Saudi National Cybersecurity Authority mark.

The Saudi National Cybersecurity Authority's Cloud Cybersecurity Controls extend its Essential Cybersecurity Controls for cloud services. They address both cloud service providers and cloud service tenants. NCA identifies CCC–2:2024 as an update that includes changes to data-localisation requirements. See the NCA CCC publication page.

Use in a programme

Establish whether the organisation acts as a provider, tenant or both, and identify the relevant cloud services and data. Review the applicable control scope and responsibility allocation with the provider and accountable business owners.

Maintain evidence for the controls your organisation operates and the assurance it obtains from other parties. Shared responsibility does not mean that either party can assume all required work is handled by the other.

Use in CSFaaS

The reviewed reference library offers NCA CCC-1:2020 - EN. This is an earlier edition than the updated publication identified by NCA. Resolve that edition difference before treating the imported framework as the current assessment baseline.

Use Systems and Third Parties to document cloud dependencies and link relevant policies and evidence to the assessed requirements. Keep workspace additions and source-edition changes clearly attributed.