Statute of the National Cybersecurity Authority

Article 1

  • In this Statute, the following words and phrases shall have the meanings assigned thereto, unless the context otherwise requires:

    • NCA: The National Cybersecurity Authority.

    • Statute: Statute of the National Cybersecurity Authority.

    • Cybersecurity: The protection of networks, information technology systems, and operational technology systems, including hardware and software, services provided thereby, and data included therein, against hacking, disruption, modification, unauthorized access, and unlawful exploitation or use. Cybersecurity includes information security, electronic security, digital security, and the like.

    • Board: NCA’s board of directors.

    • Centers: Centers referred to in Article 5(1) of this Statute. 

Article 2

  • 1. The NCA shall have a public legal personality and financial and administrative independence, and shall report to the King.

  • 2. The NCA shall be headquartered in the city of Riyadh and it may, pursuant to a Board decision, establish branches and offices within the Kingdom and abroad.

Article 3

  • The NCA shall be the national authority in charge of cybersecurity in the Kingdom. It aims at strengthening cybersecurity to safeguard the State’s vital interests, national security, critical infrastructures, priority sectors, and government services and activities. However, without prejudice to the NCA’s powers and duties provided for in this Statute, public and private entities and any other entity shall not be relieved from their responsibility towards their own cybersecurity.

Article 4

  • The NCA’s powers and duties shall include the following:

  • 1. Drafting the national strategy for cybersecurity, supervising its implementation, and proposing updates thereto.

  • 2. Setting cybersecurity policies, governance rules, frameworks, rules, standards, and directives; communicating the same to relevant agencies; monitoring compliance therewith; and updating them.

  • 3. Identifying and classifying critical infrastructures as well as the agencies related thereto, and identifying priority sectors.

  • 4. Setting and updating framework for cybersecurity risk management and monitoring compliance therewith.

  • 5. Notifying relevant agencies of cybersecurity risks and threats.

  • 6. Setting and updating frameworks for responding to cybersecurity incidents and monitoring compliance therewith.

  • 7. Establishing, supervising, and operating national cybersecurity operation centers, and the like, including centers for control, surveillance, monitoring, exchange, and information analysis; sectoral cybersecurity operation centers, as necessary; and relevant platforms.

  • 8. Conducting, on its own or through others, cybersecurity activities and operations.

  • 9. Regulating and supervising the sharing of cybersecurity-related information and data between various agencies and sectors in the Kingdom.

  • 10. Providing support to relevant agencies, upon request and in accordance with the NCA’s available resources, during the investigation of cybersecurity crimes.

  • 11. Setting and updating national encryption policies and standards and monitoring compliance therewith.

  • 12. Setting and updating standards for licensing the import, export, and use of highly sensitive cybersecurity hardware and software specified by the NCA and monitoring compliance therewith, without prejudice to the standards or requirements of other relevant agencies.

  • 13. Building national capacities in cybersecurity, participating in the preparation of educational and training programs, setting professional standards and frameworks, and developing and implementing relevant professional standardized tests and measurements.

  • 14. Licensing individuals and non-government agencies to engage in cybersecurity activities and operations specified by the NCA.

  • 15. Establishing ties with counterpart agencies abroad and private entities to exchange expertise and establish frameworks for cooperation and partnership, in accordance with applicable procedures.

  • 16. Exchanging technological and informational production as well as data and information with counterpart agencies aboard.

  • 17. Representing the Kingdom in relevant regional and international organizations, agencies, and bilateral committees and groups as well as monitoring the Kingdom’s compliance with its international cybersecurity obligations.

  • 18. Raising awareness on cybersecurity.

  • 19. Stimulating the growth of the cybersecurity sector in the Kingdom and encouraging innovation and investment therein.

  • 20. Conducting research and development studies, carrying out manufacturing processes, and transferring and developing technology in cybersecurity and related fields.

  • 21. Proposing mechanisms to optimize spending pertaining to cybersecurity.

  • 22. Developing key performance indicators relating to cybersecurity and preparing periodic reports on the state of cybersecurity in the Kingdom at the national and sectoral levels.

  • 23. Proposing cybersecurity laws, regulations, and decisions as well as amendments thereto.

Article 5

  • The NCA may employ all the means necessary to achieve its objectives, including the following:

  • 1. Establishing Centers to carry out some of its powers and duties and determining the necessary means and procedures; specifying their affiliation with the NCA; and determining their financial and administrative affairs, including granting all, or some, of such Centers administrative and financial independence.

  • 2. Seeking the assistance of others to carry out all or part of the cybersecurity activities entrusted thereto.

  • 3. Seeking the assistance of employees of public agencies or private entities and determining their remuneration, as well as seeking the assistance of consulting firms within the Kingdom and abroad.

  • 4. Forming teams from public agencies and private entities to carry out tasks related to the NCA’s activities.

  • 5. Providing consultations and services related to cybersecurity.

  • 6. Organizing workshops, symposia, conferences, and exhibitions within the Kingdom and abroad, in accordance with applicable procedures.

  • 7. Organizing and offering training programs and courses related to the NCA’s activities.

  • 8. Organizing campaigns, awareness programs, and competitions and issuing magazines, periodicals, books, booklets, manuals, and pamphlets related to the NCA’s activities.

  • 9. Investing the NCA’s assets and funds.

  • 10. Establishing companies or participating in the establishment thereof, or joining companies as a partner or shareholder, within the Kingdom and abroad, in accordance with applicable statutory procedures.

Article 6

  • The NCA’s board shall be formed of a chairman, appointed pursuant to a royal order, and the membership of the Head of the Presidency of State Security, Head of the General Intelligence Presidency, Vice-Minister of Interior, Assistant Minister of Defense, and the NCA’s Governor.

Article 7

  • The Board shall be the supreme authority of the NCA and the Centers. It shall be in charge of their management and the conduct of their affairs, and shall oversee their activities, the exercise of their powers, and the implementation of their duties as stipulated in this Statute. For these purposes, it shall take the decisions and measures necessary to achieve their objectives, particularly the following:

  • 1. Approving the National Strategy for Cybersecurity, and any amendments thereto, prior to submission thereof.

  • 2. Adopting the NCA’s policies, procedures, frameworks, standards, rules, guidelines, and key performance indicators.

  • 3. Approving the classification of critical infrastructures as well as agencies related thereto, and identifying priority sectors.

  • 4. Approving the establishment of the Centers referred to in Article 5(1) of this Statute, their organizational affiliation with the NCA, their financial and administrative arrangements, and the means to carry out their powers and duties.

  • 5. Approving the establishment of national cybersecurity operation centers, and similar centers, as well as the establishment of sectoral cybersecurity operation centers and relevant platforms.

  • 6. Approving periodic reports on the state of cybersecurity in the Kingdom at the national and sectoral levels, and taking necessary action thereon.

  • 7. Approving the NCA’s formation of teams which comprise members from public agencies and private entities, specifying their tasks, determining the remuneration of their members, and overseeing the performance of their activities.

  • 8. Approving policies and rules for investing the NCA’s assets and funds.

  • 9. Approving the organizational structures of the NCA and the Centers as well as related guides.

  • 10. Issuing the internal regulations of the NCA and the Centers, including employment, administrative, and financial regulations.

  • 11. Approving salary scales of employees of the NCA and the Centers and the salary scales of experts and specialists, as well as the remunerations of persons providing assistance thereto.

  • 12. Determining fees for services and consultations rendered by the NCA and the Centers.

  • 13. Appointing an external auditor for the NCA and the Centers from among accredited auditors in the Kingdom and determining his fees.

  • 14. Appointing a comptroller for the NCA and the Centers.

  • 15. Approving the NCA’s annual budget, final accounts, and annual report, as well as auditor's report, prior to submission to the King.

  • 16. Approving the budget, final accounts, and auditors’ report of Centers with separate budgets, as well as reviewing their annual reports, and taking necessary action thereon.

  • 17. Reviewing the periodic reports on the work progress and financial status of the NCA and the Centers.

  • 18. Accepting grants, gifts, aids, donations, bequests, and endowments presented to the NCA and the Centers, in accordance with applicable provisions.

  • 19. Forming standing or ad hoc committees at the NCA or the Centers from among Board members or others to carry out certain tasks. The formation decision of each committee shall designate its chairman and members and determine its powers. A committee may seek the assistance of nonmembers in carrying out the tasks entrusted thereto, unless the Board decides otherwise.

  • The Board may, pursuant to a decision issued thereby, delegate some of its powers to its Chairman or any of its members, or to any employee of the NCA or the Centers. It may also delegate the powers relating to the Centers to their boards of directors, formed pursuant to a decision issued by the Board, or delegate some of such powers to the chairmen of the boards of directors, if any, or to any of their employees.

Article 8

  • 1. The Board shall, in each fiscal year, convene at least twice upon a call by the Chairman.

  • 2. Board meetings shall be valid only if attended by the majority of its members, including the Chairman or his designee. Board decisions shall be passed by the majority vote of attending members. In case of a tie, the meeting chairman shall have the casting vote.

  • 3. The Board may invite non-members to attend its meetings in a non-voting capacity.

  • 4. Board deliberations and decisions shall be entered into the meeting minutes.

  • 5. The Board shall have a secretary named by the Chairman. The Chairman shall determine his tasks and remuneration.

Article 9

Previous Amendments
  • 1- The Authority shall have a Governor appointed by a royal decree at the rank of Minister based on a proposal from the Chairman of the Council, and the Council shall define his competencies and powers.

  • 2- Each center shall have an Executive Director appointed and dismissed by a decision of the Council, and the Council shall define the powers of the Executive Directors of the centers, their salaries, and other financial and job benefits.

Article 10

  • The relevant agencies shall:

  • 1. facilitate the NCA’s performance of its duties;

  • 2. promptly notify the NCA of any actual or potential breach, risk, or threat to their cybersecurity;

  • 3. comply with the NCA’s policies, governance rules, frameworks, and standards;

  • 4. fully cooperate in any cybersecurity investigation or assessment carried out by the NCA; and

  • 5. provide the NCA with documents, information, data, and reports necessary for carrying out its duties, and facilitate the inspection of their devices, networks, systems, and software.

Related files
Hide
Related file link

Next section title

Next section content