The Legal Authorities of the National Cybersecurity Authority

Show Law Preamble
  • Decision No. (409) dated 16/06/1446 AH

  • The Council of Ministers

  • After reviewing the correspondence received from the Royal Court No. 23784 dated 4/4/1446 AH, including the telegram of His Excellency the Chairman of the Board of the National Cybersecurity Authority No. 33 dated 10/1/1444 AH, regarding the regulatory enablers of the Authority.

  • And after reviewingthe Statute of the National Cybersecurity Authority, issued by Royal Order No. (6801) dated 11/2/1439 AH.

  • And after reviewing the server Process No. (217) dated 14/7/1444 AH, memoranda No. (1152) dated 7/4/1445 AH, No. (2926) dated 11/8/1445 AH, No. (4274) dated 18/12/1445 AH, and No. (1445) dated 25/4/1446 AH, prepared by the Bureau of Experts at the Council of Ministers.

  • And after reviewing the telegram of the Secretariat of the Council of Political and Security Affairs No. 9927 dated 19/7/1445 AH.

  • And after considering the Shura Council decision No. (16/3) dated 28/3/1446 AH.

  • And after reviewing the recommendation of the General Committee of the Council of Ministers No. (4624) dated 5/5/1446 AH.

  • It is decided as follows:

    • First: Approval of the regulatory enablers of the National Cybersecurity Authority, in the attached form.

      • A draft Royal Decree has been prepared accordingly, its text is attached hereto.

    • Second: The National Cybersecurity Authority shall submit a report including the results of the application of the enablers referred to in paragraph (First) of this decision, its views thereon, and any proposals it deems appropriate, after a period of (four) years from the date of their implementation.

  • Prime Minister

  •  

  •  

  • Royal Decree No. (M/117) dated 21/06/1446 AH

  • By the grace of Allah Almighty

  • We, Salman bin Abdulaziz Al Saud

  • King of the Kingdom of Saudi Arabia

  • Based onArticle (Seventy) of the Basic Law of Governance, issued by Royal Order No. (A/90) dated 27/8/1412 AH.

  • And based onArticle (Twenty) of the Council of Ministers Law, issued by Royal Order No. (A/13) dated 3/3/1414 AH.

  • And based onArticle (Eighteen) of the Shura Council Law, issued by Royal Order No. (A/91) dated 27/8/1412 AH.

  • And after reviewing the Shura Council decision No. (16/3) dated 28/3/1446 AH.

  • And after reviewing the Council of Ministers decision No. (409) dated 16/6/1446 AH.

  • We decree the following:

    • First: Approval of the regulatory enablers of the National Cybersecurity Authority, in the attached form.

    • Second: It is upon His Highness the Prime Minister, the Ministers, and the heads of the concerned independent agencies—each within their jurisdiction—to implement this Royal Decree.

  •  

  • Salman bin Abdulaziz Al Saud

First:

The following acts shall be deemed violations: 1. Engaging in cybersecurity-related activities or operations that require licensing by the National Cybersecurity Authority without obtaining such license or in violation of the terms of the license.

2. Failing to comply with cybersecurity-related policies, governance mechanisms, frameworks, standards, controls, and guidelines set by the National Cybersecurity Authority.

3. Providing to the public or to public or private entities misleading information related to cybersecurity activities, operations, or services.

4. Failing to provide the National Cybersecurity Authority with the information, data, reports, or documents necessary for performing its functions and duties, or providing such materials in a misleading manner.

5. Possessing, selling, importing, exporting, leasing, providing access to, manufacturing, producing, circulating, or using–by any means–any device, equipment, tool, service, system, software, or similar items related to cybersecurity in a manner inconsistent with the standards and requirements set by the National Cybersecurity Authority, or without obtaining the necessary license or conducting the required screening.

6. Obstructing or preventing inspectors, in any manner, from carrying out their duties or refusing to cooperate with such inspectors or provide assistance thereto.

7. Committing any other act that violates regulations and decisions related to cybersecurity activities issued by the National Cybersecurity Authority pursuant to its Statute.

Second:

1. Inspectors, designated by a decision of the Governor of the National Cybersecurity Authority, shall individually or collectively detect, record, and investigate the violations provided for in Clause (First) herein. To this end, such inspectors shall have the power to monitor and inspect locations and activities related to cybersecurity, including networks, information technology systems, operational technology systems, and their components such as devices, hardware, and software, as well as the data and documents they contain, and to seize the same and obtain copies thereof; and the power to gather the necessary evidence and information.

2. Detected and recorded violations shall be referred to the committee provided for in Clause (Fourth) herein. The National Cybersecurity Authority shall be responsible for prosecuting violators before such committee.

3. If an inspector, while performing his duties, suspects a cybersecurity-related crime, he shall detect and record the same and refer the matter to the competent agencies.

4. The National Cybersecurity Authority shall have the right to summon any person it deems necessary for questioning or for hearing statements or testimonies regarding any of the violations provided for in Clause (First) herein, and shall document such procedures and take any necessary actions.

5. The National Cybersecurity Authority shall retain items seized in connection with the detected violation until a final decision is rendered thereon. If a final decision is issued establishing the violation, the Authority may, upon the approval of the committee provided for in Clause (Fourth) herein, destroy the seized items, without prejudice to the violator’s right to seek compensation for any damage.

6. The National Cybersecurity Authority may seek the assistance of any person it deems fit to carry out the tasks of monitoring, inspection, and violation detection and recording.

Third:

1. If a person commits any of the violations provided for in Clause (First) herein, the National Cybersecurity Authority shall, in exigent and necessary circumstances and for the purpose of safeguarding cybersecurity and pursuant to a decision by the Governor of the National Cybersecurity Authority or his designee, suspend or terminate any violating cybersecurity-related activity, network, information technology system, operational technology system, or any of their components, including devices, hardware, and software.

2. The decision issued shall become effective as of the date the violator is notified thereof. The National Cybersecurity Authority must refer the violation to the committee provided for in Clause (Fourth) herein within three working days from the decision's issuance date. Such committee shall render its decision within 10 working days from the referral date. If the committee fails to reach a decision within such period or the violator objects to its decision, the violator may file an appeal with the Administrative Court in accordance with applicable legal procedures.

Fourth:

1. The Board of Directors of the National Cybersecurity Authority shall issue a decision to form a committee, or more, comprising at least three members, one of whom shall be a legal specialist. Such committee shall review the violations provided for in Clause (First) and impose the penalties stipulated in Clause (Fifth) herein.

2. The Board of Directors of the National Cybersecurity Authority shall issue a decision specifying the committee's work rules and procedures, including the remuneration of its members.

Fifth:

Sixth:

The Board of Directors of the National Cybersecurity Authority shall issue the following:

1. Rules for reporting the violations provided for in Clause (First) herein, including determining the financial rewards for persons reporting such violations, the controls for granting and disbursing such rewards, and the measures for protecting such persons and ensuring the confidentiality of their identities.

2. Rules for regulating the detection, recording, and investigation of violations provided for in Clause (First) herein at security and military agencies.

Seventh:

These Powers shall enter into force from the date of their publication in the Official Gazette and shall repeal any provisions conflicting therewith.