Back to Blog
Cybersecurity

Saudi NCA's Tahqaq Service Now Scans Files and QR Codes Before Your Staff Open Them

Origami TeamEditorial Team
6 min read
Saudi NCA's Tahqaq Service Now Scans Files and QR Codes Before Your Staff Open Them
Like what we publish? Pin Origami as a preferred source on Google.Add as a preferred source on Google

How Do You Check That a File or QR Code Is Safe Before You Open It?

Any employee in your company can now scan a file or a QR code before opening it, using the Tahqaq service from Saudi Arabia's National Cybersecurity Authority (NCA). The service started on December 29, 2025 with link scanning only, and in October 2026 the NCA added file scanning and QR code scanning. Links and QR codes go to the WhatsApp number +966118136644, files are uploaded to the Haseen portal, and the result is instant, around the clock. What you need is one rule for your team: nobody opens an attachment they did not expect, or scans an unfamiliar code, before checking it. But remember that the result is an estimate of risk, not a guarantee, and file scanning is still in a trial phase.

What Changed in the Service?

The NCA launched the service on December 29, 2025, according to the Saudi Press Agency, to scan circulated links before people visit them. On October 7, 2026, coinciding with Global Cybersecurity Awareness Month, the NCA announced in its official news release two new features: file scanning and scanning of quick response codes, known as QR codes. The service is part of Haseen, the National Portal for Cybersecurity Services, and the NCA runs it in partnership with its technical arm, the Saudi Information Technology Company (SITE).

The detail many people miss on the official service page is that the two channels do not scan the same things:

ChannelWhat it scansHow to reach it
WhatsAppLinks and QR codes+966118136644
Haseen portalLinks, files and QR codestahqaq.haseen.gov.sa

In other words, file scanning is available on the Haseen portal only, according to the NCA's page. The Tahqaq for Files service page says the check is automated by the service engine, results are instant, and the service runs 24 hours a day, 7 days a week, in Arabic and English, with no documents required. The same page labels the file service a "beta".

Why Does This Matter for Your Company?

A breach in a company can start with one employee's click rather than a sophisticated attack. A PDF invoice from a supplier you do not know, a CV that reaches HR as a zipped file, a shipping notice asking you to open an attachment, or a sticker with a QR code that someone placed over the original payment sticker in your branch. The NCA says in its announcement that the new features respond to the growing use of files and QR codes in everyday activities.

A QR code is more dangerous than an ordinary link in one respect: a written link can be read, and you may notice that the site name looks wrong, but with a code you do not know where it leads until you scan it. Checking it before you open its destination closes a gap the eye cannot.

How Your Team Uses It: Five Steps

  • Save the right number: copy the WhatsApp number +966118136644 from the NCA's own page and save it on employees' phones under a clear name. Do not rely on a number that arrives in a message, because fraudsters impersonate government services.
  • Links and codes go to WhatsApp first: before tapping a link in a message, or scanning a code on a sticker, invoice or post, the employee sends it to the service number and waits for the result.
  • Files go to the Haseen portal: an attachment the employee did not expect, especially zipped files, executable files and documents that ask you to "enable content", is uploaded to the portal before it is opened.
  • Read the result as an estimate, not a verdict: the NCA says file scanning assesses the "likelihood" of a threat. If the result is suspicious, the employee deletes the file and tells whoever is responsible. If it comes back clean but the message itself is odd, such as an urgent payment request or a request for a password, they should call the sender on a number they already know before doing anything.
  • Share your feedback: the service lets you give feedback on the analysis result, so report a result you think is wrong, and log the case internally so the rest of the team knows what reached you.

The Limits of the Service: What It Does Not Cover

The service is useful, but it is not a protection system for your company. The NCA lists it under individual services, aimed at citizens and residents of the Kingdom. Keep three points in mind:

  • It does not replace basic protection: security software on every device, system updates, email filtering, backups and two-step verification all remain necessary. You will find these basics in our cybersecurity guide for small and medium businesses.
  • Scan what is suspicious, not your own documents: the service is for checking a strange file you received, not for uploading your contracts, payroll sheets or customer data. Do not upload a file containing sensitive data to any external scanning tool without need.
  • Entities have a different service: under its entity services, the NCA lists a service called Files Examination Services, which examines the file in an isolated environment including Windows 7 and Windows 10, and issues a full technical report within 5 minutes, with confidentiality of the file and report assured. Check on the Haseen portal whether your organization is eligible.

If Your Website or App Accepts Files From Customers

The service protects the employee who opens a file by hand. But if your website, app or recruitment system accepts files from customers and applicants, such as CVs, ID photos, invoices and complaint attachments, nobody is going to check hundreds of files manually. Here the scanning has to be part of the system itself: a defined list of allowed file types, a maximum size, an automatic scan before saving, and storage for uploaded files kept away from the main application server.

This is what we review at Origami when we build a new system or develop an existing one. If you would like us to review how your system accepts files today, get in touch.

#Tahqaq service#cybersecurity#file scanning#QR codes

Frequently asked questions

What is the Tahqaq service and how do I use it?+

A service from Saudi Arabia's National Cybersecurity Authority, part of the Haseen portal, that scans links, files and QR codes before you open them. Send a link or QR code to the WhatsApp number +966118136644, or upload a file on the Haseen portal at tahqaq.haseen.gov.sa. The result is instant.

Can I scan a file through Tahqaq on WhatsApp?+

According to the NCA's official page, the WhatsApp channel handles links and QR codes, while file scanning is available on the Haseen portal. The file service is still in beta.

If the service says a file is clean, can I open it without worry?+

The result is an estimate of the likelihood of a threat, not a guarantee. If the message itself is odd, such as an urgent payment request or a request for a password, confirm with the sender by calling a number you already know before doing anything.

Does Tahqaq replace security software on company devices?+

No. It is an individual service that helps an employee before opening a file or link, while security software, updates, email filtering and backups remain necessary. If your system accepts files from customers, the system itself should scan them automatically.

Follow Origami in Google

Pin Origami as a preferred source and our articles will surface first for you in Google Search and Top Stories.

Add as a preferred source on Google

Related articles

Have a project in mind?

We build custom systems, apps and websites for your business. Tell us your idea and we will give you a straight answer on it.

One session. Twenty minutes. No commitments.