Siberson
Partnership Contact Request a Demo
Regulations · Saudi Arabia

NCA Data Cybersecurity Controls (DCC-1:2022) and the Data Lifecycle

The Data Cybersecurity Controls (DCC-1:2022) are the National Cybersecurity Authority's control set devoted specifically to data — identifying it, classifying it, protecting it, sharing it, retaining it and destroying it. Of all the NCA frameworks it is the one most directly aligned with what a data-centric security platform does, because its stages correspond almost one-to-one with discover, classify, protect and monitor.

Siberson · Saudi Arabia
Personal data located

PDPL scope

Mapped
Classification applied

NCA DCC lifecycle

Labelled
Egress attempt — external e-mail

Classified document

Blocked
Control evidence — NCA ECC · SAMA CSF
At a glance

Regulation overview

Regulation overview
Official nameData Cybersecurity Controls (DCC-1:2022)
Issuing authorityNational Cybersecurity Authority (NCA)
JurisdictionKingdom of Saudi Arabia
Relationship to ECCExtends the Essential Cybersecurity Controls with data-specific requirements rather than replacing them
Who it applies toOrganizations within NCA scope that handle data requiring protection under national cybersecurity requirements
Capability mapping

Data security requirements and how Siberson supports them

Only requirements with a defensible technical relationship to the platform are listed. No control identifiers are cited.

Regulatory requirement to Siberson capability mapping
Regulatory requirementSecurity objectiveSiberson capabilityProduct
Data identificationEstablish what regulated and sensitive data the organization actually holdsContent-inspecting discovery across databases, file shares, endpoints and cloud storage, reporting findings at column and file levelSiberson Veriket Data Discovery
Data classification and labelingRecord sensitivity in a form that survives copying and sharingLabels written into document metadata plus headers, footers and watermarks, applied automatically at creation or by the userSiberson Veriket Data Classification
Controls over data movement and sharingGovern where classified data may travel and through which channelsClassification-aware policies with block, warn, justify and log outcomes, enforced offline as well as onlineSiberson Verikor DLP
Integrity across the lifecycleShow whether protected data and its configuration were altered without authorizationBaseline hashing with real-time change detection and line-level investigation of what changedSiberson Verifim File Integrity Monitoring
FAQ

NCA DCC — questions & answers

What are the NCA Data Cybersecurity Controls?
DCC-1:2022 is a National Cybersecurity Authority control set focused on the data lifecycle. Rather than covering cybersecurity generally, it addresses how data is identified, classified, protected, shared, retained and destroyed, and it extends rather than replaces the Essential Cybersecurity Controls.
Which solutions help with NCA Data Cybersecurity Controls?
Siberson provides capabilities relevant to each stage: Siberson Veriket Data Discovery for identification, Siberson Veriket Data Classification for classification and labeling, Siberson Verikor DLP for controls over data movement, and Siberson Verifim File Integrity Monitoring for integrity and monitoring objectives.
Does DCC replace the Essential Cybersecurity Controls?
No. The Data Cybersecurity Controls extend the ECC with data-specific requirements. An organization in scope for both is expected to meet the ECC baseline and the additional data controls.
Can classification labels drive DLP decisions?
Yes — that is the design. Siberson Veriket Data Classification writes the sensitivity label into the file, and Siberson Verikor DLP reads it when the file is about to move. That gives the policy a stronger signal than content pattern matching alone and reduces false positives.
Primary sources

Regulatory sources

Last reviewed: August 2026

Regulatory applicability varies by organization, industry and deployment. Siberson provides technical security capabilities and does not constitute legal or regulatory advice. Siberson is not certified, approved or endorsed by any authority named on this page.

Build your GCC data security compliance strategy

Map your discovery, classification, DLP and integrity monitoring capabilities against the requirements relevant to your operations.

Request a Demo