Penetration Testing in Saudi Arabia: Mapped to NCA ECC

Annual penetration testing for Saudi organisations, mapped control-by-control to the National Cybersecurity Authority's Essential Cybersecurity Controls, with an audit-ready bilingual report

Organisations operating in Saudi Arabia, government and semi-government entities, and the financial, healthcare, and retail sectors, are required to implement the Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Authority (NCA), which include explicit controls for vulnerability management, penetration testing, and web application security. We run the testing and deliver a report that is mapped control by control, in Arabic and English, so your compliance team can hand it directly to an internal auditor or regulator as evidence.

Mapped to ECC controls

Every finding is tied to the relevant Essential Cybersecurity Control, not a generic vulnerability list.

Bilingual reporting

Executive summary and full technical report in Arabic and English, ready for management and auditors.

Internationally recognised methodology

OWASP Testing Guide, PTES, and NIST SP 800-115, with every finding scored using CVSS v3.1.

Free retest

After remediation we retest the affected scope and issue a final validation report proving closure.

Which ECC controls does penetration testing serve?

The Essential Cybersecurity Controls are organised into main domains, Cybersecurity Governance, Cybersecurity Defence, Cybersecurity Resilience, and Third-Party and Cloud Computing Cybersecurity. Penetration testing directly supports the following subdomains:

SubdomainTopicHow penetration testing serves it
2-10Vulnerability ManagementDiscovering and prioritising vulnerabilities, and proving remediation through a documented retest.
2-11Penetration TestingThe core control: periodic, documented penetration testing of in-scope technology assets.
2-15Web Application SecurityTesting public web applications against the OWASP Top 10 and proving applied controls actually work.
2-5Network Security ManagementPractical verification of network segregation, firewall rules, and exposed-port restrictions.
2-2Identity and Access ManagementTesting authentication mechanisms, privilege escalation paths, and unauthorised access.
4-1 / 4-2Third-Party and Cloud ComputingAssessing cloud-hosted assets and service-provider integration points within the agreed scope.

Note: the control numbers above are indicative. The final report is mapped against the control version in force at your organisation at the time of testing. Entities subject to additional frameworks, such as the Critical Systems Cybersecurity Controls (CSCC), the Cloud Cybersecurity Controls (CCC), or the Saudi Central Bank framework (SAMA CSF), get an extended mapping matrix covering those frameworks as well.

What we test

External testing

Simulating an outside attacker against your internet-facing websites, portals, and services.

Internal network testing

Assessment from inside the network: lateral movement, privilege escalation, and access to sensitive systems.

Web applications and APIs

Deep testing of platforms, e-service portals, and integration interfaces following OWASP guidance.

Mobile applications

iOS and Android testing against OWASP MASVS, covering local storage and server communication.

What you receive

  1. Executive summary: written for senior management and the CISO, not only for engineers.
  2. Control mapping matrix: a table linking each finding to the relevant ECC control, what auditors actually ask for.
  3. Findings scored with CVSS v3.1: Critical / High / Medium / Low / Info, ordered by priority.
  4. Proof of Concept evidence: exploitation steps and screenshots for every critical finding.
  5. Remediation plan with a timeline: clear, actionable guidance for your technical team ordered by impact and effort.
  6. Free retest and final validation report: documented proof of closure to attach to your compliance file.

How we work with you

  1. Free scoping session: we define the in-scope assets and the regulatory frameworks that apply to you.
  2. NDA and signed scope of work: an agreed testing window that does not disrupt service continuity.
  3. Testing execution: external, internal, and application testing, with immediate escalation of any critical finding.
  4. Report delivery: executive summary, full technical report, and the control mapping matrix.
  5. Findings walkthrough: we present results to your team and answer auditor questions.
  6. Retest and final validation report: to close the file before your review date.

Frequently asked questions

Do you work with organisations inside Saudi Arabia?

Yes. We serve clients in Riyadh, Jeddah, Dammam, and across the Kingdom, and run most testing phases remotely under controlled, time-limited access. Internal network testing can be delivered remotely through a controlled access channel, or on-site when the organisation prefers.

Will the report be accepted as NCA compliance evidence?

Our reports are built to serve as direct technical evidence: every finding is mapped to the relevant control, with proof of concept, execution dates, and a retest report. Acceptance of that evidence is a decision for your compliance team or auditor, so we format the report the way auditors typically request it and adjust it when your entity has specific wording requirements.

Are you licensed by the National Cybersecurity Authority?

We are a specialist penetration testing provider, not a regulator and not a certification body. If your engagement requires contracting a locally licensed provider for this type of work, we flag that in the first scoping session, and we can either partner with a local entity or deliver the technical portion under a contracting arrangement that suits your requirements.

How often should penetration testing be performed?

The established practice across cybersecurity frameworks, including the NCA controls, is periodic testing at least once per year, repeated after any material change: launching a new platform, migrating to the cloud, changing network architecture, or integrating a third-party system.

Will testing affect system availability?

No. We agree a testing window and a clear scope in advance, and exclude destructive tests such as denial-of-service attacks unless explicitly requested in a separate test environment. A direct communication line stays open throughout so any activity can be stopped immediately if needed.

How do you handle data confidentiality?

We sign a non-disclosure agreement before any work begins and treat all outputs as confidential: encrypted delivery channels, access limited to the delivery team, and deletion of test data after the agreed retention period.

How long does it take and what does it cost?

It depends on the number of assets and the type of testing required. A mid-sized scope typically takes 1–3 weeks of testing plus a few days for reporting. We provide an accurate quote after the free scoping session.

Ready for your next cybersecurity review?

Free scoping session, accurate quote within 24 hours

+20 102 777 0444

Guides to help you decide

Get a FREE 30-Minute Consultation

With one of our expert specialists!

We discuss your needs and provide the best solutions for your project.

Consulting illustration