Press TechRound interviews Secure.com CEO on the future of AI security
Read

Data Residency and the ECC: What Control 4-1-3-2 Means for Your Cloud and MSP Contracts

NCA ECC Control 4-1-3-2 requires Saudi data residency for managed security. See what it means for your cloud and MSP contracts today.

TL;DR

The NCA ECC has one rule that catches many teams off guard. Control 4-1-3-2 says any managed cybersecurity center that watches your systems through remote access must sit inside Saudi Arabia. If your SOC provider runs monitoring from Dubai, London, or Bangalore, your contract may put you out of compliance. This post breaks down what the control says, who it hits, and how to check your vendor agreements before an auditor does.

Introduction

Picture this. Your team signs a slick managed detection deal. The provider is well known. The price is right. Six months later, an NCA auditor asks one question: where is the operations center that monitors our network? The answer is Dubai. That single fact turns a working setup into an audit finding.

NCA ECC 2-2024  ·  Domain 4
Where Does Your Security Data Live?
One ECC control decides whether your managed security contract passes a Saudi audit.

The Control
4-1-3-2

Cybersecurity managed service centers for monitoring and operations that use remote access must be fully located inside the Kingdom of Saudi Arabia.

The same setup, two outcomes
Audit finding
Monitored from Dubai
A remote SOC outside the Kingdom breaks Control 4-1-3-2 for entities in scope.
Compliant
Monitored inside KSA
Monitoring delivered from within Saudi Arabia, named in the contract, with proof on file.
Check your contract before an auditor does
  • Where is the operations center that monitors our systems physically located?
  • Do any remote monitoring consoles connect from outside Saudi Arabia?
  • Does the contract name the country where monitoring is delivered?
  • Are subcontractors or overflow teams based in other regions?
  • Does the agreement bind the provider to apply our ECC controls?
Who this applies to: Saudi government entities and their affiliates, plus private operators of Critical National Infrastructure in the Kingdom. Other private firms are urged to adopt the ECC as a baseline. Teams that deploy tools in house rather than buying managed monitoring should confirm applicability with their compliance function.

Why Data Residency Is Suddenly Everyone’s Problem

Saudi Arabia treats cybersecurity as a national priority, not a checkbox. The National Cybersecurity Authority runs the Essential Cybersecurity Controls, and compliance is backed by Royal Decree for entities in scope. That means where your security data lives is now a legal question, not just a technical one.

What Control 4-1-3-2 Actually Says

Control 4-1-3-2 requires that cybersecurity managed service centers for monitoring and operations that use remote access be fully located within the Kingdom of Saudi Arabia. In plain terms, if a third party watches your systems from a remote console, that console and the team behind it must be inside the country. This sits under Domain 4, which covers third party and cloud cybersecurity.

Who This Rule Applies To

The ECC is mandatory for all Saudi government entities and their affiliates, and for any private company that owns, operates, or hosts Critical National Infrastructure in the Kingdom. Other private firms are strongly encouraged to follow it as a baseline. If you outsource monitoring and you fall in scope, this control is yours to prove.

The MSP Trap Hiding in Your Contract

Most managed security contracts were written for a global delivery model. That model runs monitoring from wherever talent is cheapest. Control 4-1-3-2 breaks that model for Saudi entities. Your provider’s follow the sun SOC, spread across time zones, becomes the exact thing the control forbids for remote monitoring.

Where the Cloud Piece Fits

Control 4-1 sits right above this and governs third party requirements more broadly. It says outside providers must apply your cybersecurity policies through contract. So the residency rule does not stand alone. It rides on top of a wider duty to bind vendors to ECC expectations in writing, before the work starts.

How to Check Your Contracts Before an Audit Does

You do not need a full audit to spot the gap. You need to ask a few pointed questions and read the fine print. Start with the location of the people and consoles doing the watching.

Ask these questions

Run each active managed security contract through this short list.

  • Where is the operations center that monitors our systems physically located?
  • Do any remote monitoring consoles connect from outside Saudi Arabia?
  • Does the contract name the country where monitoring is delivered?
  • Are subcontractors or overflow teams based in other regions?
  • Does the agreement bind the provider to apply our ECC controls?

Fix the Gap Without Ripping Everything Out

A residency gap does not always mean a new vendor. Sometimes it means the provider stands up a local operations center, or moves your account to one they already run in the Kingdom. Put the residency requirement in the contract, name the country, and ask for proof. Get it in writing so your audit file has an answer ready.

How Secure.com Helps

Secure.com gives you a Compliance Teammate that maps your setup to the frameworks that apply, so residency gaps surface before an auditor finds them.

  • Maps your organization to the regulations and controls that apply to your sector and region
  • Flags gaps between your current controls and framework requirements, then tracks them to close
  • Links each compliance gap to your risk register so the highest risk items get fixed first
  • Builds an audit ready trail of evidence for review
  • Watches for recurring gaps across audits so the same finding does not come back