
Two regulators shape almost every security and cloud decision in Saudi Arabia: the National Cybersecurity Authority (NCA) and, for financial institutions, the Saudi Central Bank (SAMA). What each requires, how they fit together, and the practical steps to reach and prove compliance.
Essential Cybersecurity Controls (ECC) are the NCA's baseline. They set the minimum cybersecurity requirements for in-scope national organisations across governance, defence, resilience, and third-party and cloud risk. If you operate critical or sensitive systems in the Kingdom, ECC is the floor — not the ceiling.
Cloud Cybersecurity Controls (CCC) extend the ECC specifically for the cloud. They define requirements for both cloud service providers and cloud tenants (your organisation, when you consume cloud), covering classification, data location, encryption, identity, monitoring, incident response, and exit. The CCC is why a lift-and-shift to the cloud in Saudi Arabia is never just a technical migration — the controls gate what can move, where it can be hosted, and how it must be protected. A compliant move usually pairs cloud migration with documented in-Kingdom hosting on Google Cloud.
Sensitive and government-classified data generally must be hosted inside the Kingdom, in accredited data centres, with no processing or transfer outside Saudi borders. Before you migrate a workload, you classify the data, confirm the hosting region and provider meet the controls, and document the decision. Getting this wrong is the most common reason a cloud project stalls in audit.
If you're a bank, insurer, fintech, or other SAMA-regulated entity, you also fall under the SAMA Cybersecurity Framework — a sector-specific, more prescriptive regime. Financial institutions typically must satisfy both NCA (ECC/CCC) and SAMA simultaneously, and SAMA adds stricter expectations in areas such as governance maturity, third-party risk, and prior approval for cloud hosting of financial data.
The practical takeaway: a fintech moving to the cloud in Saudi Arabia is solving for two overlapping frameworks at once. The fastest path is to map controls once, to a single evidence set, rather than running two parallel compliance programs.
| Framework | Who it applies to | What it governs |
|---|---|---|
| NCA ECC | In-scope national organisations | Baseline cybersecurity controls (the minimum) |
| NCA CCC | Cloud providers and cloud tenants | Cloud-specific controls, data location, exit |
| SAMA CSF | SAMA-regulated financial entities | Sector framework — stricter, runs alongside NCA |
Apex Aether is a Saudi-based team that designs, secures, documents, and hands over technology built to these controls — Saudi-led, no black boxes. We align delivery to NCA and SAMA standards and bring the platforms the controls call for:
Every engagement ends the way compliance auditors like: documented, validated, and owned by you. Scoping a migration or a compliance gap? Talk to an engineer →
Tell us what you're modernizing. We'll design, secure, document, and hand it over.
Talk to an engineer