شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Insights

How to choose a licensed managed SOC provider

What the NCA licence means for managed SOC providers, how to verify it, and the questions to ask before you sign.

DataSec teamPublished 28 September 20266 min read

What the licence actually means

Since 2022 the National Cybersecurity Authority (NCA) has required every cybersecurity service provider in the Kingdom to register with it. Managed Security Operations Centre (MSOC) services carry a higher requirement: an explicit licence under the Regulatory Framework for Managed Security Operations Centre Services. Registration means the Authority knows the provider exists. A licence means the Authority has examined the provider's ability to run a SOC to its requirements. It is issued for five years and is subject to renewal.

The framework defines the services a licence covers: threat monitoring and detection; threat analysis and investigation, including threat hunting; and containment recommendations. It also places obligations on the licensee that work directly in your favour, among them: operating the service around the clock throughout the year, keeping facilities and data inside the Kingdom, connecting to the Authority's national SOC, applying the Authority's alerts, detection rules and indicators of compromise, retaining security-event records for a defined period, giving long advance notice before withdrawing a service, and staffing the service with analysts who hold NCA qualification certificates, with defined Saudisation requirements. Refer to the current version of the framework for the detail and the periods of each obligation.

Why the tier matters

There are two tiers. Tier 1 authorises the service for all organisations, including government entities and organisations that own, operate or host critical national infrastructure. Tier 2 authorises the provision of managed SOC services to any organisation other than government entities and organisations that own, operate or host critical national infrastructure. In other words: if you are a government entity or operate critical national infrastructure, your provider must hold a Tier 1 licence. If you are a private-sector company outside that scope, either tier can serve you, and the decision then rests on the quality of the service and its fit with your environment.

DataSec holds the Managed Security Operations Center (MSOC) Services Licence — Tier 2, number 010220341, valid from 14 July 2026 to 14 July 2031. We therefore provide SOC services to eligible private-sector organisations only, and not to government entities or organisations that own, operate or host critical national infrastructure.

How to verify a licence

  • Ask for a copy of the licence certificate: licensee name, licence number, tier, effective and expiry dates.
  • Open the registration and licensing page on the NCA website and look for the provider's name in the MSOC provider list for the relevant tier. The site offers no search by licence number, so match the legal name exactly as it appears on the certificate.
  • Confirm that the legal name on the certificate is the same party you will sign the contract with, not a sister company or a partner.
  • Be wary of the words "certification" or "accredited"; the correct document is a licence.

Questions that separate providers

  • Integration: how does the provider connect to your existing SIEM and EDR? Does it work on your tools or impose its own, and who owns the configuration and the data in each case?
  • Detection use-case development: how are detection rules built for your environment? How many use cases are added each month, and who reviews false positives?
  • Limits of authority: what does the provider do on its own when it detects a threat, and what does it only recommend? The framework speaks of containment recommendations, so agree in writing what runs automatically and what needs your approval.
  • Reporting cadence: what do you receive daily, weekly and monthly, in what format, and does it serve as evidence for an Essential Cybersecurity Controls (ECC) audit?
  • Data location: where are the logs stored, where do the analysts sit, and does anyone outside the Kingdom reach your data?
  • Analysts: how many Saudi analysts hold NCA certificates, and how are shifts covered?
  • Exit terms: what is the notice period, and how do you get your logs and detection rules back, in what format?

Red flags

  • A provider that does not state its licence number or avoids producing the certificate.
  • Promises of guaranteed outcomes or absolute detection rates.
  • Client names or real operational data in marketing material; the framework prohibits publishing beneficiary data without the Authority's approval, and a provider that breaks that rule with others will break it with you.
  • Analysts or data outside the Kingdom without explanation.
  • A contract with no exit terms, or nothing on what happens if the licence lapses.

How to run a short pilot

Before a long contract, ask for a limited-scope pilot. An illustrative six-week pilot:

  • Week one: connect a defined set of log sources: the firewall, identity systems, and EDR on a group of endpoints.
  • Weeks two and three: agree a small number of detection use cases that matter most to you and watch alert quality and the false-positive rate.
  • Week four: run an agreed test scenario, such as a phishing simulation or lateral movement, and measure detection, communication and recommendations.
  • Weeks five and six: review the reports with your team and assess clarity and fit with your compliance needs.

What you are looking for in a pilot is not an impressive number. It is three things: did the provider understand your environment, were the alerts actionable, and was communication clear under pressure. A provider that passes all three has earned the next conversation.

This article is general awareness content, not legal advice. Refer to the current version of the regulations and frameworks mentioned.

All articles

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.