The Data Cybersecurity Controls (DCC-1:2022) are the National Cybersecurity Authority’s extension to the Essential Cybersecurity Controls for one specific asset: data. Where the ECC sets the baseline for an entity’s whole cybersecurity program, the DCC adds 19 controls and 47 sub-controls that apply to structured and unstructured data across its lifecycle, and it does something the ECC does not do: it scales each requirement to the data’s classification level. A control that is optional for public data can be mandatory for confidential data and stricter again for secret and top secret. This guide explains the structure, who is in scope, how the classification-level mechanism works, and how the controls map back to the ECC you already report against.
Everything below is read from NCA’s own DCC-1:2022 document, not from a summary of it.

Who the Data Cybersecurity Controls apply to
The scope statement is the same as the ECC’s. The DCC apply to government organizations in the Kingdom of Saudi Arabia — ministries, authorities, establishments and others — and their companies and entities, plus private sector organizations owning, operating or hosting Critical National Infrastructures. NCA “strongly encourages” all other organizations in the Kingdom to use the controls as best practice, which is the same encouragement wording the ECC uses, and it carries the same practical weight: regulators, tenders and large customers in the Kingdom increasingly ask for it.
Two scope points are easy to miss. The controls apply to all forms of physical and digital data, which the document spells out as structured data such as databases and data tables, and unstructured data such as documents and records. Paper is in scope. And the compliance basis is explicit: under item 3 of Article 10 of NCA’s mandate and Royal Decree 57231, organizations within scope must ensure continuous compliance, which the DCC says “cannot be achieved without achieving continuous compliance with the Essential Cybersecurity Controls”. The DCC is not a substitute for the ECC. It sits on top of it.
The structure: 3 domains, 11 subdomains, 19 controls
The DCC borrows three of the ECC’s four main domains and adds subdomains only where data needs something the ECC does not already say. There is no resilience domain, because backup and continuity are already covered in the ECC. The subdomains are:
| Domain | Subdomain | What it adds for data |
|---|---|---|
| 1. Cybersecurity Governance | 1-1 Periodical Cybersecurity Review and Audit | Review frequencies keyed to classification level |
| 1-2 Cybersecurity in Human Resources | Vetting for data-handling roles; a signed personal-cloud and social-media pledge | |
| 1-3 Cybersecurity Awareness and Training Program | Seven data-protection topics the awareness program must cover | |
| 2. Cybersecurity Defense | 2-1 Identity and Access Management | Approved privilege lists, Saudi-national restriction for secret data, PAM, review cycles |
| 2-2 Information System and Information Processing Facilities Protection | Patch and hardening timescales; disabling screen capture | |
| 2-3 Mobile Devices Security | MDM with remote wipe; BYOD prohibited for secret and top secret | |
| 2-4 Data and Information Protection | Watermarking, DLP and rights management, no production data in test, brand protection | |
| 2-5 Cryptography | NCS-1:2020 advanced level for secret and above, moderate for confidential | |
| 2-6 Secure Data Disposal | Identified tools, verified disposal, secure erasure, disposal records | |
| 2-7 Cybersecurity for Printers, Scanners and Copy Machines | Authentication, 12-month usage logs, CCTV, cross-shredding | |
| 3. Third-Party and Cloud Computing Cybersecurity | 3-1 Third-Party Cybersecurity | Contractual disposal, data-sharing records, transfer approval, closed rooms for consultants |
Appendix A of the DCC describes the relationship to the ECC precisely: nine ECC subdomains had data controls added to them, twenty ECC subdomains had nothing added, and two subdomains are new — Secure Data Disposal (2-6) and Cybersecurity for Printers, Scanners and Copy Machines (2-7). Those two are where most organizations find their first gaps, because neither has an ECC equivalent to have built on.
How the Data Cybersecurity Controls scale by classification level
This is the mechanism that makes the DCC different from every other NCA control set. Every control table carries four columns — Public, Confidential, Secret and Top Secret — and each sub-control is either ticked for a level or not, or carries a different frequency per level. The organization’s data classification decides which column it reads. Some examples from the document:
| Control | Public | Confidential | Secret / Top Secret |
|---|---|---|---|
| 1-1-1 Internal review of DCC implementation | At least annually | At least annually | At least annually |
| 1-1-2 Independent review and audit | At least every 2 years | At least every 2 years | At least annually |
| 2-1-3 Review of approved privilege lists | At least annually | At least annually | At least every 3 months |
| 2-2-1-1 Security patches from time of announcement | At least every month | At least every month | Immediately |
| 2-2-1-2 Configuration and hardening review | At least annually | At least annually | At least every 6 months |
| 2-3-1-2 BYOD under MDM with remote wipe | Required | Required | BYOD prohibited |
| 2-5-1 Cryptography level under NCS-1:2020 | — | Moderate level | Advanced level |
| 2-6-2 Review of secure disposal | At least annually | At least annually | At least every 6 months |
| 2-7-4 Review of printer/scanner/copier requirements | At least every 3 years | At least every 3 years | At least annually |
The practical consequence is that the DCC cannot be implemented without a working data classification scheme. Control 2-7-2 of the ECC already requires data to be protected “based on its classification level”; the DCC turns that into a set of specific obligations per level. If your classification is nominal — a policy that exists but data that was never actually labelled — the first DCC project is classification, not controls.
The Data Cybersecurity Controls most organizations have not met
Reading the 47 sub-controls of the Data Cybersecurity Controls against typical ECC-compliant environments, six stand out as new work rather than evidence of existing work.
Saudi-national privilege lists for secret data (2-1-1-1)
For secret and top secret data, access must be restricted to the minimum number of personnel “based on lists of privileges limited to Saudi-national employees unless exempted by the Authorizing Official”, with the lists approved by the Authorizing Official — the head of the organization or a delegate. This is an organizational control with HR consequences, and it needs a documented exemption route.
The personal-cloud pledge (1-2-1-2)
For confidential data and above, personnel must sign an agreement “pledging to not use social media, communication applications or personal cloud storage to create, store or share the organization’s data”, except for secure communication applications approved by the relevant authorities. Most acceptable-use policies say something similar; the DCC wants a signed pledge, per person, as evidence.
Watermarking to the user or device (2-4-1-1)
Secret and top secret documents must carry a watermark “when creating, storing, printing, on the screen and on each copy so that the symbol can be traced to the user or device level”. A static “SECRET” banner does not meet this; the watermark has to identify who or what produced the copy.
No production data outside production (2-4-1-3)
For confidential data and above, using data in any environment other than production is prohibited “except after conducting a risk assessment and applying controls to protect that data, such as data masking or data scrambling techniques”. Test and development environments loaded with live extracts are a common finding.
Printers, scanners and copiers (2-7)
For secret and top secret data: disable temporary storage on the devices, require authentication before use on centralized machines, retain usage logs for not less than 12 months, enable and protect CCTV covering the device areas, and use cross-shredders for disposal. Confidential data needs the requirements defined, documented, approved and implemented (2-7-1, 2-7-2) but not the five secret-level sub-controls.
Consultancy closed rooms (3-1-2)
Consultancy services working on “high-sensitivity strategic projects at the national level” with secret or top secret data must work in a dedicated closed room with access control, on organization-owned devices, with devices, storage media and documents prevented from leaving and other electronic devices prevented from entering. This is a physical requirement that has to be planned before the engagement starts.
Mapping the Data Cybersecurity Controls to the ECC
Each DCC control opens with a reference to the ECC control it extends — “in addition to the subcontrols in ECC control 2-2-3”, for example. The DCC was written against ECC-1:2018, but the governance and defense subdomains kept their numbering in ECC 2-2024, so every reference still resolves:
| DCC subdomain | Extends ECC control | ECC 2-2024 subdomain |
|---|---|---|
| 1-1 Review and audit | 1-8-1, 1-8-2 | 1-8 Periodical Cybersecurity Review and Audit |
| 1-2 Human resources | 1-9-3 | 1-9 Cybersecurity in Human Resources |
| 1-3 Awareness | 1-10-3 | 1-10 Cybersecurity Awareness and Training Program |
| 2-1 Identity and access | 2-2-3, 2-2-3-5 | 2-2 Identity and Access Management |
| 2-2 Systems protection | 2-3-3 | 2-3 Information System and Processing Facilities Protection |
| 2-3 Mobile devices | 2-6-3 | 2-6 Mobile Devices Security |
| 2-4 Data protection | 2-7-3 | 2-7 Data and Information Protection |
| 2-5 Cryptography | 2-8-3 | 2-8 Cryptography |
| 2-6 Secure disposal | New | — |
| 2-7 Printers, scanners, copiers | New | — |
| 3-1 Third parties | Subdomain 4-1 | 4-1 Third-Party Cybersecurity |
The mapping matters for evidence. If your ECC self-assessment already holds evidence for 2-2-3 (identity and access requirements), the DCC asks for the same control family plus the classification-specific additions. Build the DCC register as a child of the ECC register rather than a separate document, and the two assessments stay consistent. Our guide to the ECC 2-2024 domains covers the parent structure, and the seven NCA control sets shows where the DCC sits among the CCC, OTCC, TCC and the rest.
How compliance is assessed
The DCC says NCA “evaluates organizations’ compliance with the DCC through multiple means such as self-assessments by the organizations, and/or external assessments, in accordance with the mechanisms deemed appropriate by NCA”. In practice that means the same route as the ECC: a self-assessment submitted through NCA’s compliance platform, reviewed by NCA, with feedback where needed. The process is described in our guide to the NCA ECC self-assessment.
One thing the Data Cybersecurity Controls do not do is set a maturity scale. Unlike SAMA’s cyber security framework, which scores levels 0 to 5, NCA control sets are compliance tests — each applicable control is implemented, partially implemented, not implemented or not applicable. Partial credit does not accumulate into a score you can present as progress.
Frequently asked questions
Is DCC-1:2022 still the current edition?
Yes. NCA lists DCC-1:2022 on its controls page and has not issued a second edition. The ECC it extends was reissued as ECC 2-2024, and the DCC’s control references still resolve to the same subdomain numbers.
Do the Data Cybersecurity Controls apply to private companies?
Directly, only to private sector organizations owning, operating or hosting Critical National Infrastructure. NCA encourages everyone else to adopt them, and regulated sectors and government suppliers are increasingly asked to evidence them contractually.
How many controls are there?
Three main domains, eleven subdomains, 19 main controls and 47 sub-controls, each keyed to the four data classification levels.
Which classification scheme do the levels refer to?
Public, Confidential, Secret and Top Secret are the four columns in every DCC control table. Your organization’s own classification policy decides which data sits at which level; the DCC then tells you what each level requires.
Can we comply with the DCC without the ECC?
No. The DCC states that continuous compliance with it cannot be achieved without continuous compliance with the ECC, and every DCC control extends an ECC control rather than replacing it.
Where this leaves you
Treat the Data Cybersecurity Controls as a classification-driven overlay on the ECC. Confirm data is actually labelled, read the column that applies, and start with the two subdomains that have no ECC parent — secure disposal and print devices — because that is where the evidence usually does not exist yet. Then work through the consultancy, watermarking and non-production-data controls for anything confidential or above.
References
- Data Cybersecurity Controls (DCC-1:2022) — NCA’s controls page for the DCC, with the English PDF.
- Essential Cybersecurity Controls (ECC-2:2024) — The parent control set the DCC extends.
More on NCA compliance
- The Data Cybersecurity Controls — you are here
- NCA ECC: a cybersecurity compliance guide for Saudi firms
- ECC 2-2024: all four domains
- The seven NCA control sets
- NCA ECC implementation in six steps
Policies, registers and the classification-keyed control matrix for the ECC and its extensions are in the NCA Cybersecurity Toolkit, or start with the free templates.