Start with your organization’s role and any NCA notification. Government and Critical National Infrastructure entities fall within the ECC scope. NCNICC-1:2025, published on 28 December 2025, covers non-CNI small, medium and large private entities notified by NCA. Your size alone does not establish that a notice or compliance deadline applies.[S1]
Which bucket are you in?
Not sure which apply to you? → Take the 2-minute "Am I compliant?" check.
Check whether you are a government entity or own, operate or host CNI. CCC covers government and CNI cloud tenants and providers serving those tenants; other entities are encouraged to use it. A sector label alone does not establish CNI status.[S2]
The current Arabic NCNICC text makes its mandatory scope conditional on NCA notification. It distinguishes large entities (Category A) from small and medium entities (Category B), with reference to Monsha’at definitions. Check the notice, size classification and applicable timetable before declaring a company in scope.[S1]
NCNICC addresses governance, cybersecurity defense and third parties, with requirements varying by category. For cloud providers in CCC scope, NCA now publishes the GCCC-CSP-2:2026 implementation guide, which explains implementation and expected evidence for CCC-2:2024. The guide supports the existing controls; it does not replace them.[S3]
NCA governs cybersecurity; PDPL governs personal data. Assess each regime separately for your organization and processing activities. CCC-2:2024 removed two provider localization controls and refers localization decisions to NDMO. This does not authorize offshore hosting: PDPL transfer requirements, data classification and sector rules still need assessment.