HomeFrameworksNational Cyber & Cloud SchemesCCC

Framework  National Cyber & Cloud Schemes

CCC

The Cloud Cybersecurity Controls (CCC-1:2020) are Saudi Arabia's National Cybersecurity Authority requirements for cloud computing, written as an extension to the Essential Cybersecurity Controls (ECC).

They address two audiences at once: cloud service providers (CSPs) that host in-scope services, and cloud service tenants (CSTs), meaning the government bodies and critical infrastructure operators that consume them.

The controls sit in the same four domains as the ECC (governance, defense, resilience, third-party and cloud) and are tiered into levels that track the classification of the data a service handles, so a provider hosting more sensitive government workloads must meet more controls.

The NCA has issued a revised edition, CCC-2 (verify the publication date and transition timing on the NCA controls page). Anyone subject to the ECC who uses cloud must also comply with the CCC; the CCC does not replace the ECC.

In writing, a tenant needs a cloud policy and risk assessment, a data classification that drives which CCC level applies, contracts with providers that carry the NCA obligations, and monitoring records.

A provider needs a cybersecurity strategy and organization, documented controls for each CCC requirement at the level offered, data residency and segregation evidence for Saudi data, incident reporting procedures aligned to NCA timelines, and a compliance self-assessment. Both file compliance results with the NCA through its assessment tooling.

AI-compiled
Share
Sponsored
CCC
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with CCC
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Cloud service tenants: all Saudi government organizations (ministries, authorities, establishments and their companies), and private organizations that own, operate, or host critical national infrastructure, wherever located, that use or plan to use cloud services. Cloud service providers: any CSP that provides cloud services to an in-scope tenant, including foreign providers.

Other Saudi organizations are encouraged to adopt the controls voluntarily.

What the assessor asks to see

Cloud strategy and policy; data classification and mapping of workloads to CCC levels; contracts with providers containing NCA-required clauses; provider self-assessment against each CCC control with implementation evidence; data residency and logical segregation evidence; identity and access management records; cryptography and key management; logging and monitoring; incident response plans and notification records; business continuity and disaster recovery tests; personnel screening for provider staff; compliance reports submitted to the NCA.

Assessors

Who assesses CCC

Self-assessment by the in-scope organization, reported to the NCA, with the NCA (and for critical infrastructure the relevant sector regulator) able to audit and verify. There is no private certification scheme for the CCC; consultants assist but do not certify on the NCA's behalf. the NCA is the regulator and reviewer.

No firm has claimed a CCC assessor listing yet. Claim yours →

Consultants

Who helps with CCC

Saudi and regional cybersecurity consultancies and the local arms of global firms offer ECC and CCC gap assessments, control implementation, and compliance reporting; several GRC tools ship the NCA control sets. Engagements run three to twelve months depending on the provider's starting maturity and target level.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a CCC consultant listing yet. Claim yours →

Software

Tools for CCC

Tools that name this framework in their own material.

No firm has claimed a CCC tool listing yet. Claim yours →

Need a hand implementing it?

Find a Consultant for CCC

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with CCC

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.