Riyadh | +966‑557400202 | hello@nazztec.com
Cloud & DevOps

NCA Cloud Cybersecurity Controls (CCC) Explained

How the CCC extends the ECC for cloud, what it asks of providers and of tenants, and how to turn shared responsibility into evidence both sides can rely on.

25 August 20267 min readNAZZTEC Editorial Team
NCA Cloud Cybersecurity Controls (CCC) Explained — cover illustration

Key takeaways

  • The CCC extends the Essential Cybersecurity Controls for cloud environments.
  • It sets requirements for both cloud service providers and cloud service tenants.
  • Data classification drives many hosting and location decisions.
  • Shared responsibility must be written down, not assumed.

What the CCC is

The Cloud Cybersecurity Controls (CCC) are issued by the National Cybersecurity Authority as an extension of the Essential Cybersecurity Controls. Where the ECC sets the national baseline, the CCC adds requirements specific to cloud computing, for organisations that provide cloud services and for those that use them.

As with other NCA frameworks, confirm the current published edition before you assess; the NCA revises its controls as technology and threats evolve.

Two audiences, two sets of obligations

Cloud service providers (CSPs)Cloud service tenants (CSTs)
WhoOrganisations providing cloud services in or to the KingdomOrganisations using cloud services, particularly those within the ECC's scope
FocusSecuring the cloud platform, its operations and its personnelSecuring their use of the cloud — identities, data, configuration and supplier oversight
Typical evidencePlatform controls, certifications, hosting location, incident handlingConfiguration baselines, access governance, data classification, contract terms

What tenants are expected to do

  • Classify data before moving it to the cloud, and choose hosting accordingly.
  • Choose providers that can demonstrate the controls and hosting location your data classification requires.
  • Govern identities — strong authentication, least privilege and regular access review for cloud administrators.
  • Protect data — encryption in transit and at rest, with key management appropriate to sensitivity.
  • Monitor — collect and review cloud activity and security logs.
  • Contract clearly — include cybersecurity requirements, incident notification, audit rights and exit provisions.
  • Plan exit — make sure data can be retrieved and securely deleted if the relationship ends.

Data classification and location

Data classification is central to cloud decisions in the Kingdom. The national data classification approach defines levels of sensitivity, and the more sensitive the data, the stricter the expectations on where and how it may be hosted. For government and critical infrastructure data in particular, hosting inside the Kingdom is often required.

In practice, this means classification must happen before migration. Moving data first and classifying later is how organisations find themselves with non-compliant hosting that is expensive to reverse.

Making shared responsibility real

Every cloud service divides security responsibilities between provider and tenant, and the division changes between infrastructure, platform and software services. The CCC is effective only when that division is explicit. For each service you use:

  • Document which controls the provider operates and how they evidence them.
  • Document which controls you operate, with named owners.
  • Identify any shared controls and how each side contributes.
  • Review the arrangement when services, contracts or regulations change.

How the CCC fits with other obligations

The CCC works alongside the ECC, the Data Cybersecurity Controls, PDPL transfer rules and sector regulation from bodies such as SAMA. Mapping all of them to a single cloud control baseline — enforced through policy-as-code in your landing zone — turns compliance into configuration rather than paperwork.

An evidence checklist for tenants

  • Data classification records for every workload hosted in the cloud.
  • A register of cloud services in use, with the provider, service model and hosting location.
  • The shared responsibility matrix for each service, with named internal owners.
  • Configuration baselines and evidence of enforcement, such as policy-as-code reports.
  • Privileged access reviews for cloud administrators.
  • Cloud security logs retained and reviewed, with alerts investigated.
  • Contract clauses covering security requirements, incident notification, audit rights and exit.
  • Exit and data retrieval procedures, tested where practical.

Maintained continuously, this evidence makes any assessment — by the NCA, a sector regulator or an auditor — a review rather than a scramble.

Common gaps we see

  • Cloud services adopted by business teams without security review or classification.
  • Administrator accounts without strong authentication or regular review.
  • Logs retained by the provider but never collected or monitored by the tenant.
  • Contracts that say nothing about incident notification, audit rights or exit.
  • Assumptions that the provider handles security controls that are in fact the tenant's responsibility.

Each of these is straightforward to fix once identified. A short cloud security review against the CCC — covering classification, identities, logging, configuration and contracts — usually surfaces them within a few weeks and produces a prioritised plan to close them.

Frequently asked questions

Does the CCC apply to private companies?
It applies to cloud service providers and to tenants within the scope of the NCA's frameworks, including government organisations and critical infrastructure operators. Other organisations benefit from using it as a reference.
Is using a certified cloud provider enough for CCC compliance?
No. A compliant provider covers the provider's responsibilities. Tenants remain responsible for how they configure and use the service.
Must all data stay in Saudi Arabia?
Not necessarily. Requirements depend on data classification, sector and applicable regulations. Sensitive government and critical infrastructure data commonly must remain in the Kingdom.
Keep reading

More insights

Talk to the team behind this briefing

Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.

We respond to every enquiry within one business day.