
Data Residency Requirements for Cloud Adoption in the Kingdom
Residency rarely comes from one law. How PDPL, NCA controls, data classification and sector regulation combine — and a method for deciding where each workload can live.
How the CCC extends the ECC for cloud, what it asks of providers and of tenants, and how to turn shared responsibility into evidence both sides can rely on.

The Cloud Cybersecurity Controls (CCC) are issued by the National Cybersecurity Authority as an extension of the Essential Cybersecurity Controls. Where the ECC sets the national baseline, the CCC adds requirements specific to cloud computing, for organisations that provide cloud services and for those that use them.
As with other NCA frameworks, confirm the current published edition before you assess; the NCA revises its controls as technology and threats evolve.
| Cloud service providers (CSPs) | Cloud service tenants (CSTs) | |
|---|---|---|
| Who | Organisations providing cloud services in or to the Kingdom | Organisations using cloud services, particularly those within the ECC's scope |
| Focus | Securing the cloud platform, its operations and its personnel | Securing their use of the cloud — identities, data, configuration and supplier oversight |
| Typical evidence | Platform controls, certifications, hosting location, incident handling | Configuration baselines, access governance, data classification, contract terms |
Data classification is central to cloud decisions in the Kingdom. The national data classification approach defines levels of sensitivity, and the more sensitive the data, the stricter the expectations on where and how it may be hosted. For government and critical infrastructure data in particular, hosting inside the Kingdom is often required.
In practice, this means classification must happen before migration. Moving data first and classifying later is how organisations find themselves with non-compliant hosting that is expensive to reverse.
Every cloud service divides security responsibilities between provider and tenant, and the division changes between infrastructure, platform and software services. The CCC is effective only when that division is explicit. For each service you use:
The CCC works alongside the ECC, the Data Cybersecurity Controls, PDPL transfer rules and sector regulation from bodies such as SAMA. Mapping all of them to a single cloud control baseline — enforced through policy-as-code in your landing zone — turns compliance into configuration rather than paperwork.
Maintained continuously, this evidence makes any assessment — by the NCA, a sector regulator or an auditor — a review rather than a scramble.
Each of these is straightforward to fix once identified. A short cloud security review against the CCC — covering classification, identities, logging, configuration and contracts — usually surfaces them within a few weeks and produces a prioritised plan to close them.

Residency rarely comes from one law. How PDPL, NCA controls, data classification and sector regulation combine — and a method for deciding where each workload can live.

Who the Essential Cybersecurity Controls apply to, how they are structured, the governance requirements that trip organisations up, and a phased route to demonstrable compliance.

A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.