A
Experience our Helpdesk AI for 24/7 Facility Service Automation
Back to Blog
Compliance

NCA & ZATCA Compliance Checklist for Facility Management Software

ADOX AI Research
July 24, 2026
9 min read
NCA & ZATCA Compliance Checklist for Facility Management Software

A CAFM platform that can't pass a ZATCA integration test doesn't send invalid invoices. It sends invoices that don't legally exist. That's the part most facility management teams don't find out until an audit, a client contract review, or a finance team asking why the numbers in two systems don't match.

Two Saudi regulatory frameworks now reach directly into the software your facility team runs day to day: the National Cybersecurity Authority's Essential Cybersecurity Controls (NCA ECC) and ZATCA's e-invoicing mandate. Neither was written with facility management software specifically in mind. Both apply to it anyway, and the gap between "we're aware of ZATCA" and "our CAFM platform actually passes integration" is where most of the real risk sits.

This is a working checklist, not a legal summary. Verify current requirements with ZATCA and NCA directly, or with your compliance counsel — the wave schedules and control sets change, and this guide reflects where things stood as of mid-2026.

Why This Applies to Facility Management Software Specifically

It's easy to file NCA and ZATCA under "finance's problem" or "IT's problem" and move on. Two things make that a mistake for facility management specifically.

Facility management runs on invoices. Service charge billing, tenant work request invoicing, SLA-based billing across a multi-client portfolio, maintenance contract invoicing — if your CAFM platform touches any of this, it's an invoicing system under ZATCA's definition, whether or not anyone on the team thinks of it that way.

Facility management sits inside critical infrastructure. Airports, hospitals, utilities, government buildings, and large commercial portfolios are exactly the sectors NCA's cybersecurity controls target — and the software managing the assets and floor plans inside those facilities is part of what falls under supply-chain scrutiny, even when the facility management company itself isn't the primary regulated entity.

Part 1: NCA Essential Cybersecurity Controls (ECC-2:2024)

The NCA's Essential Cybersecurity Controls set a mandatory cybersecurity baseline — not a voluntary best-practice framework. The current version, ECC-2:2024, replaced the original 2018 controls and is organized into 4 domains, 28 subdomains, and roughly 110 individual controls.

Who it actually applies to:

  • Tier 1 — mandatory: all Saudi government entities.
  • Tier 2 — mandatory: private-sector organizations operating critical national infrastructure — telecoms, energy, water, healthcare systems, transport, banking infrastructure, and organizations processing sensitive national data.
  • Everyone downstream of both tiers: ECC compliance extends through the supply chain. A facility management company or software vendor serving a government entity or critical-infrastructure client can be pulled into ECC requirements through the contract itself, even without being directly regulated.

What to check in your CAFM platform:

  • Data residency. Where is your facility, asset, and floor-plan data physically hosted? A platform with no Saudi cloud hosting option (AWS Riyadh region and Azure KSA region are the two most commonly used) is a harder sell for exactly the clients most likely to demand ECC alignment — government and critical-infrastructure facilities.
  • Access control and audit logging. ECC requires demonstrable access controls and activity logging, not just a login screen. Ask whether the platform logs who accessed which asset record, work order, or floor plan, and for how long that log is retained.
  • Incident response documentation. Can the vendor produce an actual incident response plan on request, or only a general statement that security is taken seriously?
  • Certifications that back the claim. ISO 27001 alignment is the most common signal vendors point to. Ask for the certificate, not the badge on the website — a logo isn't evidence.

One requirement worth flagging even though it's about your organization rather than your software: ECC-2:2024 expanded the requirement that cybersecurity roles be filled by qualified Saudi nationals to a broader set of positions, not just senior ones. That's a staffing decision, not a procurement decision, but it shapes who on your team needs to own the vendor relationship.

Part 2: ZATCA E-Invoicing — Phase 2 (Integration Phase)

ZATCA's e-invoicing mandate rolled out in two phases. Phase 1 (Generation Phase) required businesses to generate and store invoices electronically — a relatively low bar most systems could meet with software updates. Phase 2 (Integration Phase) is a different order of requirement: real-time or near-real-time integration between your invoicing system and ZATCA's Fatoora platform, with every invoice validated by ZATCA before it carries legal standing.

What Phase 2 actually requires, technically:

  • Direct API integration with ZATCA's Fatoora platform — not a batch export, a live connection.
  • Invoices generated in UBL 2.1 XML format, or PDF/A-3 with embedded XML.
  • A cryptographic stamp and a UUID (Unique Universal Identifier) on every invoice.
  • A TLV-encoded QR code on every invoice.
  • Sequential invoice numbering.
  • A digital certificate issued for electronic signing.
  • Successful testing in ZATCA's sandbox environment before going live.

The rollout is happening in waves, not all at once. ZATCA is phasing in Phase 2 compliance by taxpayer revenue size. As of mid-2026, the active wave (Wave 24) covers businesses with taxable turnover above SAR 375,000 in 2022, 2023, or 2024, with a compliance window running from April through the end of June 2026. If your organization or your facility management client falls in scope, the deadline is closer than the wave number makes it sound — confirm your specific assigned wave and date directly with ZATCA rather than assuming.

What to check in your CAFM platform:

  • Does it generate invoices in the required XML/PDF-A3 format natively, or does someone need to export data into a separate ZATCA-compliant billing tool?
  • Does it apply the cryptographic stamp, UUID, and QR code automatically, or is that a manual step someone has to remember on every invoice?
  • Has the vendor actually connected to ZATCA's sandbox and demonstrated a passing integration — ask to see it, not just hear about it.
  • If your facility management operation bills across multiple clients or a multi-tenant portfolio, confirm the platform can apply correct, compliant invoicing per client or per site, not just at a single organizational level.

The Checklist

Print this, or hand it to whoever's running vendor evaluation.

NCA / cybersecurity

  • Data hosted on Saudi-region cloud infrastructure (or a clearly documented equivalent)
  • Access controls with per-user activity logging on assets, work orders, and floor plans
  • Documented incident response plan available on request
  • ISO 27001 certificate (not just a badge) provided on request
  • Vendor can describe how ECC-2:2024 supply-chain requirements apply to their platform specifically

ZATCA / e-invoicing

  • Native XML (UBL 2.1) or PDF/A-3 invoice generation, no manual export step
  • Automatic cryptographic stamp, UUID, and QR code on every invoice
  • Sequential invoice numbering built in
  • Demonstrated, working integration with ZATCA's Fatoora sandbox
  • Correct compliant invoicing per client/site for multi-tenant or multi-client portfolios
  • Vendor can confirm which ZATCA wave your organization falls into and your compliance deadline

Red Flags

"We're ZATCA compliant" with no specifics. Compliant with Phase 1 or Phase 2? Tested in the sandbox, or planned for a future release? Ask which wave they've been tested against.

A cybersecurity page with no certificate to show for it. "Bank-level security" and similar phrasing without a named framework or a document you can request is marketing language, not a compliance answer.

Invoicing that lives in a bolt-on module. If ZATCA compliance was added as a separate add-on after the fact rather than built into the core invoicing flow, it's more likely to break when your billing structure gets complicated — multiple sites, multiple clients, mixed VAT scenarios.

Frequently Asked Questions

Does NCA ECC-2:2024 apply to private facility management companies?
Directly, only if the company operates critical national infrastructure — telecoms, energy, water, healthcare, transport, or banking infrastructure. Indirectly, many more facility management companies are pulled in through supply-chain requirements when they serve a government entity or a critical-infrastructure client, since ECC compliance obligations can flow through the contract.

Is ZATCA e-invoicing mandatory for all facility management companies?
It applies to any VAT-registered business issuing invoices in Saudi Arabia, which includes most facility management operations that bill for services, maintenance contracts, or tenant work requests. The compliance deadline depends on your taxable turnover and assigned wave — confirm your specific wave and date with ZATCA directly.

What's the difference between ZATCA Phase 1 and Phase 2?
Phase 1 (Generation Phase) required generating and storing invoices electronically. Phase 2 (Integration Phase) requires real-time integration with ZATCA's Fatoora platform, with every invoice validated by ZATCA — including cryptographic stamps, UUIDs, QR codes, and UBL 2.1 XML formatting — before it carries legal standing.

Can I use a separate billing tool instead of relying on my CAFM platform for ZATCA compliance?
Yes, and some organizations do. The tradeoff is a second system to maintain and a manual or semi-manual data handoff between the two, which is exactly the kind of step that breaks quietly during an audit. A CAFM platform with native ZATCA integration removes that handoff.

How do I confirm which ZATCA wave my organization is in?
ZATCA notifies targeted taxpayers directly ahead of their assigned wave based on taxable turnover in prior years. Confirm your status through ZATCA's official channels or your tax advisor rather than assuming based on company size alone — wave assignments are based on specific turnover thresholds and reporting years.

[ADOX AI CAFM](/) generates ZATCA-compliant invoices natively and hosts on Saudi cloud infrastructure (AWS Riyadh and Azure KSA regions) as part of its NCA-aligned compliance framework. See the full ZATCA E-Invoicing & Saudi VAT Guide for the technical detail, or [book a demo](/book-demo) to see the invoicing flow directly.

Read more: Best CAFM Software in Saudi Arabia: 2026 Buyer's Guide

Local deployment case study: Facility Management Software in Riyadh

Share this article
Get Started Today

Ready to Transform Your Facility Operations?

Join 500+ GCC enterprises using ADOX AI CAFM to reduce costs, eliminate downtime, and build smarter facilities. Deployment starts in 4 weeks.

No credit card required·GCC cloud hosting·Arabic + English·Dedicated onboarding included