NCA ECC
The essential controls that CCC extends.
NCA ECCCompliance service
Limaz scopes cloud services, clarifies provider and tenant responsibilities, designs and implements applicable controls, builds evidence, and closes priority gaps against CCC 2-2024.
CCC 2-2024 addresses cloud cybersecurity from the perspective of both cloud service providers and cloud service tenants. The responsibilities are related, but they are not interchangeable.
Start with your role, the services in scope, and how responsibilities divide across your organization, the provider, and other parties.
01
Map cloud services, data, providers, tenants, and applicable NCA requirements.
02
Make every shared control explicit across provider and tenant teams.
03
Translate requirements into architecture, configuration, process, and ownership.
04
Connect policies and controls to current, reviewable proof.
05
Prioritize remediation by risk, dependency, and implementation effort.
The essential controls that CCC extends.
NCA ECCAssessment, evidence, and remediation delivery.
Compliance and assuranceIdentity, privileged access, DevSecOps, logging, and technical controls.
Security engineeringIt is the National Cybersecurity Authority's current Cloud Cybersecurity Controls framework for cloud service providers and cloud service tenants. It extends NCA ECC for cloud computing.
Limaz assesses, designs, implements and validates the controls. The NCA is the competent authority for the framework itself.
Last reviewed: Sep 12, 2026
Tell us which system, control, or requirement you are working on. We’ll review the scope and suggest the next step.