NCA DCC: Data Cybersecurity Controls Explained

A guide to NCA Data Cybersecurity Controls (DCC-1:2022) — four classification levels, 19 controls across the data lifecycle, and third-party sharing rules.

GRC Vantage TeamGRC Vantage Team2026-08-2611 min read

The Data Cybersecurity Controls (DCC – 1: 2022) are the NCA's control set for protecting data across its entire lifecycle — and they are the NCA document most likely to surprise a security team, because they cover things a network-centric programme never touches. Printers. Copy machines. Cross-shredders. Locked rooms for consultants.

The DCC's organising insight is that data does not stay inside systems. It is created, stored, shared, used and disposed of, and at several of those stages it leaves the technology stack entirely. The controls follow it.

What the DCC is

The DCC is an extension to the Essential Cybersecurity Controls, developed after a study of national and international standards, laws and regulations, best practice and past incidents. Continuous ECC compliance is a prerequisite — the document states plainly that DCC compliance "cannot be achieved without achieving continuous compliance with ECC, where applicable."

ComponentCount
Main domains3
Subdomains11
Main controls19
Subcontrols47

Its three objectives are to raise the level of cybersecurity protecting national data, to support organisations' cybersecurity throughout the data lifecycle, and to raise awareness of handling data securely.

Scope: all data, physical and digital

The DCC applies to government organisations in the Kingdom — ministries, authorities, establishments and others, and their companies and entities — plus private sector organisations owning, operating or hosting Critical National Infrastructure. The NCA strongly encourages every other organisation to adopt them.

The data scope is the part to read twice. The controls apply to:

…all forms of physical and digital data, including structured data (such as databases, data tables) and unstructured data (such as documents and records).

The four classification levels

Every DCC control is marked applicable or not at each of four data classification levels, drawn from the regulatory tools issued by the Saudi Data and Artificial Intelligence Authority (SDAIA):

LevelEffect on control set
PublicSmallest applicable set — awareness and basic handling controls.
ConfidentialAdds handling, disposal and third-party sharing obligations.
SecretAdds vetting, printer hardening and physical segregation controls.
Top SecretFull applicable set.

This is the same four-tier scheme the Cloud Cybersecurity Controls use to tier their own levels, which makes classification the shared dependency across the NCA's data-facing control sets. An organisation that has not completed a defensible classification exercise cannot scope either document.

The DCC's structure table makes the tiering explicit: each control clause carries a row of four columns — Public, Confidential, Secret, Top Secret — with a tick where the control applies. Some controls apply at all four levels, some only at Secret and Top Secret.

The three domains

DomainSubdomains
1 — Cybersecurity Governance1-1 Periodical Cybersecurity Review and Audit · 1-2 Cybersecurity in Human Resources · 1-3 Cybersecurity Awareness and Training Program
2 — Cybersecurity Defense2-1 Identity and Access Management · 2-2 Information System and Information Processing Facilities Protection · 2-3 Mobile Devices Security · 2-4 Data and Information Protection · 2-5 Cryptography · 2-6 Secure Data Disposal · 2-7 Cybersecurity for Printers, Scanners and Copy Machines
3 — Third-Party and Cloud Computing Cybersecurity3-1 Third-Party Cybersecurity

Two of those subdomains have no equivalent anywhere else in the NCA family: Secure Data Disposal and Cybersecurity for Printers, Scanners and Copy Machines.

The data lifecycle mapping

Appendix D of the DCC maps every control and subcontrol to the five stages of the data lifecycle: Create, Store, Share, Use, Dispose. It is the most useful page in the document for anyone designing an implementation plan, because it converts a control list into a set of process gates.

The mapping also reveals the document's shape. Subdomain 2-6 (Secure Data Disposal) maps exclusively to Dispose — all five of its subcontrols sit at the end of the lifecycle and nowhere else. Subdomain 2-1 (Identity and Access Management) maps only to Share and Use. Awareness controls under 1-3 spread across every stage.

Reading the DCC by domain gives you a control list. Reading it by lifecycle stage gives you an implementation plan — because each stage maps to a business process that already exists, with an owner who already runs it.

Printers, scanners and copy machines

Subdomain 2-7 is where the DCC's physical-data scope becomes concrete. The requirements must be defined, documented and approved (2-7-1) and implemented (2-7-2) for Confidential data and above, and 2-7-3 sets out what they must cover — most items applying at Secret and Top Secret:

  • 2-7-3-1 — disabling the temporary storage feature on the device.
  • 2-7-3-2 — enabling authentication on centralised printers, scanners and copy machines, required before use.
  • 2-7-3-3 — securely retaining usage logs for not less than 12 months.
  • 2-7-3-4 — enabling and protecting CCTV logs monitoring the areas around centralised devices.
  • 2-7-3-5 — using cross-shredding devices to securely dispose of documents when no longer needed.

Control 2-7-4 then sets the review cadence, and it is one of the few places the NCA varies a frequency by classification: implementation must be reviewed at least every three years for Public and Confidential data, and at least annually for Secret and Top Secret.

The multifunction device is a genuinely under-assessed asset. It has a hard drive, it caches documents, it usually sits on a flat network segment, and it is frequently excluded from the CMDB. Disabling temporary storage and enforcing pull-printing authentication are inexpensive; discovering during an assessment that three years of Secret documents are cached on a leased device that is about to be returned is not.

Third-party data sharing

Subdomain 3-1 governs data shared with third parties — outsourcing, managed services and consultancy — and it is the most commercially significant part of the document.

General third-party controls (3-1-1)

  • 3-1-1-1 — screening or vetting third-party employees with access to the data (Secret, Top Secret).
  • 3-1-1-2contractual commitment by third parties to securely dispose of the organisation's data at the end of the contract or on termination, including providing evidence of that disposal.
  • 3-1-1-3documenting all data sharing operations, including the justification for each.
  • 3-1-1-4 — when transferring data outside the Kingdom, verifying the capability of the hosting organisation abroad to safeguard the data, obtaining the Authorizing Official's approval, and complying with related laws and regulations.
  • 3-1-1-5 — requiring third parties to notify the organisation immediately of any cybersecurity incident that may affect data shared or created.
  • 3-1-1-6reclassifying data to the least level needed to achieve the objective before sharing it, using data masking or scrambling.

Control 3-1-1-6 deserves attention because it inverts the usual instinct. The default is not "share the data securely" — it is "share less data". Masking and scrambling to the minimum classification that still meets the objective is a design requirement on every third-party data flow.

Consultancy on national strategic projects (3-1-2)

Control 3-1-2 covers consultancy services working on high-sensitivity strategic projects at the national level, and applies in addition to the ECC and DCC domains 1, 2 and 3. Alongside vetting (3-1-2-1), NDAs and evidenced disposal (3-1-2-2), documented sharing (3-1-2-3), immediate incident notification (3-1-2-4) and reclassification before sharing (3-1-2-5), it adds three physical controls that apply at Secret and Top Secret:

  • 3-1-2-6 — dedicating a closed room for consultancy employees to perform their work, and providing dedicated organisation-owned devices to share and process data.
  • 3-1-2-7 — activating an access control system to allow only authorised access to that room.
  • 3-1-2-8preventing devices, storage media and documents from being carried out of the closed room, and preventing the entry of any other electronic devices.

This is a facilities and contracting requirement, not a security-tooling one. Engaging a strategy consultancy on a Secret national project means providing a controlled room, organisation-owned hardware, and an enforced no-device policy — arrangements that have to be scoped and priced into the engagement before it starts.

How the NCA assesses compliance

The NCA evaluates DCC compliance through self-assessments by the organisation and/or external assessments, using the mechanisms it considers appropriate. Compliance is mandated under item 3 of article 10 of the NCA's mandate and Royal Decree No. 57231 dated 10/11/1439H. The NCA also publishes a DCC Assessment and Compliance Tool to structure the exercise.

A DCC readiness sequence

  1. Classify the data first using SDAIA's scheme — Public, Confidential, Secret, Top Secret. Without it there is no applicable control set, only a document.
  2. Extend the data inventory to physical and unstructured data. Documents, records and paper are in scope, and they are almost never in the existing asset register.
  3. Work the lifecycle, not the domain list. Use Appendix D to attach controls to Create, Store, Share, Use and Dispose, then hand each stage to the process owner who already runs it.
  4. Audit the multifunction devices. Temporary storage, authentication, 12-month log retention, CCTV coverage and cross-shredding are quick wins with real exposure behind them.
  5. Rewrite third-party data clauses. Evidenced disposal on termination, immediate incident notification, documented sharing with justification, and the Authorizing Official's approval for cross-border transfers all need to be in the contract, not the policy.
  6. Scope consultancy engagements for the closed-room controls before signing, where national strategic projects at Secret or above are involved.

How GRC Vantage supports DCC compliance

GRC Vantage's compliance module carries the DCC library with the four classification levels applied per control, so setting a data domain's classification produces exactly the applicable subcontrols rather than the whole document — and holds the same classification once, shared with your CCC scoping. Controls are tagged to their lifecycle stage from Appendix D, so an implementation plan can be built by stage and assigned to the process owner rather than to the security team by default.

Third-party data-sharing obligations under 3-1 run through the vendor workflow: each sharing arrangement records its justification, its classification after reclassification, the contractual disposal commitment and the evidence received against it, with cross-border transfers carrying the Authorizing Official's approval alongside the PDPL transfer basis. The platform runs inside the Kingdom, with teams in Riyadh and Dammam.

For the full family, see the NCA frameworks pillar guide. To scope a DCC programme, talk to our team.

Want to see this in the platform?

Book a demo with the GRC Vantage team in Riyadh or Dammam.

See Compliance Management

Frequently asked questions

What is the NCA DCC?

The Data Cybersecurity Controls (DCC – 1: 2022) are the NCA's minimum cybersecurity requirements for protecting data across its lifecycle. They comprise 3 main domains, 11 subdomains, 19 main controls and 47 subcontrols, extend the Essential Cybersecurity Controls, and apply differentially across four data classification levels.

Does the DCC apply to paper documents?

Yes. The controls apply to all forms of physical and digital data, including structured data such as databases and data tables and unstructured data such as documents and records. Subdomain 2-7 addresses printers, scanners and copy machines specifically, including cross-shredding for secure disposal.

What are the four DCC classification levels?

Public, Confidential, Secret and Top Secret, based on the regulatory tools issued by SDAIA. Each DCC control is marked as applicable or not at each level, so the classification of the data determines the size of the applicable control set.

What does the DCC require before sharing data with a third party?

Documented sharing with a justification (3-1-1-3), reclassification to the least level needed using masking or scrambling (3-1-1-6), a contractual commitment to securely dispose of the data at contract end with evidence provided (3-1-1-2), immediate incident notification (3-1-1-5), and — for Secret and Top Secret — screening of the third party's employees (3-1-1-1).

What does the DCC require for cross-border data transfers?

Under 3-1-1-4, the capability of the hosting organisation abroad to safeguard the data must be verified, the Authorizing Official's approval must be obtained, and related laws and regulations must be complied with. Where personal data is involved, the PDPL's own cross-border transfer conditions apply in addition.


Sources & References
Primary regulatory documents, international standards and guidance cited in this article
  • 1
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), Kingdom of Saudi Arabia, 2022
    Source for the control counts (3 domains, 11 subdomains, 19 controls, 47 subcontrols), the scope covering physical and digital, structured and unstructured data, the four SDAIA classification levels, the printer and copier subcontrols 2-7-3-1 to 2-7-3-5 and review cadence 2-7-4, third-party controls 3-1-1-1 to 3-1-1-6, consultancy closed-room controls 3-1-2-6 to 3-1-2-8, and the Appendix D data lifecycle mapping.
  • 2
    Primary Regulation — NCA
    National Cybersecurity Authority (NCA), 2022
    Published 18/09/2022, last updated 15/05/2025. Hosts the main document and the DCC Assessment and Compliance Tool (V1.0).
  • 3
    Primary Regulation — SDAIA
    Saudi Data and Artificial Intelligence Authority (SDAIA), 2022
    Source of the four-level classification scheme — Public, Confidential, Secret, Top Secret — that the DCC uses to tier its controls.
GRC Vantage Team
GRC Vantage Team
Saudi GRC Practitioners

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.