Revenue and contract access
Customers that hand you sensitive data want proof it is protected. Clear, tested evidence shortens reviews and supports renewals.
NCA DCC sets cybersecurity requirements for protecting data throughout its lifecycle, and it builds on the ECC baseline. Summit tests how your data is actually protected and delivers evidence and a board-ready report.
Human-led VAPT · NDA first · report in 48h
The work is technical. The consequences of getting NCA DCC wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.
Customers that hand you sensitive data want proof it is protected. Clear, tested evidence shortens reviews and supports renewals.
A data breach lands on leadership. Evidence that controls were assessed, tested and fixed shows management acted.
Leaked data damages trust for years. Protecting it, and being able to show how, is part of your brand.
Named data owners and a dated plan keep the programme on track and make accountability clear.
Bodies that hold sensitive public-sector data, and the vendors that process it for them, are asked to show strong data controls.
Organisations holding customer and transaction data use DCC-style controls to structure data protection.
Providers holding sensitive personal records need clear classification, access and encryption controls.
Companies that store or process data on behalf of Saudi customers can expect DCC questions in reviews.
One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.
Your data controls compared with DCC, and with the ECC controls you already have.
Manual testing that tries to reach sensitive data through applications, APIs and infrastructure.
Checks that classification, encryption, access control and logging work in practice.
Test results and artefacts organised by control, ready for review.
Guidance for your engineers, then a retest to confirm each fix.
A plain-language summary of data risk, progress and decisions for executives.
Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.
Find where sensitive data is created, stored and shared, and who owns it.
Compare data controls with DCC, and with the ECC controls you already have.
Apply classification, encryption, access control and logging where they are missing.
Penetration testing and control validation check whether data can be reached, copied or exposed.
Confirm fixes, assemble the evidence pack and prepare the board-ready report.
Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.
Which data is most exposed and what it would cost the business if lost.
What needs budget or sign-off, in order.
Who owns each dataset and each fix.
Which controls have proof ready and which are still open.
Confirmation that fixes held, for customers and regulators.
The Data Cybersecurity Controls (DCC) are published by the Saudi National Cybersecurity Authority. They focus on protecting data itself, wherever it lives and however it moves, and are organised into three domains: Cybersecurity Governance, Cybersecurity Defense and Third-Party and Cloud Computing Cybersecurity.
DCC is designed to work alongside the Essential Cybersecurity Controls. The document includes an appendix showing how DCC relates to ECC, so organisations that already meet ECC can see where additional data-specific work is needed rather than starting again.
DCC is about cybersecurity for data, not privacy law. Saudi personal data law is a separate subject, although the same encryption, access control and logging evidence often supports both. Scope and applicability are set by the NCA, so confirm them against the published text.
DCC takes the ideas in ECC and applies them to data. These are the areas where assessors usually look for proof.
Policies, roles and risk management specific to data. Leadership should know what data the organisation holds, how sensitive it is and who is accountable for protecting it.
Technical and operational controls that protect data: classification and labelling, access control, encryption, secure storage and transfer, leakage prevention, logging of data access, and secure disposal.
Data often sits with suppliers and cloud services. This area covers contracts, due diligence and oversight so that data stays protected when someone else handles it.
DCC is about proving data is protected in practice. Testing tries to reach sensitive data the way an attacker would, which gives you evidence that classification, access control and encryption work as designed.
Testing checks whether users and attackers can reach data beyond what their role allows.
Validation confirms data is protected in storage and in transit, including through APIs.
Testing looks for ways sensitive data could leave through applications, exports or misconfigured storage.
Testing the connections to suppliers and cloud services shows how shared data is protected.
You cannot protect or evidence what you have not mapped. Start with a data inventory.
Labels that do not drive access and encryption rules do not protect anything.
DCC is cybersecurity for data. Privacy law is related but separate.
Data held by suppliers and cloud services remains your responsibility to oversee.
The Data Cybersecurity Controls issued by Saudi Arabia’s National Cybersecurity Authority. They set cybersecurity requirements for protecting data across its lifecycle.
DCC is designed to work alongside ECC. The document includes an appendix on the relationship, so you can reuse ECC work and add data-specific controls.
DCC-1:2022. Check the NCA website for the latest text.
No. DCC covers cybersecurity controls for data. PDPL is a personal data protection law. Evidence such as encryption and access logs often helps with both.
No. It is a set of control requirements. Whether your evidence is accepted is decided by the NCA or the requesting customer or regulator.
Testing is the clearest way to show that your data controls work in practice, and it supports the defense requirements.
No. It is educational. For binding interpretation, refer to the NCA’s published documents and your own counsel.
Browse all 23 security and compliance frameworks or see our penetration testing services.
Last reviewed October 2026. Requirements change; confirm current texts and dates before you commit to a plan.
Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.
Get a Quote in 15 mins →Disclaimer. Summit provides independent technical and risk assessments. This is not legal advice or a regulatory certification. Acceptance of any report is decided by the requesting auditor, customer or regulator.