Insights · Cloud and Microsoft 365

Microsoft 365 and cloud governance for Saudi organisations

What the NCA’s cloud controls say, where data localisation now sits, what Microsoft has announced for Saudi Arabia and the Microsoft 365 settings to keep.
The short answer

Saudi organisations using cloud services need to decide what data goes where. Under the NCA’s ECC-2:2024 the cloud and hosting controls (4-2) are binding on in-scope entities using or planning to use cloud, and data localisation now sits with the NDMO at SDAIA. Microsoft has announced a Saudi Arabia East cloud region from November 2026, and its announcement does not mention Microsoft 365. Good governance settings matter either way.

Key points
  • ECC-2:2024 subdomain 4-2 (cloud computing and hosting) is binding on in-scope entities that use, or plan to use, cloud services.
  • The in-Kingdom hosting sub-control was deleted from ECC-2:2024. The document refers data localisation questions to the NDMO at SDAIA.
  • Microsoft says its Saudi Arabia East region will be available in November 2026, letting customers host eligible workloads and data locally. Its announcement does not say which services are included, and does not mention Microsoft 365.
  • Get written confirmation from Microsoft or your reseller of what will be available, and when, before you commit.
  • Identity, devices, sharing, labels, retention and logging are the same governance jobs wherever the data is stored.

What the NCA’s cloud rules say

ECC-2:2024 subdomain 4-2 requires cybersecurity requirements for cloud computing and hosting to be identified, documented, approved and implemented, and to include, as a minimum, protection of your data by the provider in line with its classification level with return of the data in a usable format at the end of service (4-2-3-1), and separation of your environment, especially virtual servers, from other customers’ (4-2-3-2). The requirements must be reviewed periodically.

The NCA’s separate Cloud Cybersecurity Controls (CCC) set minimum requirements for both cloud service providers and their tenants. The NCA’s page shows the current version as CCC-2:2024, updated to reflect changes to data localisation requirements.

Data localisation now sits with the NDMO

ECC-1:2018 contained a sub-control saying an entity’s information hosting and storage must be inside the Kingdom. ECC-2:2024 deleted it. The document states that data localisation controls were transferred to the National Data Management Office (NDMO) at SDAIA, and that entities must refer to the NDMO regarding data localisation before taking any action.

So the question “can this data leave the Kingdom?” is now answered by the NDMO’s requirements, your sector regulator and your contracts, not by ECC alone. Classify your data first. That classification drives every later decision.

What Microsoft has announced

Microsoft has announced that its Saudi Arabia East datacenter region will be available in November 2026. It says the region provides local data residency and lets organisations host eligible workloads and data locally in the Kingdom, using “supported Microsoft cloud and AI services”.

The announcement does not list the services, and does not mention Microsoft 365. Do not assume your Microsoft 365 data will be stored in the Kingdom. Ask Microsoft or your licensing partner in writing which of your services will be available in the region, when, and what has to change to use it.

A Microsoft 365 governance baseline

These jobs are the same whether your tenant’s data sits in one region or another. The right-hand column shows the ECC subdomain each supports. This mapping is our own, for orientation.

JobWhat good looks likeECC subdomain
IdentityMulti-factor authentication for all users, Conditional Access, no standing global admins, privileged access managed.2-2 Identity and access
DevicesManaged, encrypted, patched devices; unmanaged devices limited.2-3, 2-6, 2-10
SharingExternal sharing controlled, guest access reviewed.2-7 Data and information
Labels and retentionSensitivity labels that follow your classification scheme, and retention rules agreed with legal.2-7 Data and information
LoggingAudit logging on, retained and searchable.2-12 Logs and monitoring
BackupProtection for Microsoft 365 data, with restore tests.2-9 Backup and recovery

Sources and further reading

Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Does ECC require us to keep data in Saudi Arabia?

ECC-2:2024 no longer contains the sub-control that said so. It refers data localisation to the NDMO at SDAIA. Check the NDMO’s requirements, your sector regulator and your contracts.

When will Microsoft’s Saudi Arabia East region be available?

Microsoft says November 2026. Its announcement does not say which services will be included, and does not mention Microsoft 365.

Are the NCA cloud controls mandatory?

ECC-2:2024’s cloud subdomain 4-2 is binding on in-scope entities that use or plan to use cloud services. The separate CCC covers both providers and tenants.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
NCA ECC

NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence

A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
6 min read · Reviewed 20 September 2026
PDPL

Saudi PDPL: an IT checklist for the Personal Data Protection Law

What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
4 min read · Reviewed 20 September 2026
Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.