NCA Cloud Cybersecurity Controls (CCC-2:2024) and Cloud Data Protection
The Cloud Cybersecurity Controls (CCC-2:2024) address the split of responsibility between cloud service providers and the organizations that use them. The 2024 edition updated the earlier controls, including in relation to data localization. For a data-centric security programme the practical consequence is that sensitivity must be decided before data reaches the cloud, and cloud repositories must be searchable afterwards.
PDPL scope
NCA DCC lifecycle
Classified document
Regulation overview
| Official name | Cloud Cybersecurity Controls (CCC-2:2024) |
| Issuing authority | National Cybersecurity Authority (NCA) |
| Jurisdiction | Kingdom of Saudi Arabia |
| Status | Current edition, published 2024; updates the earlier CCC-1:2020, including in relation to data localization requirements |
| Who it applies to | Cloud service providers and the organizations subscribing to cloud services within NCA scope |
Data security requirements and how Siberson supports them
Only requirements with a defensible technical relationship to the platform are listed. No control identifiers are cited.
| Regulatory requirement | Security objective | Siberson capability | Product |
|---|---|---|---|
| Knowing what is in cloud repositories | Locate regulated data that reached cloud storage without being reviewed | Scanning of cloud storage alongside on-premises repositories, with findings reported in the same inventory | Siberson Veriket Data Discovery |
| Classifying before data leaves the endpoint | Make the sensitivity decision where the file is created, not after it has been shared | Classification applied at creation, copy and download; the label persists in the file as it moves into cloud storage | Siberson Veriket Data Classification |
| Controlling upload to cloud and web channels | Prevent classified data from being uploaded through unapproved services | Endpoint policies covering web and cloud upload channels, evaluated against the file's classification | Siberson Verikor DLP |
Products referenced on this page
Siberson Veriket Data Discovery
Siberson Veriket Data Discovery helps enterprises identify sensitive and regulated information across structured and unstructured data environments.
Find out moreSiberson Veriket Data Classification
Siberson Veriket Data Classification helps organizations classify and label sensitive information according to enterprise and regulatory data handling policies.
Find out moreSiberson Verikor DLP
Siberson Verikor DLP is an enterprise Data Loss Prevention solution designed to help organizations protect sensitive information and enforce data security policies across enterprise environments.
Find out moreNCA CCC — questions & answers
What are the NCA Cloud Cybersecurity Controls?
Does classification still apply once a file is in the cloud?
Can Siberson support organizations that keep data in the Kingdom?
Regulatory sources
Last reviewed: August 2026
Regulatory applicability varies by organization, industry and deployment. Siberson provides technical security capabilities and does not constitute legal or regulatory advice. Siberson is not certified, approved or endorsed by any authority named on this page.
Build your GCC data security compliance strategy
Map your discovery, classification, DLP and integrity monitoring capabilities against the requirements relevant to your operations.
Request a Demo