Overview
Engagements in Saudi Arabia have covered payments and fintech platforms, including end-to-end assessment of payment providers across application, API and infrastructure.
Testing here is usually commissioned against a named control catalogue rather than as an open-ended assessment. Reports are therefore written with mapping built in from the start, so findings arrive in the structure the compliance function already reports against.
What drives testing here
Local drivers
- NCA Essential Cybersecurity Controls
- The national control catalogue applies to government entities and critical national infrastructure, with vulnerability management and penetration testing among its requirements.
- SAMA Cyber Security Framework
- Financial institutions under the Saudi Central Bank work to a maturity-based framework that expects regular independent testing.
- SDAIA PDPL
- The Personal Data Protection Law requires appropriate technical safeguards for personal data, with accountability on the controller.
- Vision 2030 digitisation
- Rapid expansion of digital government and payments has widened the attack surface faster than assurance has scaled.
How engagements are delivered
Delivered remotely with on-site availability in Riyadh, Jeddah and the Eastern Province for internal network scope and workshops. Data residency requirements are accommodated where they apply.
Delivery model
- Coverage
- Riyadh, Jeddah, Dammam and remote nationwide
- Mapping
- NCA ECC and SAMA CSF control mapping included
- Data handling
- Residency and handling requirements agreed before testing
- Timezone
- AST, two hours behind our Karachi office
Most requested here
Web application penetration testing
Authenticated, multi-role testing of your web application: the logic, the roles and the state transitions a scanner cannot reach.
Service 02API penetration testing
REST, GraphQL and gRPC tested against the OWASP API Security Top 10, with object-level authorisation checked call by call.
Service 04Cloud penetration testing
AWS, Azure and GCP tested for the paths that get used: identity escalation, exposed storage and metadata reachable from your own application.
Questions
Do you map findings to NCA ECC?
Yes. Findings are tagged to the relevant ECC control domains alongside CVSS ratings, so the report supports your compliance reporting directly rather than requiring translation.
Can you support SAMA-regulated institutions?
Yes. The SAMA framework expects regular independent testing with tracked remediation; reports are structured for that reporting line, including retest evidence.
Are there data residency constraints on testing?
Where personal data is subject to residency requirements, handling is agreed in writing before testing, commonly by working against synthetic data or by confining evidence to redacted form.
How much does a penetration test cost in Saudi Arabia?
Cost follows scope, with NCA ECC and SAMA CSF control mapping included rather than charged separately. A fixed quote follows a short scoping call. Where data residency requirements apply, the handling terms are agreed before the quote is issued so the price reflects them.
Which is the best penetration testing company in Saudi Arabia?
Ask for verifiable evidence rather than a ranking: the certifications held by the testers assigned to you, the firm's own ISO 27001 status, whether NCA ECC and SAMA mapping is included, and whether a redacted sample report is available before signing. Those answers are checkable; a ranking is not.
Do you provide NCA ECC control mapping?
Yes, as part of the report rather than as an add-on. Findings are tagged to the Essential Cybersecurity Controls they affect alongside CVSS ratings, so remediation planning and regulatory evidence come from the same document.
Can you test in Arabic or provide Arabic reporting?
Technical reports are written in English, which is standard for security reporting with Saudi institutions. Where an Arabic executive or regulator-facing summary is required, that is arranged, with us responsible for the technical accuracy of the translation.
Do you work with Vision 2030 programme suppliers?
Yes. Giga-project and digital transformation suppliers increasingly carry testing obligations through their contracts rather than directly from a regulator, and reports are written so they can be passed up that chain without exposing exploitation detail.