Skip to main content
NCA CCC · Saudi cloud security

Keep Saudi cloud customers with tested controls you can show.

NCA CCC sets the cybersecurity expectations for cloud service providers and the organisations that run workloads in the cloud. Summit tests your cloud environment and turns the results into evidence and a board-ready report.

Human-led VAPT · NDA first · report in 48h

2
roles with their own duties: cloud service providers and cloud service tenants
4
main domains: governance, defense, resilience and third-party
2024
current version, CCC-2:2024, published by the NCA
1
baseline it extends: the Essential Cybersecurity Controls (ECC)
Board and leadership view

Why NCA CCC matters to your board

The work is technical. The consequences of getting NCA CCC wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Revenue and contract access

Saudi customers moving to the cloud ask providers and vendors how they meet CCC. A clear answer keeps deals moving and renewals safe.

Regulatory exposure

Cloud responsibility is split between provider and tenant. Tested evidence shows leadership understood its side and acted on it.

Reputation

Cloud misconfigurations are a common source of public breaches. Finding them first protects customer trust.

Deadlines and ownership

A scoped plan that names the owner for each cloud control keeps migrations and reviews from stalling.

Fit

Who usually needs NCA CCC

Cloud and hosting providers

If you offer cloud services to customers in Saudi Arabia, CCC sets the provider-side requirements.

Government and regulated tenants

Organisations moving workloads to the cloud need to show their own tenant controls are in place.

SaaS and managed service providers

Software and managed services built on cloud platforms are often asked how they meet CCC in customer reviews.

Data and analytics companies

Anyone hosting sensitive Saudi customer data in the cloud should expect questions on classification and access.

Scope of work

What Summit delivers for NCA CCC

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

Your cloud environment compared with the CCC requirements for your role, ranked by risk.

Penetration testing

Manual testing of cloud workloads, identity, networks and APIs with proof of impact.

Control validation

Checks that encryption, access, logging and recovery work as documented.

Evidence pack

Findings and artefacts organised by control, ready for customer or regulator review.

Remediation support and retest

Practical fixes for your engineers, then a retest to confirm they hold.

Board-ready report

A plain-language view of cloud risk, progress and decisions for executives.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A practical CCC readiness path

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Work out your role

    Week 1

    Decide whether you are a provider, a tenant or both, and which services and data are in scope.

  2. 2

    Run a gap analysis

    Weeks 2 to 4

    Compare your cloud environment and processes with the controls that apply to your role.

  3. 3

    Close the gaps

    Months 2 to 3

    Fix configuration, access and monitoring gaps and update policies to match reality.

  4. 4

    Test the environment

    Month 3

    Penetration testing and control validation of cloud workloads, identity, networks and APIs.

  5. 5

    Retest and assemble evidence

    Month 4

    Confirm fixes and package results by control, with a board-ready report.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • Cloud risk summary

    Where your cloud environment stands against CCC, without the jargon.

  • Responsibility map

    Which controls are yours and which sit with your cloud provider.

  • Prioritised decisions

    What needs budget or sign-off, and why it matters to the business.

  • Owners and dates

    Who fixes each issue and by when.

  • Retest results

    Evidence that the fixes worked, for customers and regulators.

The detail

What NCA CCC actually is

The Cloud Cybersecurity Controls (CCC) are issued by the Saudi National Cybersecurity Authority. They cover two kinds of organisation: cloud service providers (CSPs) that deliver cloud services, and cloud service tenants (CSTs), the organisations that consume them.

CCC does not replace ECC. It extends and complements it with requirements specific to cloud, such as how a provider separates customers, how data is protected in shared infrastructure, and what a tenant must do to secure the workloads it runs. Providers and tenants carry different duties, so the first job is to work out which side you are on, or both.

The controls are organised under governance, defense, resilience and third-party cybersecurity. Which requirements apply to you can depend on the service model and on the sensitivity of the data you host. Check the NCA’s published text for the exact rules in your case.

Key terms in plain English

CSP
Cloud service provider: the organisation that offers cloud services such as hosting, platforms or software.
CST
Cloud service tenant: the organisation that uses a cloud service to run its own systems or store its data.
Shared responsibility
The split between what the provider secures and what the customer must secure themselves.
Data classification
Rating information by sensitivity so stronger controls protect more sensitive data.
Requirements

What CCC asks for, in practice

CCC is organised by domain, and your duties depend on whether you are a provider, a tenant or both. This is how the requirements look in day-to-day work.

1

Cybersecurity governance for cloud

Policies, roles, risk management and compliance processes for cloud services. For providers this includes how customer data and services are governed; for tenants it covers the decision to use cloud and who is accountable.

What it looks like in practice

  • Cloud-specific policies and risk assessments
  • Clear roles for provider and tenant responsibilities
  • Review of the provider’s security commitments
  • Management oversight of cloud decisions
2

Cybersecurity defense in the cloud

The largest area. It covers identity and access, network and workload protection, encryption and key management, secure configuration, vulnerability management, logging and monitoring, and incident response in cloud environments.

What it looks like in practice

  • Strong authentication and least-privilege access
  • Encryption with controlled key management
  • Hardened configurations for cloud resources
  • Penetration testing of cloud workloads and APIs
3

Cybersecurity resilience

Cloud services must keep running or recover quickly. Assessors look for backup, recovery and continuity arrangements that cover the cloud environment and have actually been tested.

What it looks like in practice

  • Backups that are restorable and tested
  • Recovery plans covering cloud dependencies
  • Evidence of exercises and results
4

Third-party cybersecurity

Cloud services depend on other suppliers. This area covers due diligence, contract terms and ongoing oversight of the parties that touch your cloud service or data.

What it looks like in practice

  • Supplier security requirements in contracts
  • Review of supplier assurance evidence
  • A current register of dependencies
Where testing fits

How penetration testing supports NCA CCC

CCC puts weight on secure configuration, vulnerability management and defence of cloud workloads. Testing the live environment shows whether those controls hold up, and a retest proves the fixes worked.

Defense

Identity and access

Testing checks that tenants and roles can only reach what they should, including privileged accounts.

Defense

Configuration and workloads

Manual review and testing finds misconfigured storage, networks and services before attackers do.

Defense

Vulnerability management

Findings are tracked to closure and confirmed by a retest, giving dated evidence.

Third-party

Cloud boundaries

Testing the points where your environment meets suppliers and platforms shows how those links are protected.

Avoid these

Common NCA CCC mistakes, and how to avoid them

!

Assuming the provider covers everything

Shared responsibility means tenants still own identity, configuration and data protection in their own environment.

!

Not knowing which role applies

Provider and tenant duties differ. Confusing them leads to controls built for the wrong side.

!

Testing only the application

Cloud risk often sits in identity, storage and network settings, so those need testing too.

!

Skipping ECC

CCC builds on ECC. Gaps in the baseline show up again in cloud reviews.

FAQ

NCA CCC questions, answered

Who does NCA CCC apply to?

Cloud service providers and cloud service tenants operating in Saudi Arabia. Your duties depend on your role, so confirm which side you are on first.

How does CCC relate to ECC?

CCC extends and complements ECC with cloud-specific requirements. ECC remains the baseline, so organisations in scope for both should plan them together.

What is the current version?

CCC-2:2024. Check the NCA website for the latest text and for any updates since.

Is CCC a certificate?

No. It is a set of control requirements. Whether your evidence is accepted is decided by the NCA or the customer or regulator that requested it.

Does CCC require penetration testing?

Its defense requirements include vulnerability management and testing of cloud environments. A manual test with a retest is the clearest way to show it.

Does using a global cloud provider cover me?

Not entirely. The provider handles its part, but you remain responsible for your own configuration, access and data.

Is this legal advice?

No. It is educational. For binding interpretation, refer to the NCA’s published documents and your own counsel.

Ready to get NCA CCC sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →