Expansion highlights5 records

National Cybersecurity Authority competitors and assessment

Company assessment

Direct peers

  • Bundesamt für Sicherheit in der Informationstechnik (BSI): Germany's federal cybersecurity authority responsible for IT security standards, certifications (similar to NCA's ECC framework), critical infrastructure protection, and national CERT operations. BSI's regulatory and standards-setting role closely parallels NCA's mandate across government and private sector entities.
  • European Union Agency for Cybersecurity (ENISA): The EU's dedicated cybersecurity agency, responsible for EU-wide cybersecurity certifications, cross-border incident coordination, and capacity building. ENISA mirrors NCA's regulatory framework development (similar to ECC/CCC), workforce development programs, and pan-regional cooperation scope.
  • Canadian Centre for Cyber Security (Cyber Centre): Canada's unified national cybersecurity authority providing incident response, threat intelligence, and cybersecurity guidance to government and critical infrastructure. Operates similarly to NCA in combining operational CERT, regulatory guidance, and national awareness functions under a single authority.
  • Indian Computer Emergency Response Team (CERT-In): India's national CERT operating under the Ministry of Electronics and IT, providing incident response, threat intelligence, and cybersecurity coordination. While not a fully unified regulator, CERT-In's national incident handling, mandatory cyber incident reporting, and entity coordination functions parallel Saudi CERT's role within NCA.
  • Agence nationale de la sécurité des systèmes d'information (ANSSI): France's national cybersecurity agency under the Secretariat-General for National Defence and Security. ANSSI issues binding cybersecurity regulations, operates the national CERT, certifies service providers (Qualification/PSP), and protects critical infrastructure — directly comparable to NCA's regulatory and operational functions.
  • Cyber Security Agency of Singapore (CSA): Singapore's national cybersecurity authority overseeing cybersecurity policy, licensing of cybersecurity service providers, incident response, and workforce development. CSA's Cybersecurity Labelling Scheme and provider licensing closely resemble NCA's MSOC Tier 1/Tier 2 licensing model.
  • National Cyber Security Centre (NCSC UK): UK's national cybersecurity authority under GCHQ, providing incident response, threat intelligence, regulatory guidance, and cybersecurity certifications. NCSC operates with comparable functions to NCA's Saudi CERT, control frameworks, and national cyber awareness programs.
  • Cybersecurity and Infrastructure Security Agency (CISA): The US national cybersecurity and critical infrastructure protection agency. CISA is the closest functional peer to NCA: both are government-mandated national cybersecurity authorities with regulatory, incident response (via their CERT functions), and critical infrastructure protection mandates. Both operate nationwide portals for entity registration, compliance, and threat intelligence sharing.
  • UAE Cyber Security Council: UAE's federal cybersecurity regulator established to develop and oversee national cybersecurity strategy, policies, and standards. Regional peer operating under similar Gulf state governance model with direct national mandate and equivalent focus on critical infrastructure and government entity compliance.

Emerging players

  • National Cyber and Information Security Agency of the Czech Republic (NÚKIB): Czech Republic's national cybersecurity authority with regulatory and operational responsibilities over government, critical infrastructure, and national CERT functions. NÚKIB is a smaller-scale national cybersecurity regulator with comparable scope to NCA but at country-size scale.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks5 records

Key highlights7 records

Customer concentration

National Cybersecurity Authority social profiles

Digital presence

National Cybersecurity Authority financial estimates

Financial estimate

Revenue estimate

Valuation estimate

National Cybersecurity Authority leadership team

Management profile

Number of profiles

Profiles6 records

National Cybersecurity Authority subsidiaries and ownership

Company hierarchy

Subsidiaries3 records

National Cybersecurity Authority funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

National Cybersecurity Authority M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about National Cybersecurity Authority

What does National Cybersecurity Authority do?

NCA is Saudi Arabia's national cybersecurity regulatory authority that sets mandatory cybersecurity controls and frameworks, licenses Managed Security Operations Center (MSOC) providers, operates the Haseen national cybersecurity services portal delivering 24 services to over 1,600 entities, and provides cyber enablement programs, training, incident response through Saudi CERT, and public awareness services. The authority coordinates national cybersecurity governance, threat intelligence sharing, and workforce development for government entities, critical infrastructure operators, and private sector organizations in the Kingdom.

Is National Cybersecurity Authority a public or private company?

National Cybersecurity Authority is a private company. It is classified as state government owned and is currently operating.

When was National Cybersecurity Authority founded?

National Cybersecurity Authority was founded in 2017. It employs 1 to 10 people.

Where is National Cybersecurity Authority based?

National Cybersecurity Authority is headquartered in Riyadh, Saudi Arabia, in the Middle East region.

How does National Cybersecurity Authority make money?

Two revenue lines are on record. Regulatory and Licensing Services are the primary driver. The others are cybersecurity Services.

Who are National Cybersecurity Authority's main competitors?

Direct peers on record are Bundesamt für Sicherheit in der Informationstechnik (BSI), European Union Agency for Cybersecurity (ENISA), Canadian Centre for Cyber Security (Cyber Centre), Indian Computer Emergency Response Team (CERT-In), Agence nationale de la sécurité des systèmes d'information (ANSSI), Cyber Security Agency of Singapore (CSA), National Cyber Security Centre (NCSC UK), Cybersecurity and Infrastructure Security Agency (CISA) and UAE Cyber Security Council. National Cyber and Information Security Agency of the Czech Republic (NÚKIB) is listed as an emerging player.

Does National Cybersecurity Authority have an API?

No public API is recorded for National Cybersecurity Authority.

What industry is National Cybersecurity Authority in?

National Cybersecurity Authority's product category is Government Cybersecurity Regulation. Its primary akta.pro industry code is HDADAIAG, Regulatory Change Management (RCM), with a secondary code of HDADAJAC, Critical Infrastructure Protection (CIP) & NERC-CIP Compliance. Its NAICS code is 92613.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
TechJuicePakistan, Saudi Arabia Sign a Cybersecurity MoU at LEAP 2026Pakistan and Saudi Arabia signed a cybersecurity MoU at LEAP 2026 in Riyadh, linking Pakistan's IT ministry with Saudi Arabia's National Cybersecurity Authority. The agreement aims to protect cyberspace and address emerging threats, with joint workshops planned to align Pakistan's IT strategy with Saudi Vision 2030.TelecompaperSalam obtains Tier 2 managed security operations centre service licence from National Cybersecurity AuthoritySalam (Etihad Salam Telecom Company), a Saudi telecom operator, has received a five-year license from the National Cybersecurity Authority to provide Tier 2 Managed Security Operations Center services. The authorization enables Salam to offer MSOC cybersecurity monitoring and management services under NCA regulation. The licensing represents a regulatory approval for Salam to expand its service portfolio in the cybersecurity space.TechAfrica NewsUN Opens Dedicated Cybersecurity Office in Riyadh to Strengthen Global ResilienceUNITAR opened its first dedicated cybersecurity office in Riyadh, Saudi Arabia, the third in its network. The office will work with Saudi's National Cybersecurity Authority to build skills and knowledge exchange. It supports the 2025 Global Initiative for Capacity Building in Cyberspace.Saudi Gazette/National Cybersecurity Authority launches service to verify suspicious linksSaudi Arabia's National Cybersecurity Authority has launched the "Tahqaq" service, enabling the public to scan and verify the reliability of suspicious links before visiting them to reduce risks of unauthorized data access. The service is available through WhatsApp and the Haseen government cybersecurity portal, delivered in partnership with the authority's technical arm, the Saudi Information Technology Company (SITE). This initiative forms part of broader strategic programs aimed at enhancing cybersecurity awareness and mitigating emerging cyber risks across all segments of Saudi society.CmsData protection and cybersecurity laws in ChileChile has enacted Law No. 21.719 on the Protection of Personal Data, which modernizes its legal framework to align with international standards like the GDPR and establishes a dedicated Data Protection Authority (APDP) set to become operational in December 2026. Additionally, the Cybersecurity Framework Law No. 21.663 created the National Cybersecurity Agency (ANCI) to oversee cybersecurity policies and impose sanctions for non-compliance by entities managing critical information infrastructure.International Association of Privacy ProfessionalsBrazil set to adopt Cybersecurity Legal FrameworkBrazil is poised to approve Bill No. 4752/2025, which establishes a National Cybersecurity Authority (ANC) and introduces a comprehensive legal framework for cybersecurity in both public and private sectors. The legislation mandates compliance for public procurement, requires supply chain risk assessments, and incentivizes national technology development to address recent cyber vulnerabilities. If enacted, this framework will unify previously fragmented policies under the ANC's regulatory oversight.PR NewswireO "Child Online Safety Index" revela uma "ciberpandemia persistente". O relatório do Instituto DQ mostra uma exposição consistente de 70% ao risco cibernético entre as crianças.O DQ Institute lançou em Riade, na Arábia Saudita, o Child Online Safety Index (COSI) de 2023, revelando que quase 70% das crianças e adolescentes com idades entre 8 e 18 anos em todo o mundo enfrentaram pelo menos um risco cibernético no ano passado, uma taxa que se manteve praticamente inalterada desde 2018. O instituto classificou esta situação de "pandemia cibernética persistente" e alertou que a rápida implantação de IA generativa, metaverso e dispositivos de realidade expandida agrava os riscos para as crianças. O índice, que contou com uma amostra de 351.376 crianças desde 2017 e foi apresentado no Global Cybersecurity Forum, avalia 100 países em seis dimensões, com destaque para o Reino Unido, a Alemanha e a China como melhores desempenhos globais.PR NewswireHajj Ministry: Digital Transformation and Safe Cyber EnvironmentSaudi Arabia's Ministry of Hajj and Umrah provides 121 e-services to 30 million people and pilgrims, ranking 8th among 217 government entities in the Saudi Digital Transformation Index and 11th among G20 nations. The Ministry issued over 50 million Umrah permissions and served 30 million beneficiaries during 2023, while the National Cyber-Security Authority conducted a cyber-security exercise on May 28th to protect pilgrims' data against various attacks.