Skip to main content
NCA DCC · Saudi data security

Show regulators your data is protected with evidence, not promises.

NCA DCC sets cybersecurity requirements for protecting data throughout its lifecycle, and it builds on the ECC baseline. Summit tests how your data is actually protected and delivers evidence and a board-ready report.

Human-led VAPT · NDA first · report in 48h

3
main domains: governance, defense, and third-party and cloud
2022
year the first version, DCC-1:2022, was issued by the NCA
1
baseline it relates to: the Essential Cybersecurity Controls (ECC)
Lifecycle
controls follow data from creation through storage, use and disposal
Board and leadership view

Why NCA DCC matters to your board

The work is technical. The consequences of getting NCA DCC wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Revenue and contract access

Customers that hand you sensitive data want proof it is protected. Clear, tested evidence shortens reviews and supports renewals.

Regulatory exposure

A data breach lands on leadership. Evidence that controls were assessed, tested and fixed shows management acted.

Reputation

Leaked data damages trust for years. Protecting it, and being able to show how, is part of your brand.

Deadlines and ownership

Named data owners and a dated plan keep the programme on track and make accountability clear.

Fit

Who usually needs NCA DCC

Government entities and suppliers

Bodies that hold sensitive public-sector data, and the vendors that process it for them, are asked to show strong data controls.

Financial and payments firms

Organisations holding customer and transaction data use DCC-style controls to structure data protection.

Healthcare and insurance

Providers holding sensitive personal records need clear classification, access and encryption controls.

Cloud and data processors

Companies that store or process data on behalf of Saudi customers can expect DCC questions in reviews.

Scope of work

What Summit delivers for NCA DCC

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

Your data controls compared with DCC, and with the ECC controls you already have.

Penetration testing

Manual testing that tries to reach sensitive data through applications, APIs and infrastructure.

Control validation

Checks that classification, encryption, access control and logging work in practice.

Evidence pack

Test results and artefacts organised by control, ready for review.

Remediation support and retest

Guidance for your engineers, then a retest to confirm each fix.

Board-ready report

A plain-language summary of data risk, progress and decisions for executives.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A practical DCC readiness path

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Map your data

    Weeks 1 to 3

    Find where sensitive data is created, stored and shared, and who owns it.

  2. 2

    Run a gap analysis

    Weeks 3 to 5

    Compare data controls with DCC, and with the ECC controls you already have.

  3. 3

    Close the gaps

    Months 2 to 3

    Apply classification, encryption, access control and logging where they are missing.

  4. 4

    Test data protection

    Month 3 to 4

    Penetration testing and control validation check whether data can be reached, copied or exposed.

  5. 5

    Retest and report

    Month 4 to 5

    Confirm fixes, assemble the evidence pack and prepare the board-ready report.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • Data risk summary

    Which data is most exposed and what it would cost the business if lost.

  • Prioritised decisions

    What needs budget or sign-off, in order.

  • Owners and dates

    Who owns each dataset and each fix.

  • Evidence status

    Which controls have proof ready and which are still open.

  • Retest results

    Confirmation that fixes held, for customers and regulators.

The detail

What NCA DCC actually is

The Data Cybersecurity Controls (DCC) are published by the Saudi National Cybersecurity Authority. They focus on protecting data itself, wherever it lives and however it moves, and are organised into three domains: Cybersecurity Governance, Cybersecurity Defense and Third-Party and Cloud Computing Cybersecurity.

DCC is designed to work alongside the Essential Cybersecurity Controls. The document includes an appendix showing how DCC relates to ECC, so organisations that already meet ECC can see where additional data-specific work is needed rather than starting again.

DCC is about cybersecurity for data, not privacy law. Saudi personal data law is a separate subject, although the same encryption, access control and logging evidence often supports both. Scope and applicability are set by the NCA, so confirm them against the published text.

Key terms in plain English

Data lifecycle
The stages data passes through: creation, storage, use, sharing, archiving and disposal.
Data classification
Rating data by sensitivity so that stronger controls protect more sensitive information.
Encryption at rest and in transit
Scrambling stored data and data on the move so that it is unreadable without the key.
Data leakage prevention
Technical and process controls that stop sensitive data leaving where it should not.
Requirements

What DCC asks for, domain by domain

DCC takes the ideas in ECC and applies them to data. These are the areas where assessors usually look for proof.

1

Data cybersecurity governance

Policies, roles and risk management specific to data. Leadership should know what data the organisation holds, how sensitive it is and who is accountable for protecting it.

What it looks like in practice

  • A data cybersecurity policy approved by management
  • Data owners named for key datasets
  • Risk assessments that cover data handling
  • Awareness training on data handling
2

Data protection and defense

Technical and operational controls that protect data: classification and labelling, access control, encryption, secure storage and transfer, leakage prevention, logging of data access, and secure disposal.

What it looks like in practice

  • Data classified and labelled by sensitivity
  • Encryption at rest and in transit with managed keys
  • Access limited to those who need the data
  • Logs of who accessed sensitive data and when
3

Third-party and cloud computing cybersecurity

Data often sits with suppliers and cloud services. This area covers contracts, due diligence and oversight so that data stays protected when someone else handles it.

What it looks like in practice

  • Security terms for suppliers that handle data
  • Knowledge of where data is hosted
  • Regular review of supplier assurance
  • Exit and deletion arrangements
Where testing fits

How penetration testing supports NCA DCC

DCC is about proving data is protected in practice. Testing tries to reach sensitive data the way an attacker would, which gives you evidence that classification, access control and encryption work as designed.

Defense

Access to data

Testing checks whether users and attackers can reach data beyond what their role allows.

Defense

Encryption and transfer

Validation confirms data is protected in storage and in transit, including through APIs.

Defense

Leakage paths

Testing looks for ways sensitive data could leave through applications, exports or misconfigured storage.

Third-party

Supplier and cloud links

Testing the connections to suppliers and cloud services shows how shared data is protected.

Avoid these

Common NCA DCC mistakes, and how to avoid them

!

Not knowing where the data is

You cannot protect or evidence what you have not mapped. Start with a data inventory.

!

Classification on paper only

Labels that do not drive access and encryption rules do not protect anything.

!

Treating DCC as a privacy exercise

DCC is cybersecurity for data. Privacy law is related but separate.

!

Overlooking suppliers

Data held by suppliers and cloud services remains your responsibility to oversee.

FAQ

NCA DCC questions, answered

What is NCA DCC?

The Data Cybersecurity Controls issued by Saudi Arabia’s National Cybersecurity Authority. They set cybersecurity requirements for protecting data across its lifecycle.

How does DCC relate to ECC?

DCC is designed to work alongside ECC. The document includes an appendix on the relationship, so you can reuse ECC work and add data-specific controls.

What is the current version?

DCC-1:2022. Check the NCA website for the latest text.

Is DCC the same as Saudi PDPL?

No. DCC covers cybersecurity controls for data. PDPL is a personal data protection law. Evidence such as encryption and access logs often helps with both.

Is DCC a certificate?

No. It is a set of control requirements. Whether your evidence is accepted is decided by the NCA or the requesting customer or regulator.

Does DCC require penetration testing?

Testing is the clearest way to show that your data controls work in practice, and it supports the defense requirements.

Is this legal advice?

No. It is educational. For binding interpretation, refer to the NCA’s published documents and your own counsel.

Ready to get NCA DCC sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →