Cloud Cybersecurity Controls (CCC-2:2024) compliance software
NCA's cloud-specific controls for Saudi cloud service providers and their tenants — 175 controls across 4 domains, each population seeing only the text NCA wrote for it.
- Issuing authorityNational Cybersecurity Authority (NCA)
- InstrumentCCC-2:2024, supersedes CCC-1:2020
- Structure4 domains, 24 subdomains, 175 controls — Provider 131, Tenant 44
- ClassificationAnnex A — top-secret, secret, confidential, public; highest classification governs
What Saudi CCC-2 requires
Who it applies to
- Cloud Service Providers operating in or serving Saudi Arabia
- Cloud Service Tenants — government, CNI and private-sector organisations consuming cloud services
- Organisations previously assessed against CCC-1:2020 migrating to CCC-2:2024
- Groups running both a CSP and a CST assessment where they operate on both sides
The Cloud Cybersecurity Controls (CCC-2:2024), issued by Saudi Arabia's National Cybersecurity Authority, set cybersecurity requirements specifically for cloud computing — for the Cloud Service Provider (CSP) operating the environment and, separately, for the Cloud Service Tenant (CST) consuming it. CCC-2:2024 supersedes CCC-1:2020, deleting the data-residency subcontrols that moved to SDAIA's National Data Management Office and retitling 'Confidential' data to 'Sensitive' data.
The controls are textually distinct for each side: Provider carries 37 main controls (94 sub-controls), Tenant carries 18 main controls (26 sub-controls) — 175 in total across four domains: Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience and Third-Party Cybersecurity. Annex A sets four cloud data-classification levels — top-secret, secret, confidential and public — and marks which controls are mandatory or optional at each.
GRCLens carries the controls as one framework with two populations. A tenant declares whether it is assessing as a CSP or a CST, or both, and the assessment, dashboard and report scope to that population's own control set — a CST is never asked about a CSP's data-centre staffing controls, and a CSP is never asked about a tenant's exit strategy.
How GRCLens supports Saudi CCC-2
Saudi CCC-2 runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Provider and Tenant, scoped apart
Declare CSP, CST or both. The assessment shows only the 131 Provider controls or the 44 Tenant controls that NCA actually addressed to that population.
Annex A classification levels
Controls that are mandatory only up to a given classification level are marked as such, so a public-data-only deployment is not held to a top-secret control it does not need.
Superseding CCC-1:2020
Entities moving off the 2020 edition see the residency subcontrols removed and reassigned to SDAIA/NDMO where CCC-2:2024 no longer covers them, so nothing is silently dropped.
Arabic and English
Every control, category and guidance note carried in both languages.
Saudi CCC-2 frequently asked questions
What's the difference between the Provider and Tenant control sets?
CCC-2:2024 writes two distinct sets of controls: 37 main controls (94 sub-controls) for the Cloud Service Provider operating the environment, and 18 main controls (26 sub-controls) for the Cloud Service Tenant consuming it. An organisation assesses whichever population, or both, apply to it.
Does CCC-2:2024 still require in-Kingdom data residency?
No — the data-residency subcontrols present in CCC-1:2020 were removed and moved to SDAIA's National Data Management Office; CCC-2:2024 itself carries no residency clause.
How do the Annex A classification levels work?
Four data-classification levels — top-secret, secret, confidential and public — with the highest classification in a mixed dataset governing. Most controls are mandatory at every level; a defined set is mandatory only at the higher three, optional at public.
One platform, many obligations

Talk to us about Saudi CCC-2
Security Solution Consultants provides Saudi cloud security advisory alongside the platform, so you can combine tooling with hands-on expertise.