NCA Data Cybersecurity Controls (DCC-1:2022) and the Data Lifecycle
The Data Cybersecurity Controls (DCC-1:2022) are the National Cybersecurity Authority's control set devoted specifically to data — identifying it, classifying it, protecting it, sharing it, retaining it and destroying it. Of all the NCA frameworks it is the one most directly aligned with what a data-centric security platform does, because its stages correspond almost one-to-one with discover, classify, protect and monitor.
PDPL scope
NCA DCC lifecycle
Classified document
Regulation overview
| Official name | Data Cybersecurity Controls (DCC-1:2022) |
| Issuing authority | National Cybersecurity Authority (NCA) |
| Jurisdiction | Kingdom of Saudi Arabia |
| Relationship to ECC | Extends the Essential Cybersecurity Controls with data-specific requirements rather than replacing them |
| Who it applies to | Organizations within NCA scope that handle data requiring protection under national cybersecurity requirements |
Data security requirements and how Siberson supports them
Only requirements with a defensible technical relationship to the platform are listed. No control identifiers are cited.
| Regulatory requirement | Security objective | Siberson capability | Product |
|---|---|---|---|
| Data identification | Establish what regulated and sensitive data the organization actually holds | Content-inspecting discovery across databases, file shares, endpoints and cloud storage, reporting findings at column and file level | Siberson Veriket Data Discovery |
| Data classification and labeling | Record sensitivity in a form that survives copying and sharing | Labels written into document metadata plus headers, footers and watermarks, applied automatically at creation or by the user | Siberson Veriket Data Classification |
| Controls over data movement and sharing | Govern where classified data may travel and through which channels | Classification-aware policies with block, warn, justify and log outcomes, enforced offline as well as online | Siberson Verikor DLP |
| Integrity across the lifecycle | Show whether protected data and its configuration were altered without authorization | Baseline hashing with real-time change detection and line-level investigation of what changed | Siberson Verifim File Integrity Monitoring |
Products referenced on this page
Siberson Veriket Data Discovery
Siberson Veriket Data Discovery helps enterprises identify sensitive and regulated information across structured and unstructured data environments.
Find out moreSiberson Veriket Data Classification
Siberson Veriket Data Classification helps organizations classify and label sensitive information according to enterprise and regulatory data handling policies.
Find out moreSiberson Verikor DLP
Siberson Verikor DLP is an enterprise Data Loss Prevention solution designed to help organizations protect sensitive information and enforce data security policies across enterprise environments.
Find out moreSiberson Verifim File Integrity Monitoring
Siberson Verifim File Integrity Monitoring helps organizations detect unauthorized changes to critical files and improve security monitoring and auditability.
Find out moreNCA DCC — questions & answers
What are the NCA Data Cybersecurity Controls?
Which solutions help with NCA Data Cybersecurity Controls?
Does DCC replace the Essential Cybersecurity Controls?
Can classification labels drive DLP decisions?
Regulatory sources
Last reviewed: August 2026
Regulatory applicability varies by organization, industry and deployment. Siberson provides technical security capabilities and does not constitute legal or regulatory advice. Siberson is not certified, approved or endorsed by any authority named on this page.
Build your GCC data security compliance strategy
Map your discovery, classification, DLP and integrity monitoring capabilities against the requirements relevant to your operations.
Request a Demo