New Cloud Cybersecurity Controls Released Amidst Data Localization Changes

New Cloud Cybersecurity Controls Released Amidst Data Localization Changes

First seen 24 Jul 2026, 21:20 UTC cloudsecurityalliance.orgnca.gov.sa 71% similarity 39.8

Article Content

Browse articles
ThreatCluster

On July 24, 2026, the Cloud Cybersecurity Controls (CCC – 2: 2024) were updated to address data localization requirements affecting Cloud Service Providers (CSPs) and Cloud Service Tenants (CSTs). This update aims to enhance national cybersecurity goals by establishing minimum cybersecurity requirements for cloud computing services. The CCC serves as an extension to the existing ECC framework, focusing on mitigating cyber risks associated with cloud services. The update was last modified on June 24, 2026, and is intended to help CSPs and CSTs ensure secure cloud operations. The Cloud Controls Matrix (CCM) was also released on the same day, providing a comprehensive framework for assessing cloud security controls and aligning with industry standards. The CCM includes 197 control objectives across 17 domains, guiding organizations in implementing necessary security measures. Both frameworks are crucial for organizations looking to bolster their cloud security posture in light of evolving threats.

Key Points: • The Cloud Cybersecurity Controls (CCC – 2: 2024) were updated to enhance national cybersecurity. • The CCC sets minimum cybersecurity requirements for Cloud Service Providers and Tenants. • The Cloud Controls Matrix (CCM) provides a comprehensive framework for assessing cloud security.

ThreatCluster AI

Timeline

2026-06-24
Cloud Cybersecurity Controls updated
The CCC – 2: 2024 was modified to include new data localization requirements for CSPs and CSTs.
nca.gov.sa
2026-07-24
Cloud Controls Matrix released
The CCM was published, offering a structured assessment tool for cloud security controls across 17 domains.
cloudsecurityalliance.org

Community

Browse all →