Frequently Asked Questions
Find answers to your questions about cybersecurity and the CISO Consulting platform
Cloud Security 56
NCA Cloud Cybersecurity Controls (CCC) require Saudi government entities to: obtain NCA approval before adopting cloud services; use only NCA-approved cloud service providers; implement a shared responsibility model; maintain data sovereignty for classified data; apply encryption for data at rest and in transit; implement cloud access security and monitoring.
Financial institutions in Saudi Arabia operating in the cloud must satisfy overlapping requirements from both SAMA CSF and NCA ECC, making cloud security governance a multi-layered compliance challenge. Under NCA ECC Article 2-10 (Cloud Computing Security), entities must conduct a formal cloud risk assessment before migration, classify data according to sensitivity, and ensure that critical and sensitive data is hosted within the Kingdom unless explicit regulatory approval is granted for cross-border transfer. SAMA reinforces this through its Cloud Computing Framework, which mandates that banks obtain prior SAMA approval before migrating core banking workloads to public cloud environments. Shared responsibility models must be clearly documented — defining what the cloud service provider (CSP) secures versus what the institution remains responsible for. Key technical controls required include encryption at rest and in transit (AES-256 minimum), multi-factor authentication for cloud console access, continuous cloud posture monitoring (CSPM tooling), and network segmentation. Incident response plans must be updated to include cloud-specific scenarios. From a PDPL perspective, cross-border data transfers require adequate safeguards — either contractual clauses or confirmation that the destination country offers equivalent protection. Institutions should also maintain a Cloud Asset Register, conduct annual cloud penetration tests, and perform configuration audits quarterly. Our platform maps your cloud controls against SAMA CSF Domain 3.4 and NCA ECC requirements, providing a unified compliance dashboard.
Cloud adoption in Saudi financial institutions is governed by a layered regulatory framework. Here is what you must technically implement to remain compliant: NCA ECC (Art. 2-3 & Cloud Controls Sub-domain): Data classified as 'National' or 'Sensitive' must reside within KSA borders or in approved sovereign cloud environments. You must conduct a formal cloud risk assessment before migration and maintain a cloud asset register. SAMA CSF Cloud Requirements: Before adopting any cloud service, regulated entities must perform due diligence on the Cloud Service Provider (CSP), verify their compliance with recognized standards (ISO 27001, SOC 2 Type II, CSA STAR), and ensure contractual right-to-audit provisions. Mandatory Technical Controls include: (1) Encryption at rest and in transit using AES-256 and TLS 1.2+ minimum; (2) Identity and Access Management with MFA enforced for all privileged and administrative accounts; (3) Cloud Security Posture Management (CSPM) tools to continuously detect misconfigurations; (4) Network segmentation and micro-segmentation within cloud environments; (5) Logging and SIEM integration — all cloud activity logs must feed into your SOC with minimum 12-month retention; (6) Data Loss Prevention (DLP) controls to prevent unauthorized data exfiltration; (7) Vulnerability management cadence for cloud workloads. Practical note: Many Saudi banks and fintechs use hyperscalers (AWS, Azure, Google Cloud) through their KSA regions. While this satisfies data residency, you remain fully responsible for the 'shared responsibility model' gaps. Engage your vCISO or cloud security team to map your controls against both SAMA CSF and NCA ECC before go-live.
When Saudi banks migrate workloads to public cloud environments, SAMA CSF Section 3.3 (Technology Security) mandates a comprehensive cloud security governance framework. Key requirements include: (1) Cloud Risk Assessment — Conduct a formal risk assessment prior to migration, classifying data sensitivity and evaluating provider controls per SAMA CSF Control 3.3.7. (2) Contractual Safeguards — Cloud service agreements must include data residency clauses confirming storage within the Kingdom or in jurisdictions approved by SAMA, right-to-audit provisions, and clear incident notification SLAs. (3) Shared Responsibility Model — Banks must formally document which controls are managed by the CSP versus the bank itself, covering identity management, encryption, and logging. (4) Encryption Standards — All data at rest and in transit must be encrypted using FIPS 140-2 validated algorithms; key management must remain under the bank's control. (5) Continuous Monitoring — SIEM integration with cloud-native logs (e.g., AWS CloudTrail, Azure Monitor) is required to satisfy SAMA CSF's logging and monitoring controls. (6) Exit Strategy — A documented cloud exit plan must exist to ensure operational resilience. NCA ECC Article 7-2 additionally requires that critical national infrastructure workloads avoid public cloud unless specific security criteria are met. Fintechs licensed under SAMA should also align with the SAMA Open Banking Framework's cloud guidance. Practically, banks should appoint a dedicated Cloud Security Officer, establish a Cloud Centre of Excellence, and perform quarterly cloud security posture assessments using tools like CSPM platforms.
When Saudi banks migrate workloads to public cloud environments, SAMA CSF requires a structured cloud security governance approach across several control domains.
Key Requirements:
1. Cloud Risk Assessment (SAMA CSF Control 3.3.1): Before any migration, conduct a formal cloud risk assessment covering data classification, residency requirements, and shared responsibility model gaps. Sensitive customer data (e.g., PII, financial records) must be evaluated for suitability in cloud environments.
2. Data Residency & Sovereignty: SAMA and NCA both require that critical financial data remain within the Kingdom unless explicit regulatory approval is obtained. Validate that your cloud provider offers Saudi or GCC-region data centers with contractual data residency guarantees.
3. Identity & Access Management (SAMA CSF Control 3.4.2): Enforce privileged access management (PAM), multi-factor authentication (MFA), and zero-trust principles for all cloud console access. Disable default service accounts and enforce least-privilege policies.
4. Encryption Standards: All data at rest and in transit must use strong encryption (AES-256 / TLS 1.2+). Maintain customer-managed encryption keys (CMEK) where possible to retain cryptographic control.
5. Continuous Monitoring & SIEM Integration: Cloud-native logs (e.g., AWS CloudTrail, Azure Monitor) must feed into your Security Operations Center (SOC) and SIEM. SAMA CSF Control 3.6.1 mandates continuous monitoring of security events.
6. Third-Party Cloud Provider Assessment: Treat your cloud provider as a critical third party. Review their ISO 27001, CSA STAR, and SOC 2 Type II certifications annually.
Practical Tip: Use a Cloud Security Posture Management (CSPM) tool to automate compliance checks against SAMA CSF and NCA ECC controls continuously.
Before migrating any workload to public cloud, Saudi banks must satisfy a layered set of regulatory and security requirements spanning SAMA CSF and NCA ECC.
SAMA CSF Requirements: Per SAMA CSF Control 3.3 (Technology Risk), banks must conduct a formal Cloud Risk Assessment that evaluates data classification, sovereignty, and residency obligations. Sensitive and critical data — especially customer financial records — must remain within the Kingdom unless explicit regulatory approval is obtained. A Cloud Governance Policy is mandatory, covering provider due diligence, contractual security obligations, and exit strategies.
NCA ECC Requirements: Under NCA ECC Domain 2.7 (Cloud Computing Security), organizations must ensure CSPs (Cloud Service Providers) comply with NCA-approved standards, maintain data within Saudi borders for critical systems, and implement continuous monitoring. Shared responsibility matrices must be formally documented and reviewed annually.
Practical Implementation Steps:
- Classify all workloads using a data classification framework aligned with both SAMA and PDPL sensitivity levels.
- Conduct a Cloud Security Assessment (CSA STAR or ISO 27017-aligned) of the chosen provider.
- Implement CASB (Cloud Access Security Broker) solutions for visibility and policy enforcement.
- Establish Identity and Access Management (IAM) controls with MFA and privileged access management in the cloud environment.
- Define logging, monitoring, and incident response playbooks specific to cloud infrastructure.
- Include cloud security clauses in contracts — SLAs must reference RTO/RPO aligned with SAMA BCM requirements.
Engaging a vCISO familiar with both SAMA CSF and NCA ECC during cloud migration significantly reduces compliance gaps and accelerates regulatory approval timelines.
Before migrating critical workloads to the cloud, Saudi banks must satisfy a layered set of regulatory and technical requirements. Under SAMA CSF Domain 4 (Technology Security), banks must conduct a formal cloud risk assessment covering data classification, residency, and sovereignty — ensuring that data classified as sensitive or critical remains within the Kingdom unless explicit regulatory approval is obtained. NCA ECC Article 3-2 mandates that cloud service providers (CSPs) used by financial entities must be evaluated against NCA's Cloud Cybersecurity Controls (CCC), and contracts must include binding security SLAs, audit rights, and incident notification clauses. Practically, banks should: (1) classify workloads using a documented data classification policy aligned with PDPL personal data categories; (2) perform a vendor due diligence assessment of the CSP covering ISO 27001, SOC 2 Type II, and CSA STAR certifications; (3) implement identity federation, privileged access management (PAM), and encryption at rest and in transit (TLS 1.2+ and AES-256 minimum); (4) establish a shared responsibility matrix clearly delineating security ownership between the bank and CSP; (5) ensure logging, monitoring, and SIEM integration for cloud-native events per SAMA CSF Control 3.3.6. SAMA also expects that cloud adoption be reviewed by the bank's CISO and Board Risk Committee before go-live. Failure to comply can trigger supervisory action, including suspension of cloud migration plans.
Saudi banks migrating to public cloud must satisfy overlapping requirements under SAMA CSF Domain 4 (Technology Security) and NCA ECC Article 3-4 (Cloud Computing Security). Key obligations include:
1. Pre-Migration Risk Assessment: Per SAMA CSF Control 4.3.1, conduct a formal cloud risk assessment covering data classification, residency, and sovereignty. Sensitive financial and customer data must be evaluated before any workload is moved.
2. Data Residency: NCA ECC and SAMA guidance strongly favour in-Kingdom or SAMA-approved data hosting. Confirm your Cloud Service Provider (CSP) operates a certified Saudi data centre or an approved region.
3. Shared Responsibility Model: Clearly document which security controls are owned by the bank versus the CSP. SAMA CSF Control 3.3.5 requires formal agreements defining cybersecurity responsibilities.
4. Identity & Access Management: Enforce Multi-Factor Authentication (MFA) for all privileged cloud access. SAMA CSF Control 4.2.6 mandates strict privileged access management aligned with least-privilege principles.
5. Continuous Monitoring & SIEM Integration: Cloud audit logs (e.g., AWS CloudTrail, Azure Monitor) must feed into your Security Operations Centre (SOC) per NCA ECC Control 2-15.
6. Encryption: All data at rest and in transit must be encrypted using FIPS 140-2 validated algorithms. Encryption key management must remain under the bank's control, not delegated solely to the CSP.
7. Exit Strategy: SAMA requires documented cloud exit and portability plans to avoid vendor lock-in that could threaten operational resilience.
Engage your vCISO team early in the cloud strategy phase to build a compliance-by-design architecture rather than retrofitting controls post-migration.
Before migrating critical workloads, Saudi banks must satisfy requirements across both SAMA CSF and NCA ECC. Under SAMA CSF Domain 4 (Technology Security), institutions must conduct a formal cloud risk assessment that evaluates data sovereignty, residency obligations, and the shared responsibility model with the Cloud Service Provider (CSP). Critically, SAMA CSF Control 4.4 requires that sensitive customer and financial data be stored within the Kingdom of Saudi Arabia unless explicit regulatory approval is obtained.
NCA ECC-1:2018, Article 3-2 (Cloud Computing Security), mandates that organizations classify workloads by criticality prior to migration, ensuring only appropriately secured environments host Tier-1 systems. Banks must also ensure CSPs hold recognized certifications such as ISO 27001 and CSA STAR, and that contractual agreements include the right to audit, incident notification SLAs (within 24 hours per SAMA guidance), and clear exit strategies.
From a practical standpoint, compliance teams should:
- Complete a Cloud Security Risk Assessment aligned with SAMA CSF Domain 4.
- Obtain SAMA's no-objection or approval for outsourcing arrangements involving critical systems.
- Map CSP controls to NCA ECC Article 3-2 requirements and document gaps.
- Implement CSPM (Cloud Security Posture Management) tools for continuous compliance monitoring.
- Establish a data classification policy under PDPL to ensure personal data processed in the cloud meets localization and protection standards.
Failure to address these requirements before migration exposes institutions to regulatory sanctions and heightened operational risk.
Migrating core banking workloads to the cloud in Saudi Arabia requires satisfying a layered set of regulatory obligations before go-live.
SAMA CSF Requirements: Under SAMA CSF Domain 4 (Technology Security), institutions must conduct a formal Cloud Risk Assessment covering data classification, residency, shared-responsibility boundaries, and exit strategy. SAMA CSF Control 4.3 requires that cloud service providers (CSPs) undergo due-diligence reviews equivalent to third-party risk assessments, including review of SOC 2 Type II or ISO 27001 certifications. Data classified as 'Confidential' or 'Restricted' must remain within Saudi Arabia or approved jurisdictions unless explicit regulatory approval is obtained.
NCA ECC Requirements: NCA ECC-1:2018 Article 3-15 mandates that entities using cloud services must ensure contractual clauses covering data sovereignty, audit rights, and incident notification within 24 hours. CSPs must be evaluated against NCA's Cloud Cybersecurity Controls (CCC) framework, which complements ECC for government-adjacent financial entities.
Practical Steps:
- Complete a Cloud Readiness Assessment mapping workloads by sensitivity tier.
- Validate CSP compliance with NCA CCC and obtain SAMA's written non-objection for critical system migration.
- Establish a Cloud Security Posture Management (CSPM) tool to provide continuous control monitoring.
- Define and test a cloud-specific incident response runbook integrated with your SAMA-required IR plan.
- Ensure encryption key management remains under the institution's control (Bring Your Own Key — BYOK).
Financial institutions that skip the pre-migration approval step frequently face SAMA examination findings, making upfront regulatory engagement essential.
Cloud adoption in Saudi banking is growing, but it comes with strict regulatory conditions. Before migrating any workload, financial institutions must satisfy requirements across SAMA CSF Domain 3 (IT Operations & Resilience), NCA ECC-1:2018 controls, and SAMA's Cloud Computing Guidelines.
1. Regulatory Pre-Approval SAMA requires formal notification and, for material systems, prior approval before cloud migration. Define what constitutes 'material' based on SAMA's outsourcing framework — typically core banking, payment systems, and customer data platforms.
2. Data Residency Sensitive financial and personal data must reside within Saudi Arabia unless SAMA grants explicit cross-border approval. This aligns with PDPL Article 29 on cross-border data transfers and NCA data localization guidelines.
3. Cloud Provider Assessment Only use Cloud Service Providers (CSPs) that meet NCA's Cloud Cybersecurity Controls (CCC-1:2020). Confirm the CSP holds relevant certifications (ISO 27001, CSA STAR) and has passed NCA assessment where required.
4. Shared Responsibility Model Document clearly which security controls the bank owns versus the CSP. SAMA examiners expect an explicit shared responsibility matrix covering identity management, encryption, logging, and incident response.
5. Encryption & Key Management Data at rest and in transit must be encrypted. Critically, encryption keys should remain under the bank's control — avoid CSP-managed key scenarios for regulated data.
6. Exit Strategy SAMA Cloud Guidelines mandate a documented exit/portability plan to avoid vendor lock-in and ensure operational continuity.
Our platform maps your cloud architecture controls directly to SAMA CSF and NCA CCC requirements, giving you a real-time compliance posture.
Cloud adoption in Saudi financial institutions is governed by a layered regulatory framework combining SAMA CSF, NCA ECC, and SAMA's Cloud Computing Guidance. Compliance requires addressing the following key areas:
Regulatory Pre-Approval:
- SAMA requires prior approval before migrating any material systems or customer data to the cloud. Submit a Cloud Risk Assessment and a Third-Party Outsourcing Notification per SAMA CSF Control 3.3.5 and the Outsourcing Risk Management Guidelines.
- NCA ECC (Article 3-2) mandates that cloud services used by critical national infrastructure must be evaluated against national security considerations.
Data Residency:
- Customer financial data and personally identifiable information (PII) must remain within the Kingdom of Saudi Arabia, consistent with PDPL Article 29 and SAMA's data localization directives. Confirm that your cloud provider offers a certified KSA region (e.g., AWS, Azure, Google Cloud all have local regions).
Shared Responsibility Model:
- Define and document the security responsibilities split between your institution and the cloud service provider (CSP). Map CSP controls to your SAMA CSF and ISO 27001 control requirements.
Key Technical Controls:
- Encryption at rest and in transit using approved cryptographic standards
- Identity and Access Management (IAM) with least-privilege enforcement and MFA
- Cloud Security Posture Management (CSPM) tools for continuous compliance monitoring
- Log centralization and SIEM integration for threat detection
Ongoing Governance:
- Conduct annual cloud security assessments and maintain a Cloud Asset Inventory
- Include cloud environments in your penetration testing scope
- Establish exit strategy documentation to avoid vendor lock-in risks, as recommended by SAMA outsourcing guidelines
Saudi banks must treat cloud service providers (CSPs) as critical third parties under SAMA CSF Domain 4 (Third-Party Management) and NCA ECC-1:2018 Article 3-4. Here is a practical framework:
1. Pre-Onboarding Due Diligence Conduct a Cloud Security Risk Assessment before signing any contract. Verify the CSP holds recognized certifications (ISO 27001, SOC 2 Type II, CSA STAR). Per SAMA CSF Control 3.3.7, all outsourcing arrangements must be approved by senior management.
2. Contractual Controls Ensure contracts explicitly address data residency (data must remain within KSA unless SAMA pre-approves offshore storage), incident notification SLAs (typically within 24 hours per SAMA CSF 3.3.14), right-to-audit clauses, and exit/transition plans.
3. Ongoing Monitoring Conduct annual cloud security assessments and continuous control monitoring. NCA ECC Article 3-4-2 requires periodic reviews of third-party compliance. Use automated Cloud Security Posture Management (CSPM) tools to detect misconfigurations in real time.
4. Data Classification Alignment Map data stored or processed by the CSP against your PDPL classification tiers and SAMA's data sensitivity categories. Prohibit storage of Tier 1 sensitive customer data on non-approved international platforms.
5. Incident Response Integration Incorporate the CSP into your Incident Response Plan and conduct joint tabletop exercises annually.
Failure to comply can result in SAMA supervisory action and NCA penalties. Engaging a vCISO with cloud GRC expertise can accelerate framework implementation significantly.
Before migrating any workloads to public cloud, Saudi banks must satisfy several regulatory and security requirements. Under SAMA CSF Control 3.3.6, financial institutions must conduct a formal cloud risk assessment that evaluates data classification, residency requirements, and third-party provider controls. Data classified as 'Confidential' or 'Restricted' must generally remain within the Kingdom unless explicit regulatory approval is obtained.
From the NCA ECC perspective, Article 2-14 mandates that cloud service providers used by critical sectors meet NCA's Cloud Cybersecurity Controls (CCC). Banks should verify that their chosen CSP holds a valid NCA compliance attestation or has undergone a recognized third-party audit aligned with CCC requirements.
Practically, institutions should establish a Cloud Security Framework covering: (1) a pre-migration security review and threat modeling, (2) a shared responsibility matrix defining security obligations between the bank and the CSP, (3) encryption of data at rest and in transit using approved algorithms per SAMA guidelines, (4) continuous cloud posture management using CSPM tools, and (5) a cloud-specific incident response runbook.
Additionally, contracts with CSPs must include right-to-audit clauses, incident notification SLAs of no more than 72 hours (aligning with PDPL breach notification obligations), and exit strategy provisions. SAMA also expects banks to maintain an updated inventory of all cloud-hosted assets and integrate them into the institution's broader cyber risk register. Engaging a vCISO or GRC platform with pre-built SAMA and NCA cloud control mappings can significantly accelerate compliance readiness.
Saudi banks adopting cloud services must establish a robust Cloud Security governance framework that satisfies both SAMA CSF Domain 4 (Technology Security) and NCA ECC-1:2018 controls, particularly Articles 3-2 and 3-3 covering cloud computing security.
Key governance requirements include:
1. Cloud Risk Assessment: Conduct a formal risk assessment before onboarding any cloud service provider (CSP), evaluating data classification, residency obligations, and sovereignty risks. SAMA CSF Control 3.3.5 requires institutions to assess third-party cloud risks as part of their overall risk management program.
2. Data Residency & Sovereignty: SAMA mandates that critical banking data remain within the Kingdom of Saudi Arabia unless explicit regulatory approval is obtained. Work with CSPs to ensure data localization contractual clauses are enforceable.
3. Shared Responsibility Model: Define and document the security responsibilities split between your institution and the CSP. Map CSP capabilities to NCA ECC controls to identify gaps requiring compensating controls.
4. Continuous Monitoring: Implement Cloud Security Posture Management (CSPM) tools to provide real-time visibility into misconfigurations, access anomalies, and compliance drift against defined baselines.
5. Exit Strategy & Portability: SAMA CSF requires documented exit strategies to ensure operational continuity if a CSP relationship is terminated.
6. Audit Rights: Ensure contracts grant the institution and SAMA the right to audit CSP environments, or accept equivalent third-party audit certifications (e.g., ISO 27001, SOC 2 Type II).
Establishing a dedicated Cloud Security Working Group with representatives from IT, Risk, Compliance, and Legal is a practical starting point for operationalizing these requirements effectively.
Adopting cloud services in Saudi financial institutions requires careful alignment with both SAMA CSF and NCA ECC frameworks, as both impose specific obligations around data residency, access control, and risk governance.
SAMA CSF Cloud Requirements:
- Control 3.3.5: Cloud service providers (CSPs) must be subject to formal risk assessments before onboarding, covering security certifications (ISO 27001, CSA STAR), financial stability, and exit strategy.
- Control 2.1.2: All sensitive financial data processed or stored in the cloud must remain within Saudi Arabia's geographic boundaries unless explicitly approved by SAMA.
- Control 4.1: Cloud environments must be included in BCP/DRP scope with tested failover capabilities.
NCA ECC Requirements:
- ECC Article 2-15: Mandates a cloud security policy, data classification before cloud migration, and clear definition of shared responsibility boundaries with the CSP.
- ECC Article 2-7: Requires encryption of data in transit and at rest across all cloud workloads using approved cryptographic standards.
Practical Implementation Guidance:
- Shared Responsibility Mapping: Document precisely what security controls the CSP owns versus your institution using a RACI matrix.
- Cloud Security Posture Management (CSPM): Deploy tools to continuously monitor misconfigurations in IaaS/PaaS environments (AWS, Azure, Oracle Cloud).
- Identity & Access Management: Enforce multi-factor authentication, privileged access workstations, and just-in-time access for cloud admin roles.
- Data Classification: Apply PDPL-aligned data classification labels before migrating any customer data to cloud environments.
- Audit Logging: Enable centralized cloud audit logs forwarded to your SIEM for a minimum 12-month retention per SAMA requirements.
Before migrating any workload to a public cloud, Saudi banks must complete a structured pre-migration assessment aligned with SAMA CSF Domain 4.3 (Technology Security) and NCA ECC-1:2018 Control 3-16 (Cloud Computing Security).
Key requirements include:
- Regulatory Pre-Approval: SAMA requires prior written approval for outsourcing core banking functions to cloud providers. Submit a detailed outsourcing request including risk assessment, data classification, and a business case.
- Data Residency: Customer data classified as sensitive or confidential must remain within Saudi Arabia unless SAMA grants explicit exemption. Validate that your chosen CSP (e.g., AWS Riyadh, Azure KSA) operates locally sovereign regions.
- Cloud Security Risk Assessment: Conduct a formal Cloud Security Risk Assessment per SAMA CSF Control 3.3.5, covering shared responsibility models, data encryption at rest and in transit (AES-256 minimum), and identity & access management controls.
- CSP Due Diligence: Verify the CSP holds recognized certifications — ISO 27001, SOC 2 Type II, and CSA STAR Level 2 — and can provide audit rights contractually.
- Exit Strategy: Document a cloud exit/transition plan ensuring business continuity if the CSP relationship is terminated, per SAMA outsourcing guidelines.
- Continuous Monitoring: Implement Cloud Security Posture Management (CSPM) tools to maintain real-time visibility into misconfigurations and compliance drift post-migration.
Failing to meet these controls exposes institutions to SAMA supervisory action and potential NCA escalation. Engage your vCISO or GRC team early in the cloud adoption lifecycle to ensure compliance gates are embedded in your migration playbook.
Before migrating critical workloads to the cloud, Saudi banks must satisfy a layered set of requirements across both SAMA CSF and NCA ECC frameworks.
SAMA CSF Requirements: Under SAMA CSF Domain 4 (Technology Risk Management), banks must conduct a formal Cloud Risk Assessment prior to any migration. This includes classifying data sensitivity, evaluating the cloud service provider's (CSP) security posture, and ensuring contractual obligations cover data residency, audit rights, and incident notification. SAMA also requires banks to maintain a Cloud Governance Policy and ensure the CSP undergoes third-party assurance assessments (e.g., SOC 2 Type II, ISO 27001 certification).
NCA ECC Requirements: NCA ECC Article 2-6 mandates that organizations classify information assets before cloud adoption and ensure that sensitive national data remains within Saudi Arabia unless explicitly approved otherwise. CSPs must be evaluated against NCA's Cloud Cybersecurity Controls (CCC), and a formal agreement must address security responsibilities using a shared responsibility model.
Practical Steps for CISOs:
- Conduct a Data Classification exercise aligned to SAMA and NCA taxonomies.
- Perform a Cloud Security Risk Assessment covering availability, confidentiality, and integrity risks.
- Validate CSP compliance certifications (ISO 27001, CSA STAR, PCI DSS where applicable).
- Define a Shared Responsibility Matrix documenting bank vs. CSP obligations.
- Establish continuous cloud security monitoring using a Cloud Security Posture Management (CSPM) tool.
- Ensure exit strategy and data portability clauses are included in contracts.
Failure to meet these requirements exposes banks to regulatory sanctions and audit findings during SAMA's annual cybersecurity maturity assessments.
Before migrating critical workloads to the cloud, Saudi banks must satisfy controls across both SAMA CSF and NCA ECC frameworks. Under SAMA CSF Domain 4 (Technology Security), banks are required to conduct a formal Cloud Risk Assessment that evaluates data classification, residency, sovereignty, and shared responsibility boundaries. Critically, customer and financial data classified as 'Sensitive' or 'Confidential' must remain within Saudi Arabia or approved jurisdictions unless explicit regulatory approval is obtained.
Key requirements include:
SAMA CSF Controls:
- Control 3.3.1: Establish a cloud governance policy covering provider selection, exit strategies, and contractual obligations.
- Control 4.2.7: Enforce encryption at rest and in transit using FIPS 140-2 approved algorithms.
- Control 3.2.5: Ensure third-party (CSP) risk assessments are conducted before onboarding and reviewed annually.
NCA ECC Article 2-7 (Cloud Computing Security): Organizations must apply NCA's Cloud Cybersecurity Controls (CCC) baseline, which mandates identity federation, privileged access management (PAM), logging and monitoring integration with the SOC, and vulnerability management for cloud-hosted assets.
Practical Steps for CISOs:
- Classify all workloads using your data classification policy before migration scoping.
- Demand SOC 2 Type II or ISO 27001 certifications from cloud service providers.
- Define a Cloud Exit Strategy to avoid vendor lock-in and ensure business continuity.
- Integrate cloud audit logs into your SIEM for real-time visibility.
- Conduct a pre-migration penetration test on the cloud environment.
Non-compliance with SAMA's cloud security guidance can trigger supervisory review and mandatory remediation orders, making proactive alignment essential for any cloud adoption roadmap.
Cloud adoption in Saudi financial institutions is governed by overlapping requirements from SAMA CSF, NCA ECC, and SAMA's dedicated Cloud Computing Framework. Non-compliance in this area carries significant operational and regulatory risk.
Data Residency & Sovereignty: SAMA requires that sensitive financial data and critical systems remain within the Kingdom unless explicit written approval is obtained. NCA ECC Article 2-15 reinforces this by mandating that national data not leave Saudi borders without proper authorization. CISOs must classify data before cloud migration and validate that their Cloud Service Provider (CSP) offers KSA-region data centers — currently available through AWS, Azure, Google Cloud, and STC Cloud.
Shared Responsibility Model: Per SAMA CSF Control 3.5.1, institutions remain fully accountable for cybersecurity outcomes regardless of outsourcing. Document the shared responsibility matrix with your CSP and ensure security controls not covered by the provider are compensated for internally.
Due Diligence & Contracts: Conduct formal cloud vendor risk assessments aligned to SAMA's outsourcing requirements. Contracts must include right-to-audit clauses, data breach notification obligations, SLA commitments, and data deletion procedures upon contract termination.
Technical Controls: Implement Cloud Security Posture Management (CSPM) tools to continuously monitor misconfigurations. Enforce encryption at rest and in transit, multi-factor authentication, privileged access management (PAM), and network segmentation within your cloud environment.
Ongoing Monitoring: NCA ECC requires logging and monitoring of cloud environments. Integrate cloud logs into your SIEM and establish alert thresholds for anomalous activity. Conduct cloud-specific penetration tests at least annually.
Engaging a vCISO experienced in Saudi regulatory cloud requirements can significantly accelerate compliant cloud adoption.
Cloud adoption in the Saudi financial sector is accelerating, but it introduces significant compliance obligations under both SAMA CSF and NCA ECC. Financial institutions must navigate these frameworks carefully before and during any cloud deployment.
SAMA CSF Requirements: SAMA CSF Section 3.7 (Technology Risk Management) requires that any cloud deployment undergo a formal risk assessment, receive senior management approval, and be governed by a cloud security policy. Critically, SAMA mandates that core banking data must reside within the Kingdom unless explicit regulatory approval is granted for offshore storage.
NCA ECC Requirements: NCA ECC Article 2.7 (Cloud Computing Security) requires organizations to classify data before cloud migration, enforce encryption in transit and at rest, and maintain full visibility over cloud-hosted assets. The NCA Cloud Cybersecurity Controls (CCC-1) provide additional mandatory guidance for government-adjacent entities.
Practical Implementation Steps:
- Cloud Risk Assessment: Conduct a pre-deployment risk assessment evaluating data classification, residency, access controls, and shared responsibility boundaries.
- CSP Due Diligence: Evaluate cloud service providers (CSPs) against SAMA's third-party risk requirements. Preferred CSPs include those with local Saudi regions (e.g., AWS, Azure, Google Cloud in KSA) to satisfy data residency.
- Shared Responsibility Model: Clearly document what the CSP secures versus what your institution owns — particularly for IaaS, PaaS, and SaaS models.
- Continuous Monitoring: Deploy Cloud Security Posture Management (CSPM) tools to detect misconfigurations, enforce policies, and generate audit-ready reports.
- Exit Strategy: SAMA expects documented cloud exit plans to ensure operational resilience if a CSP is terminated.
Align your cloud security program with ISO 27017 (cloud security controls) and ISO 27018 (PII in cloud) to demonstrate international best-practice alignment alongside local regulatory compliance.
Cloud migration in the Saudi financial sector is heavily regulated, and CISOs must navigate overlapping requirements from SAMA, NCA, and the Communications, Space & Technology Commission (CST) before moving critical workloads to the cloud.
SAMA CSF Cloud Requirements: SAMA CSF Control 3.1.4 and the SAMA Cloud Computing Framework (CCF) require financial institutions to conduct a formal cloud risk assessment before onboarding any cloud service. Key obligations include:
- Data Residency: Core banking data and customer personal data must remain within Saudi Arabia borders unless SAMA grants explicit written approval for cross-border transfers.
- CSP Due Diligence: Cloud Service Providers (CSPs) must be assessed against SAMA's CSP evaluation criteria covering security controls, SLAs, audit rights, and incident notification timelines (typically 72 hours for breaches).
- Exit Strategy: A documented exit and portability plan must exist to avoid vendor lock-in and ensure business continuity.
NCA ECC Requirements: NCA ECC Article 3-4 requires organizations to apply the same security baseline to cloud environments as on-premises systems, including access control, encryption, vulnerability management, and logging. Cloud-hosted systems must be included in annual compliance assessments.
Pre-Migration Checklist for CISOs:
- Classify workloads by criticality — Tier 1 (Core Banking, Payment Systems) requires the highest scrutiny.
- Verify CSP holds relevant certifications: ISO 27001, CSA STAR, and ideally local NCA certification.
- Conduct shared responsibility mapping to identify security gaps between bank and CSP obligations.
- Implement Cloud Security Posture Management (CSPM) tools to maintain continuous compliance visibility.
- Establish a Cloud Security Policy reviewed annually and approved by the board.
Both SAMA and NCA can request audit reports and penetration testing results for cloud-hosted systems at any time.
Migrating to public cloud in Saudi Arabia's financial sector requires satisfying overlapping requirements from both SAMA CSF and NCA ECC. Here is a structured compliance approach:
1. Pre-Migration Risk Assessment (SAMA CSF Control 3.3.2) Conduct a formal cloud risk assessment covering data classification, residency requirements, and shared-responsibility model gaps. Sensitive customer and financial data must be classified per SAMA's data classification policy before any workload moves to cloud.
2. Data Residency (NCA ECC Art. 2-7 & PDPL Art. 29) NCA ECC explicitly requires that critical national infrastructure data remain within Saudi Arabia. Banks must ensure their cloud provider offers Saudi-region data centers and contractually commits to data residency. PDPL further restricts cross-border transfer of personal data unless adequate safeguards exist.
3. Cloud Service Provider (CSP) Due Diligence Under SAMA CSF Control 3.3.14 (Third-Party Risk), CSPs must be assessed as vendors. Require SOC 2 Type II, ISO 27001 certification, and a completed SAMA-aligned vendor assessment questionnaire before contract execution.
4. Identity and Access Management Implement Zero Trust principles: enforce MFA, privileged identity management (PIM), and just-in-time access for cloud consoles. Map controls to NCA ECC Domain 2-4 (Access Management).
5. Continuous Monitoring and SIEM Integration Cloud-native logs (e.g., AWS CloudTrail, Azure Monitor) must feed into your SIEM. SAMA CSF requires continuous monitoring of cybersecurity events (Control 3.3.19).
6. SAMA Pre-Approval For core banking workloads, obtain SAMA's no-objection letter before migration. Engage SAMA early in your cloud roadmap to avoid project delays.
Document everything in a Cloud Security Policy aligned to ISO 27017 as a supplementary control framework.
The NCA Essential Cybersecurity Controls (ECC-1:2018) dedicates a specific domain — ECC Domain 4: Cloud Computing and Hosting — to cloud security, making it one of the most operationally complex areas for Saudi organizations. Key NCA ECC Cloud Requirements: ECC-1:2-4.1 requires a formal Cloud Security Policy defining approved cloud service models (IaaS, PaaS, SaaS) and deployment types (public, private, hybrid). ECC-1:2-4.2 mandates data sovereignty controls ensuring national data is not processed or stored outside the Kingdom without explicit authorization. ECC-1:2-4.3 requires contractual assurances from CSPs covering security responsibilities, audit rights, incident notification (within 24 hours), and data deletion upon contract termination. NCA Cloud Compliance Assessment Steps: First, verify the cloud provider holds NCA-recognized certifications such as ISO 27001, CSA STAR Level 2, or SOC 2 Type II. Second, review the provider's Shared Responsibility Model to map security obligations clearly. Third, conduct a Cloud Security Risk Assessment using the CSA Cloud Controls Matrix (CCM) mapped to NCA ECC controls. Fourth, for sensitive or critical workloads, prioritize providers operating NCA-approved local data centers such as AWS Riyadh, Azure KSA, or STC Cloud. For SAMA-regulated entities: SAMA CSF 3.7 adds additional cloud vendor due diligence requirements including onsite audits and SAMA notification for critical outsourcing arrangements. Practically, organizations should maintain a Cloud Asset Register and review CSP security posture annually, with results reported to the CISO and board-level risk committees.
Saudi fintechs operating on cloud infrastructure must comply with both the NCA Cloud Cybersecurity Controls (CCC-1:2020) and SAMA CSF Domain 4 (Technology Security), which together create a layered compliance obligation for cloud environments.
Core NCA CCC requirements:
- CCC-1.1 (Data Residency): Customer data classified as sensitive or critical must be stored within KSA borders unless explicit regulatory approval is obtained. Fintechs must confirm their cloud provider (AWS, Azure, Google, etc.) has a certified KSA-region data center.
- CCC-1.3 (Shared Responsibility): Clearly document the shared responsibility matrix with your cloud provider. Define who is responsible for patching, identity management, encryption, and logging.
- CCC-2 (Identity & Access Management): Enforce Multi-Factor Authentication (MFA) for all privileged cloud accounts, implement Role-Based Access Control (RBAC), and review permissions quarterly.
- CCC-3 (Encryption): Data at rest must use AES-256 and data in transit must use TLS 1.2 or higher. Manage encryption keys using dedicated Key Management Services (KMS) with HSM-backed key storage.
SAMA CSF alignment:
Under Control 4.3.6, SAMA requires financial institutions to assess cloud environments against their information security policies before deployment. Conduct Cloud Security Posture Management (CSPM) scans continuously and maintain a Cloud Security Risk Register.
Practical steps:
- Obtain a Cloud Security Assessment from a SAMA-recognized provider before launch.
- Enable cloud-native logging (e.g., AWS CloudTrail, Azure Monitor) and forward logs to your SIEM.
- Conduct annual third-party cloud penetration tests.
- Review cloud vendor compliance certifications (ISO 27001, SOC 2, CSA STAR).
Cloud adoption in Saudi financial services is governed primarily by SAMA CSF (Domain 3.3 and the Cloud Computing Guidelines issued in 2023) and NCA ECC (Controls 3-1 through 3-4, Cloud Computing). Additionally, NCA's Cloud Cybersecurity Controls (CCC-1:2020) applies directly. Here is a compliance-focused framework:
Pre-Migration Requirements:
- Conduct a formal Cloud Risk Assessment and obtain SAMA/board approval for outsourcing material functions.
- Ensure the Cloud Service Provider (CSP) is compliant with NCA's approved CSP list and meets ISO 27001, CSA STAR, and SOC 2 Type II standards.
- Data residency is a hard requirement: customer financial data must remain within the Kingdom per SAMA guidelines and NCA ECC Control 3-1-3.
Technical Controls (NCA CCC-1):
- Implement Identity and Access Management (IAM) with least-privilege and MFA enforcement.
- Enable encryption at rest (AES-256) and in transit (TLS 1.2+) for all data.
- Deploy Cloud Security Posture Management (CSPM) tools to continuously detect misconfigurations.
- Establish Virtual Private Cloud (VPC) segmentation and restrict public-facing endpoints.
Governance & Monitoring:
- Maintain a shared responsibility matrix clearly defining security obligations between your institution and the CSP.
- Log all cloud activity and integrate with your SIEM for real-time alerting.
- Conduct annual cloud security assessments per SAMA CSF Domain 3.3.5.
Exit Strategy: SAMA requires documented cloud exit plans ensuring operational continuity if the CSP relationship ends. This should be tested at least every two years.
Yes, but with conditions. SAMA allows financial institutions to use public cloud, provided they: conduct a cloud risk assessment; ensure data residency requirements for sensitive customer data; implement appropriate access controls and encryption; maintain regulatory reporting capabilities; have a clear exit strategy; and use SAMA-approved or internationally recognized cloud providers with local data centers in KSA.
Financial institutions in Saudi Arabia operating in the cloud must satisfy overlapping requirements from three primary authorities:
NCA ECC (Cloud Security Controls – Domain 4): Article 4-2 of the ECC mandates that critical infrastructure entities, including financial institutions, classify cloud deployments and implement controls across data sovereignty, access management, encryption, and incident response. Cloud service providers (CSPs) must themselves be NCA-compliant, and organizations must maintain the right to audit CSP security practices.
SAMA Cloud Computing Guidelines (2017, updated): SAMA requires prior written approval before migrating critical systems or sensitive customer data to the cloud. Key obligations include: storing customer financial data within Saudi Arabia or in jurisdictions with equivalent data protection standards, conducting cloud-specific risk assessments, and ensuring business continuity and disaster recovery capabilities are not compromised by cloud dependencies.
Practical Implementation Checklist:
- Classify data per PDPL sensitivity tiers before cloud migration
- Use FIPS 140-2 validated encryption for data at rest and in transit
- Implement Identity and Access Management (IAM) with privileged access controls
- Establish a Cloud Security Posture Management (CSPM) tool to continuously monitor misconfigurations
- Define clear exit strategies and data portability clauses with CSPs
- Map cloud controls to SAMA CSF maturity levels for self-assessment reporting
Cloud adoption in Saudi financial services is accelerating, particularly with hyperscalers like AWS, Microsoft Azure, and Google Cloud establishing local regions. However, regulatory pre-approval remains non-negotiable. Engaging a vCISO or GRC platform early in the cloud journey ensures compliance is embedded by design, not retrofitted.
Migrating banking workloads to public cloud requires a structured security approach aligned with SAMA CSF Domain 3.3 (Technology Security) and NCA ECC-1:2018 Cloud Computing controls. Before any migration, banks must conduct a formal Cloud Risk Assessment and classify data according to SAMA's data classification policy — critical and sensitive financial data requires heightened controls or may mandate on-premises or sovereign cloud hosting.
Key mandatory controls include:
1. Due Diligence on CSPs: Validate that cloud service providers (CSPs) hold recognized certifications such as ISO 27001, SOC 2 Type II, and CSA STAR. Per SAMA CSF Control 3.3.5, third-party hosting agreements must include enforceable security SLAs.
2. Data Residency: SAMA requires that core banking data and customer PII remain within the Kingdom of Saudi Arabia unless explicit regulatory approval is obtained. Confirm your CSP offers KSA-based data center regions.
3. Encryption & Key Management: Implement end-to-end encryption at rest and in transit. Maintain ownership of encryption keys — avoid CSP-managed key models for sensitive workloads; use dedicated HSMs where feasible.
4. Identity & Access Management: Enforce MFA, privileged access management (PAM), and zero-trust principles across cloud environments per SAMA CSF Control 3.3.3.
5. Continuous Monitoring: Deploy CSPM (Cloud Security Posture Management) tools and integrate cloud logs into your SIEM for real-time threat detection.
6. Exit Strategy: Document a cloud exit plan ensuring data portability and service continuity — a direct requirement under SAMA CSF's business continuity provisions.
Engaging a vCISO with SAMA and cloud security expertise before migration significantly reduces compliance gaps and audit findings.
Saudi banks adopting public cloud must align with SAMA CSF Domain 4.3 (Infrastructure Security) and the SAMA Cloud Computing Framework, which mandates a structured risk-based approach before any cloud migration. Key requirements include:
1. Pre-Adoption Due Diligence: Conduct a formal Cloud Risk Assessment covering data classification, residency requirements, and provider security posture. SAMA requires that critical banking data remain subject to its supervisory oversight, meaning cross-border data transfers must be explicitly approved.
2. Contractual Safeguards: Cloud Service Agreements must include right-to-audit clauses, SLA guarantees for availability (typically 99.9%+), data deletion assurances upon contract termination, and incident notification timelines aligned with SAMA CSF Control 3.3.5.
3. Technical Controls: Implement encryption at rest (AES-256) and in transit (TLS 1.2+), multi-factor authentication for all administrative access, and Cloud Access Security Broker (CASB) solutions for visibility. Network segmentation between cloud and on-premises environments is mandatory.
4. Continuous Monitoring: Deploy Security Information and Event Management (SIEM) integration with cloud-native logging (e.g., AWS CloudTrail, Azure Monitor) to maintain audit trails. SAMA expects real-time alerting for anomalous access patterns.
5. Exit Strategy: Maintain a documented cloud exit plan to ensure operational continuity if the provider relationship is terminated, addressing data portability and recovery timelines.
NCA ECC Article 7-4 further reinforces cloud security obligations for entities within its scope. Banks should conduct annual cloud security assessments and ensure any Shared Responsibility Model gaps are explicitly addressed in internal security policies.
Before migrating critical workloads to public cloud, Saudi banks must satisfy a layered set of requirements under both SAMA CSF and NCA ECC.
SAMA CSF Requirements: Per SAMA CSF Control 3.3, banks must conduct a formal Cloud Risk Assessment prior to any migration, classifying data and systems by criticality. Sensitive customer data and core banking systems typically require explicit SAMA approval or must remain on-premises or in approved private cloud environments. Contracts with Cloud Service Providers (CSPs) must include enforceable data residency clauses confirming data stays within the Kingdom of Saudi Arabia, as well as right-to-audit provisions.
NCA ECC Requirements: NCA ECC Article 3-5 mandates that entities classify information assets before cloud adoption and ensure CSPs meet NCA's Cloud Cybersecurity Controls (CCC). Specifically, banks must verify that CSPs hold valid certifications (e.g., ISO 27001, CSA STAR) and comply with NCA CCC requirements covering logical separation, encryption at rest and in transit, and incident notification SLAs.
Practical Steps:
- Conduct a data classification exercise aligned to SAMA CSF and NCA ECC sensitivity levels.
- Perform a Cloud Security Risk Assessment documented and approved by the CISO and Board Risk Committee.
- Negotiate CSP contracts to include data residency, audit rights, breach notification within 72 hours, and exit strategy clauses.
- Implement Cloud Access Security Broker (CASB) controls for visibility and policy enforcement.
- Establish continuous compliance monitoring mapped to both frameworks.
Failure to follow this process can result in regulatory findings during SAMA examinations and NCA cybersecurity audits.
Before migrating critical workloads to the cloud, Saudi banks must satisfy a layered set of requirements under both SAMA CSF and NCA ECC.
SAMA CSF Requirements: Per SAMA CSF Control 3.3.5 (Cloud Computing), banks must conduct a formal Cloud Risk Assessment prior to any migration. This includes classifying data sensitivity, evaluating the Cloud Service Provider (CSP) against SAMA's approved vendor criteria, and ensuring contractual controls cover data sovereignty, audit rights, and exit strategies. SAMA also requires that critical customer data remain within the Kingdom unless explicit regulatory approval is granted.
NCA ECC Requirements: Under NCA ECC-1: 2-1 (Cloud Computing Security), organizations must ensure CSPs comply with NCA's Cloud Cybersecurity Controls. Banks should verify that their chosen CSP holds a valid NCA cloud compliance certificate and that shared responsibility models are clearly documented.
Practical Steps:
- Classify workloads using a data classification policy aligned to ISO 27001 Annex A.8.
- Conduct a Cloud Security Risk Assessment mapped to NIST CSF Identify (ID.AM) and Protect (PR.DS) functions.
- Review CSP contracts for data residency, incident notification SLAs (within 72 hours per PDPL Article 21), and forensic access rights.
- Implement Cloud Access Security Broker (CASB) controls and encryption at rest and in transit.
- Establish a Cloud Exit Strategy document as required by SAMA CSF Control 3.3.5.4.
Cloud migration without this governance foundation exposes banks to regulatory penalties and heightened breach risk.
Cloud adoption in Saudi financial services is governed by a layered regulatory framework. SAMA CSF Control 3.4 (Technology Security) and NCA ECC Article 2-14 collectively require financial institutions to establish a formal Cloud Security Governance framework before migrating any workloads. Key obligations include: (1) Cloud Risk Classification: Classify data and workloads by sensitivity — SAMA prohibits hosting core banking data on public cloud without explicit approval and robust controls; (2) Shared Responsibility Matrix: Formally document the security responsibilities split between your institution and the cloud service provider (CSP) for each service model (IaaS, PaaS, SaaS); (3) Cloud Service Provider Due Diligence: CSPs must undergo vendor risk assessments aligned with SAMA CSF third-party requirements, including evidence of ISO 27001 certification and SOC 2 Type II reports; (4) Data Residency: Customer financial data must remain within the Kingdom unless SAMA grants an exception — NCA ECC Article 2-14-1 reinforces this requirement; (5) Encryption and Key Management: Encryption at rest and in transit is mandatory, and encryption keys must be controlled by the financial institution, not the CSP; (6) Continuous Monitoring: Implement Cloud Security Posture Management (CSPM) tools and integrate alerts into your SOC. Additionally, SAMA's Cloud Computing Regulatory Framework (CCRF) provides supplementary guidance. Institutions should maintain a Cloud Asset Register and conduct annual cloud security reviews as part of their broader IS audit cycle.
Cloud adoption in Saudi financial institutions is tightly governed by both SAMA CSF and NCA ECC. Before migrating any data or workload, institutions must complete a formal data classification exercise as required under SAMA CSF Control 3.2.1, categorizing data into tiers such as Public, Internal, Confidential, and Restricted — with financial customer data and transaction records typically falling under Restricted.
For cloud deployments, NCA ECC Article 3-7 mandates that data classified as sensitive or critical must remain within Saudi Arabia's geographic boundaries unless explicit regulatory approval is obtained. This means institutions must verify that their cloud service providers (CSPs) operate sovereign data centers within the Kingdom, or leverage approved models such as Hyperscaler Sovereign Cloud offerings.
Key technical controls required include: (1) encryption of data at rest using AES-256 and in transit using TLS 1.2 or higher; (2) customer-managed encryption keys (CMEK) so the institution retains cryptographic control; (3) strict Identity and Access Management (IAM) with least-privilege principles enforced across all cloud tenants; (4) continuous cloud security posture management (CSPM) to detect misconfigurations; and (5) data loss prevention (DLP) policies aligned with your classification tiers.
SAMA also requires that cloud contracts include specific security clauses, audit rights, and incident notification obligations. Your GRC platform should map cloud controls to both SAMA CSF and NCA ECC requirements, providing a unified compliance view rather than managing two separate frameworks in silos.
Migrating core banking workloads to public cloud in Saudi Arabia requires satisfying a layered set of regulatory and technical requirements. Under SAMA CSF Control Domain 3.6 (Cloud Computing) and NCA Cloud Cybersecurity Controls (CCC), institutions must complete the following before go-live: (1) Regulatory pre-approval: SAMA requires prior notification and, for critical systems, explicit approval before cloud migration. Engage SAMA early and document your risk assessment. (2) Data residency: All customer financial data classified as sensitive must reside within the Kingdom of Saudi Arabia. Validate that your cloud provider (AWS Riyadh, Azure UAE North with data sovereignty guarantees, or STC Cloud) offers certified KSA data residency. (3) Cloud Security Posture Management (CSPM): Deploy CSPM tooling to continuously monitor misconfiguration risks against benchmarks such as CIS Cloud Foundations. (4) Encryption: Data must be encrypted at rest and in transit using approved algorithms (AES-256, TLS 1.2+). Crucially, key management must remain under the institution's control — use Bring Your Own Key (BYOK) or Hold Your Own Key (HYOK) models, per NCA CCC Control 3.4. (5) Shared Responsibility Model documentation: Clearly define and document security responsibilities between the bank and the CSP, covering incident response, patch management, and access control. (6) Exit strategy: Per SAMA CSF, a documented and tested cloud exit strategy is mandatory to avoid vendor lock-in risk. (7) Third-party audit: Annual cloud security assessments by an approved third party are required, with findings reported to the board risk committee. Engage your cloud provider's financial services compliance team early — AWS, Microsoft Azure, and Google Cloud all maintain dedicated Saudi financial sector compliance programs.
Cloud migration in Saudi financial services is governed by a layered set of regulatory requirements. Before moving any workload to public cloud, institutions must satisfy obligations from SAMA, NCA, and in some cases the Communications, Space & Technology Commission (CST).
SAMA Cloud Requirements: SAMA's Regulatory Framework for Cloud Computing in the Financial Sector requires prior notification or approval depending on workload criticality. Critical systems (core banking, payment processing) require explicit SAMA approval before migration. Non-critical workloads require formal risk assessments and documented board approval.
NCA Cloud Cybersecurity Controls (CCC): The NCA's CCC framework mandates that cloud service providers used by financial institutions meet specific security standards, including data sovereignty (data must reside in Saudi Arabia for sensitive workloads), encryption at rest and in transit, and multi-tenancy isolation controls.
Pre-Migration Checklist:
- Classify workloads by sensitivity (using SAMA CSF data classification guidelines)
- Conduct a Cloud Security Risk Assessment covering shared responsibility models
- Validate CSP compliance with NCA CCC and ISO 27017/27018
- Define exit strategy and data portability provisions
- Ensure incident response and logging capabilities extend to cloud environments (per NCA ECC Control 2-14)
- Establish Identity and Access Management (IAM) controls aligned with least-privilege principles
Ongoing Compliance: Post-migration, conduct quarterly cloud configuration reviews, enable CSPM (Cloud Security Posture Management) tools, and include cloud environments in annual penetration testing scope per SAMA CSF Control 3.3.5.
Engaging a vCISO or cloud security specialist familiar with Saudi regulatory nuances is strongly recommended before initiating migration.
The NCA ECC (Essential Cybersecurity Controls) addresses cloud computing under Control 2-14 (Cloud Computing and Hosting Services), establishing clear requirements for organizations operating in Saudi Arabia, including financial institutions subject to both NCA ECC and SAMA CSF oversight.
Key NCA ECC Cloud Requirements:
- Cloud services must be assessed and approved through a formal risk management process before adoption
- Data classification must be performed prior to cloud migration; sensitive and critical data requires additional safeguards
- Contracts with Cloud Service Providers (CSPs) must include security requirements, data residency clauses, and incident response obligations
- Data sovereignty is paramount: personal and sensitive financial data should preferably reside within Saudi Arabia, aligned with PDPL Article 29 on cross-border data transfers
SAMA-Specific Considerations: SAMA's Cloud Computing Guidelines require banks to notify SAMA before migrating material systems to the cloud and to maintain a cloud risk register. Core banking and customer data systems face stricter scrutiny.
Practical Implementation Steps:
- Cloud Security Assessment: Evaluate CSPs against CSA STAR, ISO 27017/27018, and local compliance requirements
- Shared Responsibility Model: Clearly document what security controls the CSP owns versus your institution
- Access Controls: Implement Zero Trust architecture, MFA, and privileged access management for all cloud environments
- Continuous Monitoring: Deploy Cloud Security Posture Management (CSPM) tools to detect misconfigurations
- Data Encryption: Enforce encryption at rest and in transit with customer-managed keys (CMK)
Financial institutions using hyperscalers (AWS, Azure, Google Cloud) should leverage their Saudi Arabia local regions to satisfy data residency requirements while benefiting from cloud scalability.
Migrating critical workloads to the cloud in Saudi Arabia's financial sector requires careful alignment with both NCA ECC and SAMA CSF frameworks before and after migration. Here's a structured compliance roadmap:
1. Pre-Migration Risk Assessment (SAMA CSF Domain 3 & NCA ECC Art. 3-2): Conduct a formal Cloud Risk Assessment covering data classification, regulatory data residency requirements, and shared responsibility model gaps. SAMA requires that risk assessments for cloud services be documented and approved at the board/senior management level.
2. Data Residency & Sovereignty: SAMA mandates that customer financial data must reside within the Kingdom of Saudi Arabia. Ensure your cloud provider (e.g., AWS Riyadh, Azure Saudi North) can demonstrate in-Kingdom data storage with contractual guarantees. Non-compliance here is a critical finding during SAMA examinations.
3. NCA Cloud Cybersecurity Controls (NCA ECC-1:2018 Domain 2-9): NCA ECC requires implementing specific controls for cloud environments including: identity and access management, encryption of data at rest and in transit, logging and monitoring, and secure API management.
4. Cloud Security Architecture Review: Before go-live, conduct an architecture review validating: network segmentation, WAF deployment, DDoS protection, and privileged access management. ISO 27017 controls provide a useful supplementary baseline.
5. Vendor Due Diligence & Exit Strategy: Assess the CSP's financial stability, SLA terms, and incident response capabilities. Critically, document a cloud exit strategy per SAMA CSF to avoid vendor lock-in risks.
Key Reminder: SAMA requires formal approval for cloud adoption of critical systems — engage your SAMA relationship manager early in the process.
Cloud adoption in Saudi financial institutions is governed by a layered regulatory framework combining NCA ECC, SAMA CSF, and the NCA Cloud Cybersecurity Controls (CCC). Before migrating any workload, security and compliance teams must address the following key requirements:
1. Data Residency (NCA ECC Art. 2-7 & CCC Control 1-3): Critical and sensitive data — especially customer financial and personal data — must reside within the Kingdom of Saudi Arabia. Confirm that your chosen CSP (e.g., AWS Riyadh, Azure KSA) operates sovereign, locally compliant data centers.
2. Cloud Risk Assessment (SAMA CSF 3.3.4): Conduct a formal cloud risk assessment prior to migration. This must evaluate data classification, shared responsibility boundaries, availability SLAs, and residual risks.
3. Shared Responsibility Model Documentation: Clearly delineate security responsibilities between your institution and the CSP. Many audit failures stem from assuming the CSP handles controls that remain the customer's responsibility (e.g., IAM configurations, encryption key management).
4. Encryption Requirements (NCA CCC Control 3-1): All data at rest and in transit must be encrypted. Institutions must retain ownership and management of encryption keys — avoid CSP-managed keys for sensitive workloads.
5. Identity and Access Management: Enforce least-privilege access, MFA for all cloud console access, and privileged access monitoring aligned with SAMA CSF Control 3.3.16.
6. Exit Strategy and Portability: Regulatory guidance requires documented cloud exit strategies to prevent vendor lock-in and ensure operational resilience.
Engage your CISO Consulting team early in cloud migration planning to map technical controls to regulatory requirements and avoid costly remediation post-deployment.
Migrating core banking systems to the public cloud in Saudi Arabia requires rigorous compliance with multiple regulatory frameworks before go-live. The primary references are NCA Cloud Cybersecurity Controls (CCC-1:2020), SAMA CSF Domain 3.3, and SAMA's Cloud Computing Guidelines.
Pre-Migration Requirements:
- Regulatory Approval: SAMA requires prior written notification and, for critical systems, explicit approval before migrating to any cloud environment. Institutions must submit a Cloud Risk Assessment report as part of this process.
- Data Residency: All customer financial data and transaction records must be stored within the Kingdom of Saudi Arabia, per SAMA directives and NCA CCC Control 3-1. Contracts with CSPs must explicitly enforce this.
- Cloud Security Architecture Review: Per NCA CCC Control 2-4, a formal security architecture review must be conducted, covering network segmentation, identity and access management (IAM), encryption (at rest and in transit), and API security.
- Shared Responsibility Model Documentation: Institutions must formally document which security controls are managed by the CSP and which remain the institution's responsibility, aligned to ISO 27017 guidelines.
- Continuous Monitoring and SIEM Integration: NCA CCC Control 3-3 mandates real-time log collection and security event monitoring. Cloud workloads must be integrated into the institution's Security Operations Center (SOC).
- Exit Strategy: SAMA expects a documented cloud exit strategy to prevent vendor lock-in and ensure operational continuity.
Institutions should also validate that their CSP holds NCA certification or equivalent recognized accreditation before selection.
Cloud adoption in Saudi financial institutions is governed by a layered regulatory framework. Institutions must align with NCA ECC Article 2-2 (Cloud Computing), NCA's dedicated Cloud Computing Controls (CCC), and SAMA's Cloud Computing Guidelines before deploying any cloud-based systems.
Core Requirements:
Data Residency: Sensitive customer financial data and core banking workloads must reside within Saudi Arabia. Cloud providers must demonstrate compliance with NCA CCC data localization mandates. This applies to both infrastructure-as-a-service (IaaS) and software-as-a-service (SaaS) deployments.
Cloud Risk Assessment: Prior to any cloud migration, a formal Cloud Security Risk Assessment must be conducted per SAMA guidelines. This should evaluate data classification, shared responsibility models, and regulatory implications of the deployment.
Access Control & Identity Management: NCA ECC Control 2-2-3 requires strict identity and access management (IAM) for cloud environments, including multi-factor authentication (MFA), privileged access management (PAM), and least-privilege principles.
Encryption Standards: Data at rest and in transit must be encrypted using approved cryptographic standards. Key management must remain under the institution's control, not the cloud provider's.
Continuous Monitoring & SIEM Integration: Cloud workloads must feed into centralized Security Information and Event Management (SIEM) systems to maintain visibility per SAMA CSF Domain 3 (Cybersecurity Operations).
Exit Strategy: SAMA requires documented cloud exit strategies to ensure portability and prevent vendor lock-in, protecting operational resilience.
Our platform maps your cloud architecture against NCA CCC and SAMA cloud requirements, providing gap analysis, control implementation tracking, and audit-ready compliance documentation.
Cloud adoption in Saudi financial services is governed by multiple overlapping frameworks. Before any migration, institutions must navigate SAMA CSF Domain 5 (Cloud Computing), NCA ECC Article 2-14 (Cloud Security), and NCA Cloud Cybersecurity Controls (CCC).
Pre-Migration Requirements:
- Risk Assessment: Classify data sensitivity and determine which workloads are permissible for cloud hosting. SAMA restricts certain core banking data from residing outside Saudi Arabia without explicit approval.
- Cloud Service Provider (CSP) Due Diligence: CSPs must demonstrate compliance with NCA ECC and ideally hold CST (Communications, Space & Technology Commission) certification or equivalent.
- Data Residency: Per NCA ECC Art. 2-14-4 and SAMA guidance, customer financial data must remain within KSA borders unless formally approved otherwise.
Key Technical Controls:
- Implement Cloud Security Posture Management (CSPM) tools for continuous misconfiguration detection.
- Enforce encryption at rest (AES-256) and in transit (TLS 1.2+) per SAMA CSF Control 3.3.
- Apply Zero Trust Architecture principles — no implicit trust for any cloud resource.
- Deploy Identity and Access Management (IAM) with MFA enforced for all privileged accounts.
- Maintain full audit logs exported to a SIEM outside the CSP environment to prevent tampering.
Governance Requirements:
- Establish a Cloud Security Policy reviewed annually.
- Define clear shared responsibility matrices with each CSP.
- Include cloud environments in annual penetration testing scope.
Institutions using hyperscalers (AWS, Azure, GCP) must ensure their KSA-region deployments satisfy all local regulatory obligations before go-live.
Before migrating critical workloads to the cloud, Saudi banks must satisfy a layered set of regulatory requirements under SAMA CSF Domain 4 (Technology Risk Management) and NCA ECC-1:2018 Article 3-5 (Cloud Computing Controls).
Key requirements include:
- Risk Classification: Conduct a formal data and workload classification exercise. SAMA CSF Control 3.3.2 requires that data sensitivity levels guide hosting decisions — critical and confidential data may require on-premises or sovereign cloud deployments.
- SAMA Pre-Approval: Banks must obtain SAMA's explicit no-objection before moving core banking systems or customer data to cloud environments, particularly public cloud. Submit a Cloud Risk Assessment report as part of this process.
- Data Residency: NCA ECC mandates that data classified as 'Restricted' or above must remain within the Kingdom of Saudi Arabia. Verify your cloud provider maintains KSA-based data centers (e.g., AWS Riyadh, Azure Saudi North).
- Third-Party Due Diligence: Per SAMA CSF Control 3.4.1, cloud providers must undergo formal vendor risk assessments covering security certifications (ISO 27001, CSA STAR), SLA terms, audit rights, and incident notification obligations.
- Exit Strategy: Document a cloud exit and portability plan to avoid vendor lock-in, as required under SAMA outsourcing guidelines.
- Encryption & Access Control: Enforce encryption at rest and in transit, implement privileged access management (PAM), and maintain full audit logs accessible to SAMA examiners.
Practically, banks should establish a Cloud Security Governance Committee and integrate cloud risk reviews into the existing IT Risk Management framework before any migration begins.
Before migrating critical workloads to the cloud, Saudi banks must satisfy a layered set of requirements across both SAMA CSF and NCA ECC. Under SAMA CSF Control 3.3, institutions must conduct a formal cloud risk assessment that evaluates data classification, residency obligations, and vendor security posture. Data classified as sensitive or critical must — per SAMA CSF Appendix C — either remain on-premises or be hosted within the Kingdom unless explicit regulatory approval is obtained.
From an NCA ECC perspective, Article 3-8 mandates that cloud service providers used by financial entities meet ECC baseline controls and, where applicable, hold NCA certification. Banks must perform due diligence on CSP compliance documentation, shared responsibility matrices, and audit rights before signing contracts.
Key pre-migration steps include:
- Data Classification Review – Identify which workloads contain personal, financial, or regulated data under PDPL and SAMA guidelines.
- CSP Risk Assessment – Evaluate SOC 2 Type II, ISO 27001, and NCA ECC alignment of the chosen provider.
- Contractual Controls – Enforce clauses covering data sovereignty, incident notification (within 72 hours per SAMA CSF 3.7.3), audit rights, and exit strategies.
- Encryption & Key Management – Ensure customer-managed encryption keys (CMEK) are used for data at rest and in transit.
- Continuous Monitoring – Implement Cloud Security Posture Management (CSPM) tools and integrate alerts into your SOC.
Engaging a vCISO or GRC consultant with SAMA and NCA expertise during the pre-migration phase significantly reduces regulatory exposure and accelerates approval timelines.
Before migrating critical workloads to the cloud, Saudi banks must satisfy several layered requirements across both SAMA CSF and NCA ECC frameworks.
SAMA CSF Requirements: Under SAMA CSF Domain 4 (Technology Security), banks must conduct a formal Cloud Security Risk Assessment prior to any migration. Control 4.3 requires that all cloud deployments maintain data residency within the Kingdom of Saudi Arabia for sensitive financial data. Banks must also ensure contractual clauses with Cloud Service Providers (CSPs) address right-to-audit, incident notification timelines (within 72 hours), and data deletion guarantees upon contract termination.
NCA ECC Requirements: Per NCA ECC Article 3-5 (Cloud Computing Security), organizations must classify data before migration using the NCA Data Classification Policy and ensure that Tier 1 (confidential) data is hosted on government-approved or Saudi-localized infrastructure. ECC also mandates that CSPs undergo third-party security assessments aligned with ISO 27001 and CSA STAR certifications.
Practical Steps:
- Conduct a Cloud Readiness Assessment mapped to SAMA CSF and NCA ECC controls.
- Evaluate CSPs against SAMA's approved vendor criteria and NCA's Cloud Cybersecurity Controls.
- Implement CASB (Cloud Access Security Broker) solutions for continuous visibility.
- Establish a shared responsibility matrix clearly defining bank vs. CSP security obligations.
- Ensure Business Continuity and Disaster Recovery plans cover cloud-hosted systems.
Engaging a qualified vCISO or GRC consultant early in the migration planning phase significantly reduces compliance gaps and regulatory exposure.
Cloud adoption in Saudi fintech is accelerating, but it introduces significant compliance obligations under both NCA's Cloud Computing Controls (CCC) and SAMA CSF. Getting cloud security right requires addressing governance, architecture, and operational controls simultaneously.
NCA CCC Key Requirements: NCA CCC mandates that critical national infrastructure data — including financial customer data — must reside within Saudi Arabia or designated regions. Fintechs must verify that their cloud service provider (CSP) has a Saudi-region data center (AWS, Azure, and Google Cloud all operate local zones).
SAMA CSF Cloud Obligations (Controls 3.6 & 4.x):
- Conduct a cloud risk assessment before migration
- Maintain a cloud asset inventory covering all workloads, APIs, and storage
- Ensure CSP contracts include explicit security responsibilities per the Shared Responsibility Model
- Implement data encryption at rest (AES-256) and in transit (TLS 1.2+)
Technical Security Controls:
- Identity & Access: Enforce MFA for all cloud console access; implement least-privilege IAM policies; use Privileged Access Management (PAM) for admin accounts
- Network Segmentation: Deploy Virtual Private Clouds (VPCs) with strict security group rules; segregate production, development, and test environments
- Logging & Monitoring: Enable cloud-native logging (e.g., AWS CloudTrail, Azure Monitor) and integrate with your SIEM for real-time threat detection — required under SAMA CSF Control 3.5
- Vulnerability Management: Conduct quarterly cloud configuration reviews and use CSPM (Cloud Security Posture Management) tools to detect misconfigurations continuously
PDPL Considerations: When processing customer personal data in the cloud, ensure data processing agreements with CSPs address PDPL Article 29 requirements for cross-border transfers if applicable.
A vCISO with cloud expertise can accelerate your NCA CCC gap assessment and build a cloud security roadmap aligned to both frameworks.
Cloud adoption in Saudi financial institutions is subject to strict regulatory scrutiny under both SAMA CSF (Domain 4: Cloud Computing) and NCA ECC (Article 3-7: Cloud Computing Controls). Before migrating any workload, CISOs must conduct a formal cloud risk assessment and classify data per PDPL and internal sensitivity tiers. SAMA requires that institutions retain full ownership of data and that cloud service providers (CSPs) are contractually obligated to support regulatory audits. Key compliance steps include: (1) Ensure the CSP is approved or assessed under NCA's Cloud Cybersecurity Controls (CCC-1:2020). (2) Implement data residency controls — sensitive financial and customer data must remain within the Kingdom unless explicitly approved. (3) Establish a Cloud Security Governance Framework covering access control, encryption at rest and in transit (AES-256 minimum), and continuous monitoring. (4) Per SAMA CSF Control 4.3, conduct annual cloud-specific risk assessments and include cloud environments in your penetration testing scope. (5) Define clear exit strategies and data portability clauses in CSP contracts to avoid vendor lock-in risks. CISOs should also map cloud controls to ISO 27017 and CSA CCM for a layered compliance posture. Failure to comply can trigger SAMA supervisory action and NCA audit findings, both of which carry reputational and operational consequences for licensed financial entities.
SAMA CSF Domains 3.3 and 4.2 impose stringent requirements on cloud adoption within Saudi financial institutions. Before onboarding any cloud service provider (CSP), CISOs must conduct a formal Cloud Risk Assessment covering data residency, sovereignty, encryption standards, and exit strategy feasibility.
Key requirements include:
1. Data Residency: Per SAMA CSF Control 3.3.2, sensitive financial and customer data must be stored within the Kingdom of Saudi Arabia or in jurisdictions approved by SAMA. Confirm this contractually with your CSP.
2. Due Diligence: Evaluate CSPs against ISO 27001, CSA STAR, and SOC 2 Type II certifications. SAMA expects documented evidence of third-party audits and penetration testing results from providers.
3. Access Controls: SAMA CSF Control 4.2.3 requires privileged access management (PAM) controls for cloud environments, including MFA enforcement and just-in-time access provisioning.
4. Shared Responsibility Model: CISOs must formally document and communicate the shared responsibility boundary, ensuring configuration management, logging, and incident response responsibilities are explicitly assigned.
5. NCA ECC Alignment: NCA ECC Article 3-4 further mandates that government-regulated entities (including licensed banks) seek NCA approval before migrating critical national infrastructure workloads to cloud environments.
6. Continuous Monitoring: Implement Cloud Security Posture Management (CSPM) tools to detect misconfigurations and compliance drift in real time.
Practically, CISOs should build a Cloud Security Policy that references both SAMA CSF and NCA ECC controls, conduct annual cloud security reviews, and ensure Business Continuity Plans (BCPs) explicitly address cloud provider outage scenarios.
Cloud adoption is accelerating across Saudi financial institutions, but NCA ECC and SAMA CSF impose strict requirements that must be met before any migration to cloud environments — particularly for critical and sensitive workloads.
NCA ECC Cloud Security Requirements (Domain 2-13: Cloud Computing and Hosting):
- Cloud services hosting sensitive or critical data must be provided by CSPs holding a valid NCA Cloud Computing Cybersecurity Controls (CCC) certification or equivalent recognized approval.
- Data sovereignty requirements mandate that data classified as sensitive or national-critical must reside within the Kingdom of Saudi Arabia unless an explicit regulatory exemption is granted.
- Organizations must maintain full visibility and control over data stored in cloud environments, including encryption key ownership — per NCA ECC Control 2-13-1.
- Exit strategies and portability must be documented to avoid CSP lock-in risks.
SAMA CSF Alignment (Control 3.7 — Outsourcing and Cloud):
- Financial institutions must conduct a formal cloud risk assessment before onboarding any CSP.
- Contractual agreements with CSPs must include right-to-audit clauses, SLA guarantees, and incident notification obligations.
- Shared responsibility models must be clearly documented, with the institution retaining accountability for data protection regardless of CSP involvement.
CSP Evaluation Checklist:
- Regulatory certifications: Verify NCA CCC certification, ISO 27001, SOC 2 Type II, and CSA STAR.
- Data residency: Confirm all primary and backup data remains within KSA data centers.
- Encryption controls: Ensure customer-managed encryption keys (CMEK) are supported.
- Access management: Validate support for MFA, privileged access workstations, and zero-trust architecture.
- Incident response SLAs: Confirm breach notification timelines meet SAMA's 72-hour reporting obligation.
- Audit rights: Ensure contracts permit independent third-party audits of the CSP environment.
For financial institutions, hyperscalers such as AWS, Microsoft Azure, and Google Cloud now operate KSA-based regions — but contractual and technical controls must still be validated before onboarding.
Cloud adoption in Saudi financial services is tightly regulated. Both SAMA CSF and NCA ECC impose specific controls that CISOs must address before and during cloud deployments.
SAMA CSF Cloud Requirements (Domain 3.7):
- Formal cloud risk assessment before onboarding any cloud service provider (CSP)
- Data classification must determine what data can reside in the cloud — critical/sensitive financial data requires heightened controls
- Contractual obligations: CSPs must agree to SAMA's security requirements, audit rights, and data residency clauses
- Exit strategy and data portability provisions must be documented
NCA ECC Controls (Article 2-14 and Cloud Controls Annex):
- NCA's Cloud Cybersecurity Controls (CCC) framework applies to all government-connected entities and regulated financial institutions
- Data sovereignty: NCA mandates that certain data categories must reside within Saudi Arabia — verify CSP availability zones in KSA
- Shared responsibility model must be formally documented and reviewed annually
Practical Implementation Steps:
- Classify all data assets before migration using your data classification policy
- Conduct a formal Cloud Security Risk Assessment aligned with ISO 27017/27018
- Evaluate CSPs against NCA's approved cloud service provider list where applicable
- Implement Cloud Access Security Broker (CASB) controls for visibility and policy enforcement
- Establish continuous cloud security posture management (CSPM) monitoring
- Ensure encryption at rest and in transit meets SAMA's cryptographic control requirements
Key Risk: Misunderstanding the shared responsibility model remains the top cloud compliance gap in Saudi financial institutions. Document exactly what the CSP secures versus your internal obligations.
Cloud adoption in Saudi financial institutions must align with both SAMA CSF Control Domain 3.3 and NCA ECC-2 Article 3-12 (Cloud Computing Security). Compliance requires a layered approach across governance, architecture, and operations.
Regulatory Baseline: SAMA requires prior approval before migrating critical systems to the cloud. Submit a formal Cloud Risk Assessment and obtain written SAMA acknowledgment. NCA ECC mandates that all cloud service providers (CSPs) used by regulated entities must hold a valid NCA Cloud Compliance certificate or equivalent recognized certification.
Data Residency: Both frameworks require that sensitive financial and personal data remain within Saudi Arabia unless explicit regulatory approval is granted. This aligns with PDPL Article 29 on cross-border data transfers. Confirm your CSP offers KSA-based regions (e.g., AWS Riyadh, Microsoft Azure Saudi North) and that data sovereignty is contractually guaranteed.
Shared Responsibility Model: Define and document the security responsibilities split between your institution and the CSP. Map each NCA ECC control to either the CSP or internal teams — this is critical for audit evidence.
Key Technical Controls: Enforce encryption at rest and in transit (minimum AES-256 / TLS 1.2+), implement privileged access management (PAM) for cloud admin accounts, enable continuous cloud security posture management (CSPM) tooling, and conduct cloud-specific penetration testing annually.
Incident Response: Ensure your CSP contractually commits to incident notification within SAMA's required timeframe. Integrate cloud logs (CloudTrail, Azure Monitor) into your SIEM for real-time threat detection aligned with NCA SOC requirements.
Cloud adoption in Saudi banking is accelerating, but it introduces complex compliance obligations that span both SAMA CSF and NCA ECC simultaneously. Financial institutions must navigate these requirements carefully to avoid regulatory exposure.
SAMA CSF Cloud Requirements: SAMA's Technology Risk Management (TRM) guidelines and CSF Control Domain 4.5 require that cloud deployments undergo a formal risk assessment, with critical banking systems restricted to approved cloud service models. Key controls include:
- Data classification and enforcement of residency requirements (sensitive customer data must remain within the Kingdom per PDPL Article 29).
- Shared Responsibility Model documentation clarifying security obligations between the institution and the Cloud Service Provider (CSP).
- Exit strategy and data portability planning.
NCA ECC Cloud Controls: NCA ECC Articles 2-11 and 2-14 establish baseline cloud security controls including:
- Mandatory use of NCA-approved or locally regulated cloud providers for government-adjacent data.
- Encryption at rest and in transit using approved cryptographic standards.
- Continuous monitoring and logging with retention aligned to NCA requirements (minimum 12 months).
Practical Implementation Roadmap:
- Cloud Security Policy: Draft a dedicated policy referencing both SAMA TRM and NCA ECC obligations.
- CSP Due Diligence: Validate that your CSP holds ISO 27001, CSA STAR, and ideally Saudi CITC certifications.
- Security Baseline: Implement Cloud Security Posture Management (CSPM) tools to continuously enforce NCA ECC controls.
- Identity & Access: Enforce Zero Trust principles with MFA and Privileged Access Management (PAM) across all cloud workloads.
- Incident Response Integration: Extend your IR playbooks to cover cloud-specific breach scenarios with SAMA notification timelines in mind.
Regular cloud security assessments — at minimum annually per SAMA CSF — are essential to maintain compliance posture.
The NCA Essential Cybersecurity Controls (ECC) dedicates an entire domain — Domain 4: Cloud Computing and Hosting Cybersecurity — to regulating how Saudi organizations must secure cloud environments. Compliance is mandatory for all government entities and strongly recommended for regulated private sector organizations including financial institutions.
Key ECC Cloud Controls Include:
ECC 4-1 (Cloud Security Governance): Organizations must define a cloud security policy, classify workloads by sensitivity, and obtain formal approval from leadership before migrating any critical systems to cloud environments.
ECC 4-2 (Cloud Provider Assessment): Before selecting a Cloud Service Provider (CSP), a formal security assessment must be conducted covering data residency (Saudi data must reside within the Kingdom unless explicitly approved), certifications (ISO 27001, CSA STAR), and SLA commitments for security incident response.
ECC 4-3 (Shared Responsibility Model): Organizations must formally document what security responsibilities are retained internally versus delegated to the CSP, particularly around identity management, encryption, and logging.
ECC 4-4 (Data Protection in Cloud): All sensitive and personal data stored or processed in cloud environments must be encrypted at rest and in transit. Access must follow least-privilege principles with MFA enforced for administrative accounts.
SAMA Alignment: For banks and fintechs, SAMA CSF additionally requires that outsourcing to cloud providers be notified to SAMA in advance for material outsourcing arrangements, with a risk assessment documented.
PDPL Consideration: Personal data transferred to cloud environments must comply with PDPL cross-border transfer restrictions unless the destination jurisdiction provides adequate protection.
Practical guidance: Implement a Cloud Security Posture Management (CSPM) tool to continuously validate your cloud configurations against NCA ECC benchmarks and detect drift in real time.
Cloud adoption in Saudi Arabia's financial sector is subject to layered regulatory oversight. The NCA's Cloud Cybersecurity Controls (CCC-1:2020) and SAMA's Cloud Computing Framework establish the primary compliance baseline, while NCA ECC Domain 2-13 addresses cloud-specific cybersecurity requirements.
Critical controls organizations must implement:
- Data Residency & Sovereignty: Government and critical national infrastructure entities are generally required to store sensitive and confidential data within Saudi Arabia. Financial institutions must conduct data classification before migration to determine what can reside offshore versus what must stay local.
- Shared Responsibility Model (CCC-1 Control 3.1): Clearly document and contractually define the division of security responsibilities between the organization and the cloud service provider (CSP). Assume nothing is covered by default.
- Identity & Access Management: Enforce least-privilege access, multi-factor authentication (MFA) for all administrative accounts, and privileged access workstations (PAW) for cloud console access.
- Encryption Standards: Data must be encrypted at rest (AES-256) and in transit (TLS 1.2 minimum). Organizations must retain control of encryption keys — avoid CSP-managed keys for sensitive financial data.
- Security Monitoring & Logging (NCA ECC 2-13-3): Enable cloud-native logging (e.g., AWS CloudTrail, Azure Monitor) and integrate with the organization's SIEM. Log retention must meet SAMA's minimum 12-month online requirement.
- Exit Strategy: Maintain documented cloud exit plans to avoid vendor lock-in and ensure business continuity.
- CSP Assessment: Verify that your cloud provider holds recognized certifications (ISO 27001, CSA STAR, SOC 2) and has completed NCA's CSP assessment process where applicable.
For SAMA-regulated entities, any outsourcing to cloud providers also triggers the Outsourcing Risk Management Guidelines, requiring board-level approval for critical functions.
The NCA ECC (Essential Cybersecurity Controls) sets clear obligations for Saudi organizations planning to adopt cloud services, particularly under Control Domain 3-18 (Cloud Computing and Hosting). These requirements apply to government entities, critical infrastructure operators, and financial institutions supervised by SAMA.
Mandatory pre-migration controls include:
- Cloud Risk Assessment: Conduct a formal risk assessment specific to the target cloud environment. Evaluate the cloud service provider (CSP) against NCA-approved criteria, including data residency (Saudi Arabia or compliant jurisdiction), certifications (ISO 27001, ISO 27017/27018, CSA STAR), and breach notification capabilities.
- Data Classification: Per NCA ECC Control 3-7, classify all data before migration. Highly sensitive or "secret" data may be prohibited from public cloud environments without explicit authorization and compensating controls such as customer-managed encryption keys (CMEK).
- Shared Responsibility Model Documentation: Define and document the security responsibilities between your organization and the CSP. Gaps in coverage — particularly around identity, logging, and incident response — must be addressed before go-live.
- Access Control & Privileged Access: Implement MFA for all cloud management console access, enforce least-privilege IAM policies, and log all privileged actions per NCA ECC Control 3-5.
- Security Monitoring & SIEM Integration: Cloud audit logs (e.g., AWS CloudTrail, Azure Monitor) must feed into your central SIEM to support real-time threat detection and compliance reporting.
- Exit Strategy: NCA ECC requires organizations to maintain the ability to migrate away from a CSP without data loss or prolonged unavailability — document your portability and data retrieval procedures.
For SAMA-regulated entities, the SAMA Cloud Computing Framework supplements these NCA controls with additional financial-sector-specific requirements around outsourcing approval and regulatory notification.
Saudi financial institutions adopting cloud services face dual compliance obligations: SAMA CSF's technology risk management requirements and NCA ECC's cloud security controls (specifically ECC-1:2018 Section 3-14: Cloud Computing Controls). Here is how to build a compliant cloud security framework:
1. Pre-Adoption Risk Assessment: Before migrating any workload, conduct a formal Cloud Risk Assessment per SAMA CSF Control 3.2 (Technology Risk Management). Classify data sensitivity — PDPL 'sensitive personal data,' financial records, and transaction data require elevated protection measures and may restrict which cloud regions are permissible.
2. Data Residency & Sovereignty: NCA ECC mandates that critical national infrastructure data — which includes core banking data — must reside within the Kingdom of Saudi Arabia. Verify your cloud provider offers KSA-region data centers (e.g., AWS Riyadh, Azure KSA) and contractually enforce data residency.
3. Shared Responsibility Model Documentation: Clearly define security responsibilities between your institution and the Cloud Service Provider (CSP). SAMA examiners expect documented evidence of this delineation covering identity management, encryption, logging, and incident response.
4. Encryption Standards: Implement encryption at rest (AES-256) and in transit (TLS 1.2 minimum) for all financial data, consistent with SAMA CSF 3.3.5 and NCA ECC encryption controls. Maintain your own key management using HSM or BYOK models.
5. Continuous Monitoring & SIEM Integration: Cloud workloads must feed security events into your SIEM for real-time anomaly detection. NCA ECC Section 3-10 requires comprehensive logging and monitoring of all access to sensitive systems.
6. Cloud Security Posture Management (CSPM): Deploy automated CSPM tools to continuously audit cloud configurations against CIS Benchmarks, detecting misconfigurations before they become breaches.
7. Exit Strategy: SAMA CSF requires documented exit/migration plans from cloud providers to prevent vendor lock-in risk to operational continuity.
Our vCISO team can perform a cloud readiness gap assessment, map your architecture to SAMA CSF and NCA ECC controls, and deliver a remediation roadmap within weeks.
No matching questions found.
Didn't find what you're looking for?
✉️ Contact Us