forumNew topic

What is the cybersecurity compliance required in Saudi tenders, and how much does it cost?

VVeliNew member
Job title
Pesticide dealer
Organization type
8-person team
Joined
Aug 2024
Message
38
#1

We are a logistics and fleet software company in Riyadh with 14 employees. Last week, we bid on a vendor tender for a semi-public energy distribution firm. The technical specifications asked for compliance certification or a formal commitment to the local cybersecurity authority's essential controls and vendor security requirements.

We've taken on smaller projects in Turkey and the Gulf before, but this is our first time running into such a strict, formal cybersecurity compliance clause. We don't have a full-time cybersecurity specialist; we handle IT with an external freelance engineer. Our annual budget is tight, and this contract is worth around 350,000 SAR.

Does the tender expect a full third-party audit report or just a self-assessment declaration? How much does it cost a small business to implement these controls from scratch, and what is the smartest way to navigate this without losing the bid?

ZZafer B***Member
Job title
Customer service representative
Sector
Insurance
Organization type
chain store
Joined
Nov 2023
Message
34
Most Helpful#2

Short answer: The compliance requested refers to the Saudi National Cybersecurity Authority's essential controls and its cybersecurity framework for vendors. In government and critical sector tenders, they generally ask for a stamped self-assessment declaration and an action plan initially, followed by audit evidence before contract signing.

To manage this properly as a small software company, follow these steps: 1) Review the RFP to confirm whether they require the general baseline controls or specifically the vendor cybersecurity controls. Vendor controls are more targeted, focusing on data encryption, access control, staff security training, and incident response procedures. 2) Download the authority's official checklist and run a gap analysis on your current setup. Two-factor authentication, managed antivirus, and retaining logs for at least 12 months are the most scrutinized items.

On the cost side, getting a comprehensive compliance report from an independent audit firm can run between 40,000 SAR and 85,000 SAR. However, for a company your size, hiring an outside consultant for 10-15 days to address technical gaps and draft policy documents will likely cost around 15,000 - 25,000 SAR. Considering the 350,000 SAR contract value, that's a reasonable investment.

ÖÖmer O***Member
Job title
Field sales representative
Sector
Software
Organization type
sole proprietorship
Joined
Feb 2023
Message
135
#3

The items that trip people up most in technical audits are: encryption of data at rest in databases, multi-factor authentication (MFA) on all admin panels, and a central log server. Also, your cloud provider is required to have a local data center in Saudi Arabia under data sovereignty regulations.

OOsman K***MemberCommunity member
Joined
Mar 2024
Message
117
#4

Including these documents in your bid package might save the day: 1) A completed self-assessment form based on the official template, 2) A summary of your company information security policy, 3) A signed 60-day compliance commitment letter detailing target dates for any pending items. Public entities usually accept this commitment instead of an outright rejection.

CCaner K***VeteranCommunity member
Joined
May 2023
Message
21
#5

This happened to us last year on a 500,000 SAR public tender in Dammam. An audit firm quoted us 60,000 SAR, which was way over budget. We hired a local consultant for 18,000 SAR to conduct the gap analysis, write up the policies, and we won the contract. They came and inspected the controls on-site before final delivery.

VVildan A***Member
Job title
Information Security Specialist
Sector
Agriculture
Organization type
two-branch business
Joined
Jul 2023
Message
114
#6

If this clause is in the tender and you win the contract, the primary contractor retains the right to conduct unannounced audits throughout the project. Signing off that you're 'compliant' just to submit a bid without implementing actual technical measures is extremely risky. If a breach happens, you'll lose your performance bond and get blacklisted from official vendor registries.

DDoruk K***Expert
Job title
Quality Assurance Manager
Sector
Construction
Organization type
20-person company
Joined
Feb 2024
Message
28
#7

Does the tender documentation explicitly require a third-party verified report from an accredited audit firm, or is it just asking for a vendor commitment letter? That single detail can easily triple your costs.

YYavuz B***Member
Job title
Human Resources Specialist
Sector
Leather
Organization type
120-person company
Joined
Mar 2024
Message
5
#8

Cybersecurity regulations in the Saudi Arabian market have been made mandatory for critical infrastructure vendors over the last two years. It would be beneficial to view the specifications not as a one-off tender expense, but as an investment that will boost your enterprise business potential in the region.

GGamze Y***Member
Job title
Graphic Designer
Sector
Furniture manufacturing
Organization type
8-person team
Joined
Mar 2022
Message
6
#9

Don't let it intimidate you, sorting out the processes in a 14-person team is way faster than in big companies. Instead of buying expensive enterprise security software, you can quickly check off most of the controls by encrypting your existing infrastructure and setting clear logging and access rules.

UUğur Ö***Member
Job title
Warehouse Manager
Sector
Education
Organization type
family business
Joined
Jan 2023
Message
1
#10

Let me share my experience. When making a decision, first look at what data you have on hand.

When making a decision, first look at what data you have on hand. Good luck with that.

MMelis Ç***New member
Job title
Production planning
Sector
E-commerce
Organization type
sole proprietorship
Joined
May 2026
Message
179
#11

Just a heads-up. Most incidents start with a leaked password, not a vulnerability.

If you have questions write them; I'll answer as best I can.

YYusuf Ö***MemberCommunity member
Joined
Sep 2025
Message
325
#12

yes that's exactly how it is with cybersecurity compliance. payment informatino changes are never verified through the channel they came from.

correct me if Im wrong.

CCeren B***Member
Job title
Sales Manager
Sector
Law
Organization type
early-stage startup
Joined
Jan 2025
Message
282
#13

I have a question. An automated scan report is not the same as a penetration test.

Hope this helps.

EEmre T***Member
Job title
Purchasing manager
Sector
Security services
Organization type
cooperative
Joined
Feb 2024
Message
170
#14

Let me share what happened to me; it might be useful. Everyone rushing into cybersecurity compliance gets stuck at the same point.

I'm also curious if anyone does it differently.

HHasan U***MemberCommunity member
Joined
May 2024
Message
41
#15

Three different views emerged, they all complement each other. The harder it is to reverse a decision, the slower you should make it.

DDilara B***Member
Job title
Operations manager
Sector
Furniture manufacturing
Organization type
regional distributor
Joined
Jun 2024
Message
1

Doki · Interface design · 2024

#16

I've been down this road, let me tell you. If you don't write this down from the start, it leads to arguments later.

The real issue isn't the number, but what it's based on. Proven by experience.

MMetin T***Expert
Job title
Software team lead
Sector
Packaging
Organization type
8-person team
Joined
Dec 2024
Message
348
#17

I've been dealing with this for a long time. If you get three different answers on a topic, the question was asked wrong.

Of course, it varies if your situation is different.

SSena S***MemberCommunity member
Joined
May 2023
Message
175
#18

Yes, thats exactly how it is with cybersecurity compliance. I mean if permission and scope arent in writing dont start that test.

If its your first time, start small; scaling comes later. Thats all sorry if I went on too long.

AAslı Y***New memberCommunity member
Joined
Sep 2026
Message
304
#19

exactly like that. honestly if you get three different answers on a topic the question was asked wrong.

of course, it varise if your situation is different.

AAyşe A***New member
Job title
IT manager
Sector
Agriculture
Organization type
regional distributor
Joined
Jul 2026
Message
40

Doki · Incident response support · 2025

#20

Let me summarize what's been said so far. If permission and scope aren't in writing don't start that test.

Reply