Buying from a certified cloud vendor feels like it should settle a compliance question. Under Saudi Arabia's cloud controls it settles roughly half of one, because the framework assigns duties to the customer as deliberately as it does to the platform. Knowing which half is yours, and in what order to work through it, is most of the value here.
NCA CCC: the Cloud Cybersecurity Controls published by Saudi Arabia's National Cybersecurity Authority, which apply to cloud service providers and to the organisations that use them. The structural point that catches people is that both sides carry obligations, so choosing a compliant provider discharges only half of your own.
Accuracy note. The NCA maintains several control frameworks and revises them. This explains the structure and what it asks of infrastructure, which is stable, and does not restate control counts or classification labels that may have moved. Verify the current edition and your scope against the NCA's published documents. This is not legal advice.
The Two Roles
The framework divides the world into cloud service providers and cloud service tenants, and assigns controls to each. A third set is shared, meaning both parties have something to do and the boundary must be agreed rather than assumed.
That division is the most useful thing about the framework and the most commonly misread. A provider holding a certification satisfies the provider-side controls. It does not configure your access policies, classify your data, or write your incident response plan.
| Typically the provider's | Typically yours |
|---|---|
| Physical and environmental security | Data classification before anything is uploaded |
| Hypervisor and platform integrity | Identity, access approval and periodic review |
| Tenant isolation | Encryption configuration, and key custody decisions |
| Platform-level logging capability | Log retention, review, and acting on alerts |
| Provider personnel screening | Your own personnel and their privileges |
| Facility resilience | Backup, tested restoration and continuity planning |
| Providing exit and export mechanisms | Having an exit plan and proving it works |
Get the shared column written into the contract. A control that both parties assume the other performs is the failure mode this framework exists to prevent.
Classification Drives Everything
The framework is tiered: which controls apply depends on the classification of the data and the criticality of the service. That has an important practical consequence for sequencing.
Classify first, then shortlist platforms. Doing it the other way round produces a migration that has to be unwound when the classification lands higher than assumed, and that is an expensive discovery to make late.
Classification also determines whether a residency obligation exists, which is a different question from the control questions and narrows the options far more sharply. Our guide to Saudi PDPL and data residency covers how to make that determination.
It Builds on the Baseline
CCC assumes the Essential Cybersecurity Controls underneath it. It is an overlay for cloud, not a standalone regime, so an organisation in scope for CCC is normally in scope for ECC as well and possibly for the critical systems controls too.
Build one control set mapped to all applicable frameworks rather than running parallel programmes. The overlap is large, and the cost of three separate implementations is mostly duplicated evidence. Our explainer on NCA Essential Cybersecurity Controls covers the baseline and the rest of the family.
What to Ask a Provider
In this order, because the early answers change the shortlist:
Where is data stored, and where is it processed? These differ. A management plane in another country processes data even when storage is local.
Where do backups and replicas live? The most commonly overlooked location question.
Where is support delivered from, and what can support see? An engineer with production access is a data flow.
Which subprocessors are involved, and how are changes notified? Supply chain is explicitly in scope.
What can be evidenced rather than asserted? Certifications and audit reports are how a tenant discharges due diligence without auditing a datacenter.
What does exit look like? Export format, timeframe, and confirmation that the data comes back in a usable state.
The Controls Infrastructure Has to Satisfy
Tenant-side, the technical obligations reduce to a familiar list, and what the framework adds is the requirement to evidence each one on demand.
Identity with multi-factor authentication on administrative paths, privileged access approved before grant and reviewed on a schedule. Encryption in transit and at rest, with a documented key management practice and a decision recorded about who holds the keys. Security event logging, centralised, protected from tampering, retained for a defined period, and reviewed by a named function. Backup with tested restoration and documented recovery objectives. Vulnerability management on a defined cycle with an exception register. Change control with approvals and rollback.
None of this is unusual. What separates organisations that pass from organisations that struggle is whether the evidence was produced as the control operated or reconstructed afterwards.
Where MassiveGRID Fits
On the provider side of that table, MassiveGRID runs an ISO 27001 certified control environment with SOC 2 Type II audit coverage and ISO 27017 cloud security alignment, which is what shortens tenant due diligence. The platform provides encryption in transit and at rest, role-based access with multi-factor authentication, audit logging, and resilience through Proxmox high-availability clustering with automatic failover over Ceph storage replicating every block three times across independent NVMe drives. Log review and monitoring are available as SOC and NOC services where you cannot staff them internally.
On placement, MassiveGRID deploys into partner facilities operated by Equinix, Digital Realty, Sparkle and NTT, a published footprint of more than 700 datacenters across 85 metros, 30 countries and six continents, and infrastructure can be ordered in any of them. Saudi Arabia is not among the metros currently listed on the datacenter page, and partner footprints change, so where a classification requires in-Kingdom placement, confirm current availability directly and treat colocation or a private cloud in a local facility as the route.
What no provider supplies is the tenant column: your classification, your access decisions, your evidence. See the NCA CCC alignment, or NCA CSCC if your systems are designated critical.