nca.gov.sa
New Cloud Cybersecurity Controls Released Amidst Data Localization Changes
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 24, 2026, the Cloud Cybersecurity Controls (CCC – 2: 2024) were updated to address data localization requirements affecting Cloud Service Providers (CSPs) and Cloud Service Tenants (CSTs). This update aims to enhance national cybersecurity goals by establishing minimum cybersecurity requirements for cloud computing services. The CCC serves as an extension to the existing ECC framework, focusing on mitigating cyber risks associated with cloud services. The update was last modified on June 24, 2026, and is intended to help CSPs and CSTs ensure secure cloud operations. The Cloud Controls Matrix (CCM) was also released on the same day, providing a comprehensive framework for assessing cloud security controls and aligning with industry standards. The CCM includes 197 control objectives across 17 domains, guiding organizations in implementing necessary security measures. Both frameworks are crucial for organizations looking to bolster their cloud security posture in light of evolving threats.
Key Points: • The Cloud Cybersecurity Controls (CCC – 2: 2024) were updated to enhance national cybersecurity. • The CCC sets minimum cybersecurity requirements for Cloud Service Providers and Tenants. • The Cloud Controls Matrix (CCM) provides a comprehensive framework for assessing cloud security.