Cloud Security
DETAIL

Saudi Arabia SACS-002 — Saudi Arabian Cloud Security Controls Standard

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

Saudi ArabiaSACS-002 — Saudi Arabian Cloud Security Controls Standard is anational cybersecurity framework that helps organizations establishand maintain security controls for cloud computing environments. Itsprimary purpose is to safeguard cloud-hosted data and services,ensuring resilience against cyber threats while supporting compliancewith regulatory requirements.

Issued by theSaudi National Cybersecurity Authority (NCA), SACS-002 applies topublic and private sector entities that provide or utilize cloudservices within Saudi Arabia. The standard covers a broad range ofareas including risk management, data protection, access control,incident response, and monitoring, aligning with both localregulations and leading international security best practices.

Organizationsadopt SACS-002 by integrating its controls into their cloud securityarchitectures, performing regular compliance assessments, andaligning internal policies with its requirements. In practice, theframework supports risk assessments, audit readiness, and ongoingcybersecurity governance, often complementing global standards likeISO 27001 or NIST frameworks.

Why it Matters

SACS-002establishes comprehensive cloud security requirements designed tostrengthen cyber risk management for organizations operating in SaudiArabia.

Key benefitsinclude:

•  Strengthen security governance

Establishesclear accountability and oversight structures for cloud security,ensuring leadership engagement and effective management of controls.

•  Enhance regulatory alignment

Facilitatesadherence to national cloud compliance requirements, supportingorganizations in fulfilling Saudi regulatory and legal obligations.

•  Improve service availability

Reduces risksassociated with cloud outages by requiring robust business continuityand disaster recovery planning across environments.

•  Increase audit readiness

Standardizessecurity documentation and reporting practices, streamliningpreparations for internal and external audits.

•  Protect sensitive information

Implementscontrols to prevent unauthorized access, supporting confidentialityand integrity of personal and business-critical data.

How it Works

The Saudi ArabiaSACS-002 — Saudi Arabian Cloud Security Controls Standard providesa structured set of security controls organized into distinct controlfamilies that address cloud-specific risks and regulatoryrequirements. These control families encompass areas such as dataprotection, access management, governance, incident response,compliance, and physical and environmental safeguards. SACS-002outlines a baseline of mandatory and recommended practices tailoredto align with the Kingdom’s regulatory context, ensuringcomprehensive coverage of security domains relevant to cloudservices.

In practice,organizations implement SACS-002 by mapping its security controls totheir existing governance and compliance frameworks, conducting riskassessments, and establishing processes for ongoing monitoring andincident management. Regular compliance assessments are performed tovalidate adherence to mandated controls, and evidence is collected todemonstrate conformity during audits. Security programs are oftenupdated to reflect changes in the SACS-002 requirements, and keycontrols are integrated into broader organizational risk managementstrategies.

With SmartSuite,organizations streamline operationalization of SACS-002 by leveragingcontrol libraries for efficient mapping, maintaining risk registerslinked to control deficiencies, and centralizing policy governance.Automated evidence collection, compliance tracking, and remediationworkflows support ongoing monitoring activities, while reportingdashboards facilitate audit readiness and governance oversight. Thisenables comprehensive management of security and regulatoryrequirements defined by SACS-002.

Key Elements

•  Cloud Security Classification Levels

Specifiesdistinct levels for classifying cloud data, services, and workloadsbased on sensitivity and risk.

•  Governance and Compliance Framework

Establishescomprehensive domains addressing legal, regulatory, and contractualobligations within cloud environments.

•  Cloud Service Security Controls

Organizesmandated technical and procedural safeguards across network,endpoint, and infrastructure layers.

•  Vendor Management and Outsourcing

Describesrequirements for third-party provider assessment, monitoring, andcontractual compliance.

•  Identity and Access Management Controls

Outlinesmechanisms for verifying users and controlling permissions withincloud services.

•  Incident Response and Reporting

Definesstructured processes for detecting, documenting, and escalating cloudsecurity incidents.

Framework Scope

Saudi ArabianCloud Security Controls Standard (SACS-002) is adopted by cloudservice providers and organizations leveraging cloud environments forprocessing or storing sensitive data within Saudi Arabia. Thestandard governs cloud-based information systems and related assets,and is typically implemented when complying with national regulatorymandates and supporting assurance programs for secure cloud adoption.

Framework Objectives

Saudi ArabiaSACS-002 defines comprehensive security controls to managecybersecurity risks in cloud computing environments.

•  Strengthen risk management and governance for cloud-basedinformation assets

•  Ensure compliance with Saudi Arabian regulatory and legal cloudsecurity requirements

•  Enhance operational resilience through robust security controlsand processes

•  Improve data protection and privacy across cloud platforms andservices

•  Support audit readiness by maintaining comprehensivedocumentation and evidence

•  Promote standardized cybersecurity practices to mitigateemerging threats SACS-002 aligns closely with international standardssuch as ISO 27001, NIST SP 800-53, and CSA Cloud Controls Matrix,integrating Saudi-specific regulatory requirements. Organizationstypically implement SACS-002 to achieve compliance with Saudiregulatory mandates, ensure secure cloud operations, and demonstrateadherence to best practices in cloud security and governance withinthe Kingdom.

Common Framework Mappings

SACS-002 isoften mapped against leading international frameworks to streamlinecompliance, demonstrate best practices, and facilitate cross-borderoperations for organizations with global customers and regulatoryobligations.

Mappedframeworks include:

CIS CriticalSecurity Controls

CSA CloudControls Matrix

GDPR

ISO/IEC 27001

ISO/IEC 27017

ISO/IEC 27018

NISTCybersecurity Framework

NIST SP 800-53

PCI DSS

SOC 2

At a Glance
Saudi Arabian Cloud Security Controls Standard SACS-002
  • checklist
    Classicifation
    Category
    info
    Cloud Security
    Domain
    info
    Cloud Security
    Framework Family
    info
    CSA STAR
  • info
    Regulatory Context
    Type
    info
    Standard
    Legal Instrument
    info
    Standard
    Sector
    info
    Cross-Sector
    Industry
    info
    Cloud & Technology Providers
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Europe
    Region Detail
    info
    Saudi Arabia
    Publisher
    info
    Saudi Aramco
  • published_with_changes
    Versioning
    Version
    info
    February 2022
    Effective Date
    info
    February 2022
    Issue Date
    info
    February 2022
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

The Saudi Arabian Cloud Security Controls Standard (SACS-002) is published by the Saudi National Cybersecurity Authority (NCA) and is publicly available for download from the NCA website. License included with platform

Official Resources
SACS‑002 Third‑Party Cybersecurity Standard
Defines the full set of mandatory cybersecurity controls third parties must implement.
chevron_forward
Third‑Party Cybersecurity Controls Guideline
Provides implementation guidance supporting the SACS‑002 standard controls for vendors.
chevron_forward
SMARTSUITE

How SmartSuite Supports SACS-002

Manage Saudi Arabia Cloud Security Controls Standard (SACS-002) by organizing cloud security requirements, tracking control implementation across environments, and maintaining evidence supporting compliance and risk management.

Cloud Control Framework Library

Structure SACS control domains covering cloud infrastructure, data protection, and service governance.

Cloud Service and Environment Tracking

Track cloud services, environments, and data flows across providers and systems.

Risk Assessment and Control Implementation

Link cloud risks to controls and manage mitigation across cloud deployments.

Cloud Authentication and Access Management

Manage authentication, permissions, and secure configurations across cloud environments.

Monitoring, Logging, and Incident Response

Track cloud security events and manage detection and response workflows.

Cloud Control and Regulatory Readiness Reporting

Provide dashboards showing cloud control coverage, risk posture, and regulatory readiness.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
ISO 27017

ISO/IEC 27017 provides cloud-specific security controls to help organizations protect data and manage cloud-related risks.

Learn More
arrow_forward
ISO 27018

ISO/IEC 27018 provides guidelines for protecting personally identifiable information processed in public cloud services.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For Saudi Arabia SACS-002 (Saudi Arabian Cloud Security Controls Standard)

What is Saudi Arabia SACS-002 used for?

Saudi Arabia SACS-002 provides mandatory cloud security controls for entities that offer or consume cloud services within the Kingdom of Saudi Arabia. It aims to ensure the confidentiality, integrity, and availability of data processed or stored in the cloud, especially for government entities and organizations handling sensitive information.

Is SACS-002 a mandatory requirement in Saudi Arabia?

Yes, SACS-002 is mandatory for government agencies, their affiliated organizations, and entities that process, store, or transmit government data using cloud environments in Saudi Arabia. Compliance is essential to obtain authorization to deliver or utilize cloud services within the country.

What is the scope of SACS-002 and who must comply?

The scope of SACS-002 covers all cloud service providers operating in Saudi Arabia, as well as organizations (public or private) that use cloud solutions to process governmental or regulated data. It applies to IaaS, PaaS, and SaaS models, and organizations must ensure that both technical and organizational measures are in place.

What are the key security controls required by SACS-002?

SACS-002 outlines technical and administrative controls across domains such as data protection, access management, incident response, compliance monitoring, and business continuity. Organizations must implement controls like encryption, secure configuration, identity management, and regular security audits.

How do organizations implement SACS-002 requirements?

Implementation involves conducting a risk assessment, mapping SACS-002 controls to internal processes, and maintaining documentation for governance and technical measures. Continuous monitoring, employee training, and periodic audits are also required to maintain compliance.

How does SACS-002 relate to other international cloud security standards?

SACS-002 incorporates global standards such as ISO/IEC 27017 and 27018 but includes additional requirements relevant to local regulatory and cultural context in Saudi Arabia. Organizations already certified in international frameworks must map and extend their controls to address unique SACS-002 provisions.

What are the ongoing compliance requirements for SACS-002?

Ongoing compliance includes regular control assessments, evidence collection, incident reporting, and responding to government or regulator audits. Organizations must maintain up-to-date documentation and remediate any identified findings or deficiencies in a timely manner.

How would SmartSuite support Saudi Arabia SACS-002?

SmartSuite enables organizations to efficiently manage SACS-002 compliance by tracking risks, mapping and monitoring required controls, collecting and organizing evidence, and maintaining audit readiness. Its reporting features support the generation of compliance status updates and executive summaries to facilitate regulatory communication and continuous improvement.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward