NCA DCC Compliance Checklist (Free Template)
A free NCA DCC-1:2022 compliance checklist — the four classification levels, every control by data lifecycle stage, and the third-party sharing rules.
Most teams scope the Data Cybersecurity Controls around databases and file shares, then discover during assessment that the controls also cover printed documents, multifunction printers, cross-shredders and the room a consultant works in. The DCC applies to all forms of physical and digital data, structured and unstructured — and about a third of the work sits outside the technology estate.
This is the structured NCA DCC compliance checklist, organised by the framework's three domains, with the classification levels and lifecycle stages that determine applicability. A downloadable working copy is available at the end.
Before you start: classification determines everything
Every DCC control is marked applicable or not at each of four classification levels, drawn from SDAIA's scheme:
Public · Confidential · Secret · Top Secret
Without a completed classification exercise there is no applicable control set — only a document. Some controls apply at all four levels; many apply only at Secret and Top Secret.
How to use this checklist
- Set the classification for each data domain first, then filter the checklist to the applicable levels.
- Mark the current state — compliant, partially compliant, or non-compliant.
- Assign the line to the process owner who already runs that lifecycle stage, not to the security team by default.
- Note the evidence reference and the assessment date.
- Identify the gap and the action required.
Domain 1 — Cybersecurity Governance
1-1 Periodical cybersecurity review and audit. Review of DCC implementation on the cadence specified for each classification level, with findings tracked to closure.
1-2 Cybersecurity in human resources. Personnel requirements for staff handling classified data, before, during and after employment.
1-3 Cybersecurity awareness and training programme. The awareness programme must cover data protection topics specifically:
- Risks of data leakage and unauthorised access during the data lifecycle (all levels)
- Secure handling of classified data while travelling and outside the workplace (Confidential and above)
- Secure handling of data during meetings, virtual and in person (Confidential and above)
- Secure use of printers, scanners and copy machines (Confidential and above)
- Procedures for secure data disposal (Confidential and above)
- Risks of sharing documents through non-secure channels (all levels)
- Cybersecurity risks of external storage media (all levels)
Domain 2 — Cybersecurity Defence
2-1 Identity and access management. Access to classified data granted on need, reviewed on cadence. Maps to the Share and Use lifecycle stages.
2-2 Information system and information processing facilities protection. Hardening and protection of the systems holding classified data.
2-3 Mobile devices security. Controls for mobile devices handling classified data, including disposal considerations.
2-4 Data and information protection. Protection controls applied per classification, covering data at rest, in transit and in use.
2-5 Cryptography. Aligned to the National Cryptographic Standards, with the strength level chosen on data sensitivity.
2-6 Secure data disposal. All five subcontrols map exclusively to the Dispose stage — this subdomain is the end of the lifecycle and nowhere else. Disposal methods defined per media type and classification, with evidence retained.
2-7 Cybersecurity for printers, scanners and copy machines. The subdomain most often missed entirely:
| Ref | Requirement | Applies at |
|---|---|---|
| 2-7-1 / 2-7-2 | Requirements defined, documented, approved — and implemented | Confidential+ |
| 2-7-3-1 | Temporary storage feature disabled on the device | Secret+ |
| 2-7-3-2 | Authentication enabled on centralised devices, required before use | Secret+ |
| 2-7-3-3 | Usage logs securely retained for not less than 12 months | Secret+ |
| 2-7-3-4 | CCTV logs enabled and protected for the areas around the devices | Secret+ |
| 2-7-3-5 | Cross-shredding devices used to dispose of documents | Secret+ |
| 2-7-4 | Implementation reviewed | Every 3 years (Public / Confidential) · Annually (Secret / Top Secret) |
The multifunction device is a genuinely under-assessed asset: it has a hard drive, it caches documents, it usually sits on a flat network segment, and it is rarely in the CMDB. Disabling temporary storage and enforcing pull-printing are inexpensive. Discovering three years of Secret documents cached on a leased device about to be returned is not.
Domain 3 — Third-Party and Cloud Computing Cybersecurity
3-1-1 Third-party cybersecurity. For data shared with outsourcing, managed service and consultancy providers:
- 3-1-1-1 Screening or vetting of third-party employees with access to the data (Secret+)
- 3-1-1-2 Contractual commitment to securely dispose of the organisation's data at contract end or termination, including providing evidence of disposal (Confidential+)
- 3-1-1-3 All data sharing operations documented, including the justification for each (Confidential+)
- 3-1-1-4 For transfers outside the Kingdom: verify the foreign host's capability to safeguard the data, obtain the Authorizing Official's approval, and comply with related laws (Confidential+)
- 3-1-1-5 Third parties must notify the organisation immediately of any incident affecting shared or created data (Confidential+)
- 3-1-1-6 Reclassify data to the least level needed to achieve the objective before sharing, using masking or scrambling (Confidential+)
3-1-2 Consultancy on national strategic projects. For consultancy services working on high-sensitivity strategic projects at national level, in addition to the above — vetting, NDAs with evidenced disposal, documented sharing, immediate incident notification and reclassification before sharing, plus three physical controls at Secret and Top Secret:
- 3-1-2-6 A dedicated closed room for consultancy staff, with organisation-owned devices provided to share and process data
- 3-1-2-7 An access control system allowing only authorised entry to that room
- 3-1-2-8 No devices, storage media or documents carried out of the room, and no other electronic devices carried in
This is a facilities and contracting requirement. Engaging a strategy consultancy on a Secret national project means providing a controlled room and organisation-owned hardware — scope and price it into the engagement before it starts.
Work it by lifecycle, not by domain
Appendix D of the DCC maps every control to the five lifecycle stages — Create, Store, Share, Use, Dispose. It is the most useful page in the document, because it converts a control list into process gates you can hand to the people who already run those processes.
Reading by domain gives you a control list. Reading by lifecycle gives you an implementation plan.
Get the downloadable checklist
The full checklist — a working spreadsheet with the four classification levels as columns, a lifecycle-stage tag per control, and state, owner, evidence and target date fields — is available on request. Contact us to receive a copy.
For the framework in depth, read NCA DCC: Data Cybersecurity Controls explained. For the wider family, see the NCA frameworks complete list, and for the personal-data overlay the PDPL implementation checklist.
Book a demo with the GRC Vantage team in Riyadh or Dammam.
See Compliance Management →
The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.
Related articles
A guide to NCA Data Cybersecurity Controls (DCC-1:2022) — four classification levels, 19 controls across the data lifecycle, and third-party sharing rules.
A guide to NCA Cloud Cybersecurity Controls (CCC-2:2024) — the CSP and CST control sets, four classification levels, and the data localisation change.
A free NCA CCC-2:2024 compliance checklist — the provider and tenant control sets, all four classification levels, and the evidence each subdomain needs.