Dunicot A cybersecurity consultancy and advisory firm.

Market · Saudi Arabia

Penetration testing in Saudi Arabia

Saudi Arabia has the most prescriptive control catalogue in the region. The NCA’s Essential Cybersecurity Controls and SAMA’s framework both state what must be in place, which makes the useful question not whether controls exist but whether they hold.

Overview

Engagements in Saudi Arabia have covered payments and fintech platforms, including end-to-end assessment of payment providers across application, API and infrastructure.

Testing here is usually commissioned against a named control catalogue rather than as an open-ended assessment. Reports are therefore written with mapping built in from the start, so findings arrive in the structure the compliance function already reports against.

What drives testing here

Local drivers

NCA Essential Cybersecurity Controls
The national control catalogue applies to government entities and critical national infrastructure, with vulnerability management and penetration testing among its requirements.
SAMA Cyber Security Framework
Financial institutions under the Saudi Central Bank work to a maturity-based framework that expects regular independent testing.
SDAIA PDPL
The Personal Data Protection Law requires appropriate technical safeguards for personal data, with accountability on the controller.
Vision 2030 digitisation
Rapid expansion of digital government and payments has widened the attack surface faster than assurance has scaled.

How engagements are delivered

Delivered remotely with on-site availability in Riyadh, Jeddah and the Eastern Province for internal network scope and workshops. Data residency requirements are accommodated where they apply.

Delivery model

Coverage
Riyadh, Jeddah, Dammam and remote nationwide
Mapping
NCA ECC and SAMA CSF control mapping included
Data handling
Residency and handling requirements agreed before testing
Timezone
AST, two hours behind our Karachi office

Most requested here

Questions

Do you map findings to NCA ECC?

Yes. Findings are tagged to the relevant ECC control domains alongside CVSS ratings, so the report supports your compliance reporting directly rather than requiring translation.

Can you support SAMA-regulated institutions?

Yes. The SAMA framework expects regular independent testing with tracked remediation; reports are structured for that reporting line, including retest evidence.

Are there data residency constraints on testing?

Where personal data is subject to residency requirements, handling is agreed in writing before testing, commonly by working against synthetic data or by confining evidence to redacted form.

How much does a penetration test cost in Saudi Arabia?

Cost follows scope, with NCA ECC and SAMA CSF control mapping included rather than charged separately. A fixed quote follows a short scoping call. Where data residency requirements apply, the handling terms are agreed before the quote is issued so the price reflects them.

Which is the best penetration testing company in Saudi Arabia?

Ask for verifiable evidence rather than a ranking: the certifications held by the testers assigned to you, the firm's own ISO 27001 status, whether NCA ECC and SAMA mapping is included, and whether a redacted sample report is available before signing. Those answers are checkable; a ranking is not.

Do you provide NCA ECC control mapping?

Yes, as part of the report rather than as an add-on. Findings are tagged to the Essential Cybersecurity Controls they affect alongside CVSS ratings, so remediation planning and regulatory evidence come from the same document.

Can you test in Arabic or provide Arabic reporting?

Technical reports are written in English, which is standard for security reporting with Saudi institutions. Where an Arabic executive or regulator-facing summary is required, that is arranged, with us responsible for the technical accuracy of the translation.

Do you work with Vision 2030 programme suppliers?

Yes. Giga-project and digital transformation suppliers increasingly carry testing obligations through their contracts rather than directly from a regulator, and reports are written so they can be passed up that chain without exposing exploitation detail.

Penetration testing in Saudi Arabia

Describe the scope and the deadline. Delivery in your working hours, with a fixed quote after scoping.