Siberson
Partnership Contact Request a Demo
Regulations · Saudi Arabia

NCA Cloud Cybersecurity Controls (CCC-2:2024) and Cloud Data Protection

The Cloud Cybersecurity Controls (CCC-2:2024) address the split of responsibility between cloud service providers and the organizations that use them. The 2024 edition updated the earlier controls, including in relation to data localization. For a data-centric security programme the practical consequence is that sensitivity must be decided before data reaches the cloud, and cloud repositories must be searchable afterwards.

Siberson · Saudi Arabia
Personal data located

PDPL scope

Mapped
Classification applied

NCA DCC lifecycle

Labelled
Egress attempt — external e-mail

Classified document

Blocked
Control evidence — NCA ECC · SAMA CSF
At a glance

Regulation overview

Regulation overview
Official nameCloud Cybersecurity Controls (CCC-2:2024)
Issuing authorityNational Cybersecurity Authority (NCA)
JurisdictionKingdom of Saudi Arabia
StatusCurrent edition, published 2024; updates the earlier CCC-1:2020, including in relation to data localization requirements
Who it applies toCloud service providers and the organizations subscribing to cloud services within NCA scope
Capability mapping

Data security requirements and how Siberson supports them

Only requirements with a defensible technical relationship to the platform are listed. No control identifiers are cited.

Regulatory requirement to Siberson capability mapping
Regulatory requirementSecurity objectiveSiberson capabilityProduct
Knowing what is in cloud repositoriesLocate regulated data that reached cloud storage without being reviewedScanning of cloud storage alongside on-premises repositories, with findings reported in the same inventorySiberson Veriket Data Discovery
Classifying before data leaves the endpointMake the sensitivity decision where the file is created, not after it has been sharedClassification applied at creation, copy and download; the label persists in the file as it moves into cloud storageSiberson Veriket Data Classification
Controlling upload to cloud and web channelsPrevent classified data from being uploaded through unapproved servicesEndpoint policies covering web and cloud upload channels, evaluated against the file's classificationSiberson Verikor DLP
FAQ

NCA CCC — questions & answers

What are the NCA Cloud Cybersecurity Controls?
The Cloud Cybersecurity Controls are the National Cybersecurity Authority's requirements for cloud service providers and the organizations that subscribe to them. The current edition is CCC-2:2024, which updated the 2020 controls including in relation to data localization.
Does classification still apply once a file is in the cloud?
Siberson Veriket Data Classification writes the label into the document's own metadata and can add a visible marking, so the sensitivity decision travels with the file rather than living only in a separate register. Cloud repositories can also be scanned afterwards for data that arrived without a label.
Can Siberson support organizations that keep data in the Kingdom?
Yes. The platform is designed for on-premises deployment, including air-gapped and sovereign environments, which is the usual answer where data residency is a constraint. Deployment choice remains the organization's decision based on its own regulatory analysis.
Primary sources

Regulatory sources

Last reviewed: August 2026

Regulatory applicability varies by organization, industry and deployment. Siberson provides technical security capabilities and does not constitute legal or regulatory advice. Siberson is not certified, approved or endorsed by any authority named on this page.

Build your GCC data security compliance strategy

Map your discovery, classification, DLP and integrity monitoring capabilities against the requirements relevant to your operations.

Request a Demo