NCA Tier 1 Licensed Providers in Saudi Arabia — TheAudit.org

NCA Tier 1 Licensed Providers in Saudi Arabia

NCA Tier 1 refers to the highest category of licence issued by Saudi Arabia’s National Cybersecurity Authority under its Managed Security Operations Centre (MSOC) licensing framework. A Tier 1 licence authorises a provider to deliver managed security operations to government entities and to organisations operating Critical National Infrastructure (CNI) in the Kingdom.

If you are procuring managed security services in Saudi Arabia, the licence tier of your provider is not a marketing badge — for CNI and government workloads it determines whether the provider is permitted to serve you at all.

Licensing status changes as new applications are approved. The position below reflects our latest review; verify current licence status directly with the NCA through the National Cybersecurity Services Portal (Haseen) before relying on it in a procurement decision. Last reviewed: July 2026.

Which companies hold NCA Tier 1 licences?

Six companies were granted Tier 1 MSOC licences in the first licensing round:

  • SITE (Saudi Information Technology Company)
  • Sirar by STC
  • Haboob
  • Cyberani by Aramco Digital
  • TCC
  • SAMI-AEC

These providers are authorised to deliver comprehensive MSOC services to critical infrastructure operators and government entities, covering 24/7 monitoring and threat detection, incident response and remediation, compliance reporting, and threat intelligence.

The NCA MSOC licensing framework

In March 2024 the NCA issued the National Policy for Managed Security Operations Centres together with the Regulatory Framework for Licensing MSOC Services. The framework sets the requirements a provider must meet before delivering security services to government organisations and CNI operators.

This sits on top of a broader obligation: since August 2022, every entity providing cybersecurity services in Saudi Arabia must register with the NCA through its digital platform. Registration and licensing are different things — registration is the baseline to operate; a Tier 1 or Tier 2 licence is what authorises MSOC delivery.

Licensing timeline

  • March 2024 — NCA issues the National Policy for MSOC and the licensing regulatory framework
  • August 2024 — Tier 1 licence applications open for a 60-day window
  • October 2024 — Tier 1 application period closes
  • March 2025 — six companies granted Tier 1 licences
  • Ongoing — Tier 2 applications continue to be accepted through the Haseen portal

Tier 1 versus Tier 2

  • Tier 1 — mandatory for government entities and CNI operators. Full-scope MSOC delivery, closed licensing round, six licensees.
  • Tier 2 — an expanding pool of authorised providers serving broader organisational needs: specialised security services, sector-specific compliance support, scalable monitoring, and integration with existing security infrastructure. Applications remain open through Haseen.

The practical read: if you are a government entity or you operate critical national infrastructure, your MSOC provider must hold a Tier 1 licence. If you are neither, a Tier 2 provider may be entirely appropriate — and the wider pool usually means better commercial terms and more sector-specific capability.

What this means when you procure

  • Confirm your own classification first. Whether you are treated as CNI drives which tier you must buy from. Classification is an audit-relevant control in its own right — see NCA critical system compliance.
  • Verify the licence, do not take it on trust. Ask for the licence and check current status through Haseen. Licence scope and validity change.
  • Licensing is not the same as suitability. A Tier 1 licence proves regulatory authorisation, not that the provider is good at your sector, your technology stack, or your incident response expectations.
  • The obligation does not transfer. Outsourcing the SOC does not outsource accountability. Your third-party governance controls are still tested against you, not the provider.

Frequently asked questions

What is an NCA Tier 1 licence?

Authorisation from Saudi Arabia’s National Cybersecurity Authority to deliver managed security operations centre services to government entities and Critical National Infrastructure operators, issued under the MSOC licensing framework introduced in March 2024.

How many companies hold NCA Tier 1 licences?

Six were granted in the first round: SITE, Sirar by STC, Haboob, Cyberani by Aramco Digital, TCC and SAMI-AEC. Verify current status through the Haseen portal, as licensing continues to evolve.

Do I need a Tier 1 provider?

If you are a government entity or operate critical national infrastructure, yes. Other organisations can use Tier 2 licensed providers, which is a larger and still-growing pool.

Where do I check a provider’s licence?

Through the NCA’s National Cybersecurity Services Portal (Haseen), which is also where Tier 2 applications are submitted.

Related reading

Leave a Reply

Your email address will not be published. Required fields are marked *