
NCA Cloud Cybersecurity Controls (CCC) Explained
How the CCC extends the ECC for cloud, what it asks of providers and of tenants, and how to turn shared responsibility into evidence both sides can rely on.
Residency rarely comes from one law. How PDPL, NCA controls, data classification and sector regulation combine — and a method for deciding where each workload can live.

Saudi Arabia's digital transformation has accelerated cloud adoption across government and the private sector. At the same time, the Kingdom has built a clear expectation that sensitive data is protected and, in many cases, kept in-country. Organisations that treat residency as a checkbox at the end of a migration often discover they must redesign.
There is rarely a single rule that answers the question “can this data leave the Kingdom?” The answer comes from reading several obligations together.
The national data classification approach groups data by sensitivity — from public through restricted, secret and top secret. Classification determines which hosting options are acceptable. Before any cloud decision:
| Data profile | Typical hosting approach |
|---|---|
| Highly sensitive government or critical infrastructure data | In-Kingdom hosting with providers and services that meet the applicable NCA and sector requirements |
| Personal data of Saudi residents | In-Kingdom by default; transfers only where a PDPL condition and documented assessment support them |
| Regulated financial data | Per SAMA outsourcing and cloud requirements, confirmed with the regulator where needed |
| Public or low-sensitivity data | Broader choice, including global services, subject to contract terms |
These are general patterns, not legal advice. Specific decisions should be confirmed against the current text of each obligation.
Residency does not have to mean giving up modern services. Hybrid architectures keep sensitive data and its processing in-Kingdom while using global services for non-sensitive workloads. Tokenisation and pseudonymisation can let analytics run on data that no longer identifies individuals. And because in-country cloud capacity in the Kingdom has expanded quickly, options that were unavailable a few years ago may now exist — always confirm current service availability in each in-country region before finalising a design.
Record the answers in the contract or its annexes. A residency commitment made in a sales meeting is only useful if it is written down.
Residency is not a one-off decision. Regulations are updated, providers open new regions and add services, and your own workloads change. Review hosting decisions at least annually and whenever a significant change occurs — a new data type, a new provider service or a regulatory update. A simple register of workloads, their data classification, hosting location and the rationale behind it makes these reviews quick and gives auditors a clear trail.

How the CCC extends the ECC for cloud, what it asks of providers and of tenants, and how to turn shared responsibility into evidence both sides can rely on.

Who the Essential Cybersecurity Controls apply to, how they are structured, the governance requirements that trip organisations up, and a phased route to demonstrable compliance.

A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.