Revenue and contract access
Saudi customers moving to the cloud ask providers and vendors how they meet CCC. A clear answer keeps deals moving and renewals safe.
NCA CCC sets the cybersecurity expectations for cloud service providers and the organisations that run workloads in the cloud. Summit tests your cloud environment and turns the results into evidence and a board-ready report.
Human-led VAPT · NDA first · report in 48h
The work is technical. The consequences of getting NCA CCC wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.
Saudi customers moving to the cloud ask providers and vendors how they meet CCC. A clear answer keeps deals moving and renewals safe.
Cloud responsibility is split between provider and tenant. Tested evidence shows leadership understood its side and acted on it.
Cloud misconfigurations are a common source of public breaches. Finding them first protects customer trust.
A scoped plan that names the owner for each cloud control keeps migrations and reviews from stalling.
If you offer cloud services to customers in Saudi Arabia, CCC sets the provider-side requirements.
Organisations moving workloads to the cloud need to show their own tenant controls are in place.
Software and managed services built on cloud platforms are often asked how they meet CCC in customer reviews.
Anyone hosting sensitive Saudi customer data in the cloud should expect questions on classification and access.
One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.
Your cloud environment compared with the CCC requirements for your role, ranked by risk.
Manual testing of cloud workloads, identity, networks and APIs with proof of impact.
Checks that encryption, access, logging and recovery work as documented.
Findings and artefacts organised by control, ready for customer or regulator review.
Practical fixes for your engineers, then a retest to confirm they hold.
A plain-language view of cloud risk, progress and decisions for executives.
Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.
Decide whether you are a provider, a tenant or both, and which services and data are in scope.
Compare your cloud environment and processes with the controls that apply to your role.
Fix configuration, access and monitoring gaps and update policies to match reality.
Penetration testing and control validation of cloud workloads, identity, networks and APIs.
Confirm fixes and package results by control, with a board-ready report.
Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.
Where your cloud environment stands against CCC, without the jargon.
Which controls are yours and which sit with your cloud provider.
What needs budget or sign-off, and why it matters to the business.
Who fixes each issue and by when.
Evidence that the fixes worked, for customers and regulators.
The Cloud Cybersecurity Controls (CCC) are issued by the Saudi National Cybersecurity Authority. They cover two kinds of organisation: cloud service providers (CSPs) that deliver cloud services, and cloud service tenants (CSTs), the organisations that consume them.
CCC does not replace ECC. It extends and complements it with requirements specific to cloud, such as how a provider separates customers, how data is protected in shared infrastructure, and what a tenant must do to secure the workloads it runs. Providers and tenants carry different duties, so the first job is to work out which side you are on, or both.
The controls are organised under governance, defense, resilience and third-party cybersecurity. Which requirements apply to you can depend on the service model and on the sensitivity of the data you host. Check the NCA’s published text for the exact rules in your case.
CCC is organised by domain, and your duties depend on whether you are a provider, a tenant or both. This is how the requirements look in day-to-day work.
Policies, roles, risk management and compliance processes for cloud services. For providers this includes how customer data and services are governed; for tenants it covers the decision to use cloud and who is accountable.
The largest area. It covers identity and access, network and workload protection, encryption and key management, secure configuration, vulnerability management, logging and monitoring, and incident response in cloud environments.
Cloud services must keep running or recover quickly. Assessors look for backup, recovery and continuity arrangements that cover the cloud environment and have actually been tested.
Cloud services depend on other suppliers. This area covers due diligence, contract terms and ongoing oversight of the parties that touch your cloud service or data.
CCC puts weight on secure configuration, vulnerability management and defence of cloud workloads. Testing the live environment shows whether those controls hold up, and a retest proves the fixes worked.
Testing checks that tenants and roles can only reach what they should, including privileged accounts.
Manual review and testing finds misconfigured storage, networks and services before attackers do.
Findings are tracked to closure and confirmed by a retest, giving dated evidence.
Testing the points where your environment meets suppliers and platforms shows how those links are protected.
Shared responsibility means tenants still own identity, configuration and data protection in their own environment.
Provider and tenant duties differ. Confusing them leads to controls built for the wrong side.
Cloud risk often sits in identity, storage and network settings, so those need testing too.
CCC builds on ECC. Gaps in the baseline show up again in cloud reviews.
Cloud service providers and cloud service tenants operating in Saudi Arabia. Your duties depend on your role, so confirm which side you are on first.
CCC extends and complements ECC with cloud-specific requirements. ECC remains the baseline, so organisations in scope for both should plan them together.
CCC-2:2024. Check the NCA website for the latest text and for any updates since.
No. It is a set of control requirements. Whether your evidence is accepted is decided by the NCA or the customer or regulator that requested it.
Its defense requirements include vulnerability management and testing of cloud environments. A manual test with a retest is the clearest way to show it.
Not entirely. The provider handles its part, but you remain responsible for your own configuration, access and data.
No. It is educational. For binding interpretation, refer to the NCA’s published documents and your own counsel.
Browse all 23 security and compliance frameworks or see our penetration testing services.
Last reviewed October 2026. Requirements change; confirm current texts and dates before you commit to a plan.
Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.
Get a Quote in 15 mins →Disclaimer. Summit provides independent technical and risk assessments. This is not legal advice or a regulatory certification. Acceptance of any report is decided by the requesting auditor, customer or regulator.