Security & compliance · Saudi Arabia

Edrak and the National Cybersecurity Authority

The NCA sets the Kingdom's cybersecurity requirements. Running AI across your systems should not loosen any control you already have, so Edrak works inside your permissions, keeps data where you put it, and records everything it does.

NCA
National authority. Sets the Kingdom's cybersecurity requirements.
Applies to
Government entities, critical national infrastructure, and the organisations that supply them.
Where Edrak stands
Edrak maps its controls to the NCA frameworks and shares that mapping with your team. The NCA does not certify vendors.

The NCA frameworks

Four control sets matter for most organisations. Which apply to you depends on your sector and the systems involved; your compliance team will know.

  • ECC

    Essential Cybersecurity Controls

    The baseline for national organisations: governance, defence, resilience and third-party controls.

  • CCC

    Cloud Cybersecurity Controls

    Requirements for cloud providers and for the organisations that use them.

  • DCC

    Data Cybersecurity Controls

    Protection of data through its lifecycle, by classification level.

  • CSCC

    Critical Systems Cybersecurity Controls

    Additional controls for systems whose disruption would have national impact.

How Edrak supports your NCA obligations

The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.

  • Identity and access

    Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.

    You: Identities, roles, and joiner, mover and leaver processes.

  • Data location

    Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.

    You: Classifying data and choosing the deployment that fits each class.

  • Records

    Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.

    You: Retention periods and forwarding to your monitoring tools.

  • Models and third parties

    Edrak: Routing rules keep restricted data on open-weight models inside your boundary; hosted frontier models handle the rest.

    You: Approving which models may handle which classes of data.

  • Human oversight

    Edrak: Approval steps sit where you set them. Nothing completes without the sign-off you require.

    You: Defining the approval points and who holds them.

  • Incidents

    Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.

    You: The incident process and any regulatory notifications.

For your security and compliance teams

We share a requirement-by-requirement mapping to the NCA frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.

Talk to our team

The NCA issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Confirm applicability with your compliance team.