Saudi organisations using cloud services need to decide what data goes where. Under the NCA’s ECC-2:2024 the cloud and hosting controls (4-2) are binding on in-scope entities using or planning to use cloud, and data localisation now sits with the NDMO at SDAIA. Microsoft has announced a Saudi Arabia East cloud region from November 2026, and its announcement does not mention Microsoft 365. Good governance settings matter either way.
ECC-2:2024 subdomain 4-2 requires cybersecurity requirements for cloud computing and hosting to be identified, documented, approved and implemented, and to include, as a minimum, protection of your data by the provider in line with its classification level with return of the data in a usable format at the end of service (4-2-3-1), and separation of your environment, especially virtual servers, from other customers’ (4-2-3-2). The requirements must be reviewed periodically.
The NCA’s separate Cloud Cybersecurity Controls (CCC) set minimum requirements for both cloud service providers and their tenants. The NCA’s page shows the current version as CCC-2:2024, updated to reflect changes to data localisation requirements.
ECC-1:2018 contained a sub-control saying an entity’s information hosting and storage must be inside the Kingdom. ECC-2:2024 deleted it. The document states that data localisation controls were transferred to the National Data Management Office (NDMO) at SDAIA, and that entities must refer to the NDMO regarding data localisation before taking any action.
So the question “can this data leave the Kingdom?” is now answered by the NDMO’s requirements, your sector regulator and your contracts, not by ECC alone. Classify your data first. That classification drives every later decision.
Microsoft has announced that its Saudi Arabia East datacenter region will be available in November 2026. It says the region provides local data residency and lets organisations host eligible workloads and data locally in the Kingdom, using “supported Microsoft cloud and AI services”.
The announcement does not list the services, and does not mention Microsoft 365. Do not assume your Microsoft 365 data will be stored in the Kingdom. Ask Microsoft or your licensing partner in writing which of your services will be available in the region, when, and what has to change to use it.
These jobs are the same whether your tenant’s data sits in one region or another. The right-hand column shows the ECC subdomain each supports. This mapping is our own, for orientation.
| Job | What good looks like | ECC subdomain |
|---|---|---|
| Identity | Multi-factor authentication for all users, Conditional Access, no standing global admins, privileged access managed. | 2-2 Identity and access |
| Devices | Managed, encrypted, patched devices; unmanaged devices limited. | 2-3, 2-6, 2-10 |
| Sharing | External sharing controlled, guest access reviewed. | 2-7 Data and information |
| Labels and retention | Sensitivity labels that follow your classification scheme, and retention rules agreed with legal. | 2-7 Data and information |
| Logging | Audit logging on, retained and searchable. | 2-12 Logs and monitoring |
| Backup | Protection for Microsoft 365 data, with restore tests. | 2-9 Backup and recovery |
Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
