Security & compliance · Saudi Arabia
Edrak and the National Cybersecurity Authority
The NCA sets the Kingdom's cybersecurity requirements. Running AI across your systems should not loosen any control you already have, so Edrak works inside your permissions, keeps data where you put it, and records everything it does.
- NCA
- National authority. Sets the Kingdom's cybersecurity requirements.
- Applies to
- Government entities, critical national infrastructure, and the organisations that supply them.
- Where Edrak stands
- Edrak maps its controls to the NCA frameworks and shares that mapping with your team. The NCA does not certify vendors.
The NCA frameworks
Four control sets matter for most organisations. Which apply to you depends on your sector and the systems involved; your compliance team will know.
ECC
Essential Cybersecurity Controls
The baseline for national organisations: governance, defence, resilience and third-party controls.
CCC
Cloud Cybersecurity Controls
Requirements for cloud providers and for the organisations that use them.
DCC
Data Cybersecurity Controls
Protection of data through its lifecycle, by classification level.
CSCC
Critical Systems Cybersecurity Controls
Additional controls for systems whose disruption would have national impact.
How Edrak supports your NCA obligations
The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.
Identity and access
Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.
You: Identities, roles, and joiner, mover and leaver processes.
Data location
Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.
You: Classifying data and choosing the deployment that fits each class.
Records
Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.
You: Retention periods and forwarding to your monitoring tools.
Models and third parties
Edrak: Routing rules keep restricted data on open-weight models inside your boundary; hosted frontier models handle the rest.
You: Approving which models may handle which classes of data.
Human oversight
Edrak: Approval steps sit where you set them. Nothing completes without the sign-off you require.
You: Defining the approval points and who holds them.
Incidents
Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.
You: The incident process and any regulatory notifications.
For your security and compliance teams
We share a requirement-by-requirement mapping to the NCA frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.
Talk to our teamThe NCA issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Confirm applicability with your compliance team.

