Wadira: Find your way through Saudi data & privacy law.

HomeFrameworksCybersecurity › Guide to Cloud Cybersecurity Controls (CCC) Implementation

Guide to Cloud Cybersecurity Controls (CCC) Implementation

TypeGuideline
Issuing authorityNational Cybersecurity Authority (NCA)
FrameworkCybersecurity
TierGuidelines & circulars
Legal statusGuidance

The Guide to Cloud Cybersecurity Controls: Cloud Service Tenants Implementation (GCCC-CST-1:2023) is the National Cybersecurity Authority's implementation guide for its Cloud Cybersecurity Controls (CCC), published to help in-scope entities meet the compliance requirements the controls impose. Its focus is the tenant side of cloud adoption: organisations that use, or plan to use, cloud computing and hosting services.

The guide presents the CCC domain and subdomain structure (spanning cybersecurity governance, defence and resilience), explains how the guideline itself is organised, and then provides implementation guidance, with a section addressed to cloud service providers and a detailed section for cloud service tenants. It complements the Cloud Cybersecurity Controls themselves, which extend the NCA's Essential Cybersecurity Controls (ECC) baseline into cloud environments, and belongs to the NCA's series of implementation guides covering the CSCC, DCC, OSMACC, OTCC and TCC control sets.

Documents

In this framework


Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13