Country guide

Rail cyber security regulations in Saudi Arabia

For rail projects in Saudi Arabia, the National Cybersecurity Authority's controls are a central reference. The applicable requirements depend on the organisation and the systems in scope, including whether it operates critical national infrastructure or relevant operational technology. These are national cybersecurity controls, rather than a single law applying identically to every rail product.

Official sources checked

Who needs to consider these requirements?

A new metro or mainline programme should establish the operator's NCA obligations early enough to shape procurement. Separate the corporate technology environment from the operational systems that control or support railway services. Suppliers need clear requirements for the equipment, remote connections and support services they deliver into those environments.

Key regulations and frameworks

Essential Cybersecurity Controls — ECC 2:2024

Mandatory controls for organisations within scope

NCA's ECC 2:2024 establishes national baseline controls. Its scope includes government organisations and private-sector entities that own, operate or host critical national infrastructure. The organisation should determine its scope and applicable controls, maintain implementation evidence and consider the relevant complementary NCA frameworks. Do not assume an equipment supplier and its regulated customer have the same direct obligations.

Official source: Essential Cybersecurity Controls — ECC 2:2024

Operational Technology Cybersecurity Controls — OTCC 1:2022

OT controls — assess facility and system scope

NCA publishes additional controls for operational technology in critical industrial facilities. For rail, determine with the operator which operational environments and facility categories are covered. Apply the OT-specific requirements alongside the relevant baseline, rather than treating enterprise IT controls as a complete answer for signalling, control and other operational systems.

Official source: Operational Technology Cybersecurity Controls — OTCC 1:2022

Practical steps for rail teams

Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.

  1. Request the operator's applicable NCA control set and system boundaries before tender acceptance. Allocate an evidence owner for each requirement passed to the supplier.
  2. Document all operational support connections, including vendor maintenance paths. Agree how access is authorised, limited, monitored and revoked when a support engagement ends.
  3. Plan acceptance tests and operational handover together. Record configuration baselines, backup responsibilities and how security changes will be assessed against service and safety constraints.

Using this guide

This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.