TL;DR
The NCA ECC has one rule that catches many teams off guard. Control 4-1-3-2 says any managed cybersecurity center that watches your systems through remote access must sit inside Saudi Arabia. If your SOC provider runs monitoring from Dubai, London, or Bangalore, your contract may put you out of compliance. This post breaks down what the control says, who it hits, and how to check your vendor agreements before an auditor does.
Introduction
Picture this. Your team signs a slick managed detection deal. The provider is well known. The price is right. Six months later, an NCA auditor asks one question: where is the operations center that monitors our network? The answer is Dubai. That single fact turns a working setup into an audit finding.
Cybersecurity managed service centers for monitoring and operations that use remote access must be fully located inside the Kingdom of Saudi Arabia.
- Where is the operations center that monitors our systems physically located?
- Do any remote monitoring consoles connect from outside Saudi Arabia?
- Does the contract name the country where monitoring is delivered?
- Are subcontractors or overflow teams based in other regions?
- Does the agreement bind the provider to apply our ECC controls?
Why Data Residency Is Suddenly Everyone’s Problem
Saudi Arabia treats cybersecurity as a national priority, not a checkbox. The National Cybersecurity Authority runs the Essential Cybersecurity Controls, and compliance is backed by Royal Decree for entities in scope. That means where your security data lives is now a legal question, not just a technical one.
What Control 4-1-3-2 Actually Says
Control 4-1-3-2 requires that cybersecurity managed service centers for monitoring and operations that use remote access be fully located within the Kingdom of Saudi Arabia. In plain terms, if a third party watches your systems from a remote console, that console and the team behind it must be inside the country. This sits under Domain 4, which covers third party and cloud cybersecurity.
Who This Rule Applies To
The ECC is mandatory for all Saudi government entities and their affiliates, and for any private company that owns, operates, or hosts Critical National Infrastructure in the Kingdom. Other private firms are strongly encouraged to follow it as a baseline. If you outsource monitoring and you fall in scope, this control is yours to prove.
The MSP Trap Hiding in Your Contract
Most managed security contracts were written for a global delivery model. That model runs monitoring from wherever talent is cheapest. Control 4-1-3-2 breaks that model for Saudi entities. Your provider’s follow the sun SOC, spread across time zones, becomes the exact thing the control forbids for remote monitoring.
Where the Cloud Piece Fits
Control 4-1 sits right above this and governs third party requirements more broadly. It says outside providers must apply your cybersecurity policies through contract. So the residency rule does not stand alone. It rides on top of a wider duty to bind vendors to ECC expectations in writing, before the work starts.
How to Check Your Contracts Before an Audit Does
You do not need a full audit to spot the gap. You need to ask a few pointed questions and read the fine print. Start with the location of the people and consoles doing the watching.
Ask these questions
Run each active managed security contract through this short list.
- Where is the operations center that monitors our systems physically located?
- Do any remote monitoring consoles connect from outside Saudi Arabia?
- Does the contract name the country where monitoring is delivered?
- Are subcontractors or overflow teams based in other regions?
- Does the agreement bind the provider to apply our ECC controls?
Fix the Gap Without Ripping Everything Out
A residency gap does not always mean a new vendor. Sometimes it means the provider stands up a local operations center, or moves your account to one they already run in the Kingdom. Put the residency requirement in the contract, name the country, and ask for proof. Get it in writing so your audit file has an answer ready.
How Secure.com Helps
Secure.com gives you a Compliance Teammate that maps your setup to the frameworks that apply, so residency gaps surface before an auditor finds them.
- Maps your organization to the regulations and controls that apply to your sector and region
- Flags gaps between your current controls and framework requirements, then tracks them to close
- Links each compliance gap to your risk register so the highest risk items get fixed first
- Builds an audit ready trail of evidence for review
- Watches for recurring gaps across audits so the same finding does not come back