Gulf Cooperation Council

External attack surface management for Saudi organisations

Saudi Arabia’s controls name the internet-facing estate more directly than almost anywhere else. The NCA’s ECC sets penetration test scope as every service you provide over the internet, NCNICC makes periodic scanning of external applications mandatory for private companies it applies to, and SAMA requires asset processes that discover new assets. EASMLens shows you that estate from outside, continuously.

Serving organisations in Riyadh, Jeddah, Dammam, Khobar.

What the rules in Saudi Arabia expect

Essential Cybersecurity Controls, ECC-2:2024

The ECC apply to government entities and their companies and to private entities that own, operate or host critical national infrastructure. Control 2-1 expects an accurate, up-to-date inventory of all information and technology assets. Control 2-11-3-1 sets the scope of penetration testing as all services provided externally over the internet and their technical components: infrastructure, websites, web applications, mobile apps, email and remote access.

ECC also requires email domains to be validated with SPF, DKIM and DMARC (2-4-3-5), DNS security (2-5-3-7), periodic vulnerability assessment (2-10-3-1) and protection of external web applications (2-15). One common error is worth correcting: ECC-2:2024 sets no numeric scanning frequency. The monthly external and quarterly internal figures come from CSCC-1:2019 and apply to critical systems only.

NCNICC-1:2025 for the private sector

The NCA published the Non-CNI Private Sector Entities Cybersecurity Controls (NCNICC-1:2025) in Arabic in December 2025. They bind private companies outside critical national infrastructure to which the NCA circulates them. Category A (over 250 staff or over SAR 200 million revenue) has 65 mandatory controls and Category B has 26.

Several are attack surface controls in both categories: periodic vulnerability scanning of external applications (2-10-1-3), documenting the entity’s email domain on the Haseen platform with SPF, DKIM and DMARC (2-4-1-2), and asset management (2-1). Category A must also use a brand protection service against impersonation (2-7-1-2) and scan all assets periodically (2-10-1-2).

SAMA Cyber Security Framework

For banks, finance companies and payment firms, the SAMA Cyber Security Framework requires a unified, accurate asset register whose process includes the discovery of new information assets (3.3.3), a risk-based vulnerability management process covering all information assets (3.3.17), and annual review and penetration testing of customer and internet-facing services (3.2.4). Medium and high incidents must be reported to SAMA immediately.

What is exposed in practice

Saudi CERT publishes a steady stream of critical alerts on internet-facing products; the week of 27 September 2026 alone covered Citrix, F5, ManageEngine and WatchGuard. Researchers reported in 2024 that a ministry environment file containing credentials had been visible to internet search engines since 2022. Passive internet datasets often see these exposures long before the owner does.

What each rule asks for, and what EASMLens shows you

RuleWhat it asks forWhat EASMLens shows you
ECC 2-11-3-1 and NCNICC 2-11-1Penetration test scope covers every internet-provided serviceA complete list of internet-facing services, so the test scope has no gaps
NCNICC 2-10-1-3Periodic vulnerability scanning of external applications (Cat A and B)Every external application attributed to you, with exposure findings to feed scanning
ECC 2-4-3-5 and NCNICC 2-4-1-2SPF, DKIM and DMARC; email domain documented on HaseenSPF, DKIM and DMARC status for every domain, including subsidiaries and campaign domains
SAMA CSF 3.3.3Asset process includes discovery of new information assetsNewly appearing domains, hosts and certificates, flagged within hours
NCNICC 2-7-1-2Brand protection against impersonation (Cat A)Spoofable domains and email posture that make impersonation easier

Reporting clocks

  • SAMA-regulated entities

    Immediately for medium and high classified incidents

  • ECC and NCNICC entities

    Notify the NCA when an incident occurs

  • PDPL controllers

    72 hours to SDAIA after becoming aware of a breach

Questions for the board

  1. 1Could we produce, today, the full list of internet-facing services our penetration test must cover under ECC 2-11-3-1, and who reconciles it with what attackers can see?
  2. 2Is every domain we own, including subsidiaries and campaign domains, registered on Haseen with SPF, DKIM and DMARC?
  3. 3If the NCA has circulated NCNICC to us, which category are we in, and is periodic scanning of external applications evidenced?

How EASMLens supports these obligations

  • Continuous discovery of every internet-facing service, website, application and remote access point
  • SPF, DKIM, DMARC and DNSSEC grading across all domains, with spoofability flagged
  • Change detection that evidences SAMA’s discovery of new information assets
  • Exposure intelligence mapped to Saudi CERT alerts on edge and web products
The NCA requires registration of entities that provide cybersecurity solutions, services or products in the Kingdom through the Haseen licensing portal, and licenses managed SOC providers separately. EASMLens is a software platform with automated vulnerability checks, not a managed SOC. Saudi customers should confirm registration status with us during procurement.

EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Does ECC-2:2024 require monthly external scanning?
No. ECC-2:2024 requires periodic vulnerability assessment without a numeric frequency. The monthly external and quarterly internal figures come from CSCC-1:2019 and apply to critical systems only.
Does NCNICC apply to every private company?
It binds private entities outside critical national infrastructure to which the NCA circulates it, split into Category A and Category B. Micro entities, government and CNI are excluded.
Is there Arabic content?
NCNICC is published in Arabic only, and the Arabic ECC text prevails. Contact us for Arabic-language material for your team or board.