Blog · N.10 · Local Hub

VAPT services in Saudi Arabia: engagements, costs, timelines

In Saudi Arabia, VAPT is rarely optional — the NCA, SAMA and PDPL see to that. But a test that isn't mapped to the right Saudi control set is a report your assessor sends back. Here's what a KSA engagement actually involves, what drives the cost and timeline, and why regional fluency decides whether your report lands clean.

Saudi ArabiaVAPTNCA ECCSAMA CSFPDPL
KSA VAPT: Drivers = NCA ECC / CSCC · SAMA CSF · PDPL · OTCC · PCI DSS · Timeline = 1–3 Weeks Testing (4–6 Total) · Report Mapped to Your Regulator KSA VAPT: Drivers = NCA ECC / CSCC · SAMA CSF · PDPL · OTCC · PCI DSS · Timeline = 1–3 Weeks Testing (4–6 Total) · Report Mapped to Your Regulator
// TL;DR

VAPT (Vulnerability Assessment and Penetration Testing) is required across much of the Saudi economy by the NCA ECC (periodic testing; CSCC adds six-month intervals for critical systems), the SAMA CSF (pentest plus red teaming at higher maturity), the PDPL (personal-data systems), NCA OTCC (operational technology) and PCI DSS. A KSA engagement typically runs 1–3 weeks of active testing (about 4–6 weeks total including remediation and retest). Cost scales with scope. The decisive factor isn't just technical quality — it's a provider who maps the report to your exact Saudi control set, so your assessor accepts it first time. Map your obligations with the requirements finder.

// 01 What VAPT means, and who needs it in KSA

VAPT pairs a broad vulnerability assessment — wide coverage to catch known weaknesses — with a human-led penetration test that exploits the important ones to prove real impact. Breadth plus depth. In Saudi Arabia the term is ubiquitous because so many organisations are compelled to do it: government and regulated entities under the NCA, banks and financial firms under SAMA, any business processing personal data under the PDPL, critical-infrastructure and industrial operators under OTCC, and card handlers under PCI DSS. Add the enterprise customers who now require a recent test before signing, and most medium-to-large KSA organisations carry a VAPT obligation whether they went looking for one or not.

// 02 The Saudi regulatory drivers

DriverApplies toTesting expectation
NCA ECCGovernment & regulated entitiesPeriodic penetration testing (control 2-11)
NCA CSCCCritical systemsSix-month interval
SAMA CSFCentral-bank-regulated (banks, fintech, insurers)Pentest; red teaming at higher maturity
PDPLAnyone processing personal dataSecurity testing of personal-data systems
NCA OTCCOperational technology / ICSOT-aware security testing
PCI DSSCard handlersAnnual + on change; segmentation testing

Many Saudi organisations sit under several of these at once — a bank is SAMA, PCI and PDPL simultaneously. A well-scoped engagement can satisfy them together; see requirements by framework.

// 03 What a KSA engagement covers

Scope follows your assets and regulator, but a typical Saudi VAPT programme spans:

01

Web & API

Applications and APIs against OWASP Top 10 and API Top 10 — usually the core.

02

Network

External and internal network and Active Directory testing.

03

Cloud

AWS, Azure and GCP configuration and identity, increasingly common under Vision 2030 digitisation.

04

OT / ICS

Industrial and energy environments under OTCC, tested safety-first.

// 04 Timelines and cost drivers

A Saudi VAPT engagement typically involves one to three weeks of active testing, bracketed by scoping and reporting, for a total of roughly four to six weeks including remediation and a retest. Cost scales with the same drivers everywhere — the number and complexity of applications, network size, whether cloud and OT are included, and the depth required — which we break down in the cost guide. The Saudi-specific point is timing: book six to ten weeks ahead of any NCA or SAMA reporting deadline, because you need room to fix findings and retest before the report is due. Leaving it late means submitting with open critical findings. See the GCC compliance calendar for the cycles.

// 05 Why regional knowledge is the deciding factor

Here's the thing Saudi buyers learn the hard way: a technically brilliant test that isn't mapped to your control set is a report your assessor rejects. A provider fluent in the NCA ECC, CSCC, SAMA CSF, PDPL and OTCC scopes the right systems, uses the right methodology, and delivers findings mapped to the exact controls your assessor is checking — so it's accepted the first time. A distant provider with no Saudi context can hand you an excellent technical document that still fails the compliance conversation, and that failure tends to surface uncomfortably close to a deadline. This is why regional fluency, not just technical skill, is the quiet deciding factor for KSA engagements — and it's core to how we work. Map your exact obligations with the requirements finder.

// 06 Frequently asked questions

What is VAPT and who needs it in Saudi Arabia?

VAPT is Vulnerability Assessment and Penetration Testing — broad weakness discovery plus human-led exploitation to prove impact. In KSA it's needed by NCA ECC-regulated entities, SAMA-regulated financial firms, PDPL data processors, OTCC critical/OT operators, and PCI DSS card handlers. Most medium and large Saudi organisations have an obligation.

Which Saudi regulations require penetration testing?

NCA ECC (periodic; CSCC adds six-month intervals for critical systems), SAMA CSF (pentest plus red teaming at higher maturity), PDPL (personal-data systems), NCA OTCC (operational technology), and PCI DSS for card handlers.

How long does a KSA VAPT engagement take?

Typically 1–3 weeks of active testing plus scoping and reporting — about 4–6 weeks total including remediation and a retest. Small scopes are shorter; large estates or combined external/internal/cloud testing extend it. Book 6–10 weeks ahead of an NCA or SAMA deadline.

Why does regional knowledge matter?

A test not mapped to your regulator is half useful. A provider fluent in NCA ECC, CSCC, SAMA, PDPL and OTCC scopes faster, tests the right systems, and delivers a report mapped to the exact controls your assessor checks — accepted first time, rather than sent back near a deadline.

// 07 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Delivers VAPT across Saudi Arabia mapped to the NCA ECC, SAMA CSF, PDPL and OTCC — so clients' reports are accepted by their assessors the first time.

Need VAPT in Saudi Arabia?

We deliver VAPT across the Kingdom mapped to the NCA, SAMA, PDPL and OTCC — scoped to your obligations, timed to your reporting deadline, with a report your assessor accepts.

Scope your KSA engagement → Check requirements →