Introduction
The Kingdom of Saudi Arabia (KSA) has developed one of the region’s largest and most advanced digital markets, supported by significant investment in digital infrastructure and an increasingly developed regulatory framework. The KSA ranked first globally in the ITU’s 2025 ICT Development Index, which measures universal and effective connectivity across 164 economies, and second globally in the ITU’s 2025 Digital Regulatory Maturity Index, reflecting the development of its regulatory and governance framework for the digital sector.
Cloud computing has become an important part of that development. As adoption has increased across both the public and private sectors, the KSA regulatory framework has moved beyond facilitating cloud market entry towards addressing how cloud services are procured, contracted for and used, how data is treated within cloud environments, and how the maturity of the market itself is assessed.
This chapter considers some of the principal developments shaping the Saudi cloud market, including the evolution of the Communications, Space and Technology Commission (CST)’s cloud regulatory framework, its interaction with the KSA’s data and privacy regime, cybersecurity requirements and the development of the Cloud Computing Special Economic Zone.
Overview of Cloud Computing Framework in the Kingdom
The KSA has a comparatively mature regulatory framework specifically addressing the provision of cloud computing services. The centrepiece of that framework is the Cloud Computing Services Provisioning Regulations (the “Cloud Regulations”), issued by the CST.
The current, fourth version of the Cloud Regulations entered into force on 10 October 2023, together with updated versions of the Guide for Cloud Computing Service Providers and the Registration Guide in the Qualifying Category for Provisioning of Cloud Computing Services.
Registration and qualification of cloud service providers (CSPs)
CST operates a tiered registration framework for CSPs comprising the Qualifying Category and Classes A, B and C, with the applicable category depending on the scope of services and customers the provider intends to serve.
Registration is made through CST’s electronic portal. An applicant must select the appropriate category and submit the information and supporting documents required by CST. Additional requirements apply to CSPs seeking registration under Classes A, B or C, including prescribed certifications and other evidence of eligibility.
For CSPs entering the Saudi market, the registration analysis should therefore be undertaken at an early stage. In particular, a CSP should identify the services it intends to offer, the customers it intends to serve and the entity through which those services will be provided before determining the appropriate registration route. Changes to the provider’s activities may also require it to update its registration or obtain a different category.
Responsibilities of CSPs
The Cloud Regulations impose a number of obligations directly on CSPs, including requirements relating to customer contracts, transparency and disclosure, service changes, customer content, termination and exit arrangements. These requirements apply alongside the parties’ contractual terms and should therefore be reflected in the CSP’s standard terms for Saudi customers.
This is particularly relevant to the standard contracting model of global hyperscale providers. Cloud services are commonly offered internationally on substantially standardised terms, with service descriptions and operational policies incorporated by reference and capable of being updated periodically. Paragraph 3-6 prescribes minimum content for cloud contracts, including the services and permitted uses, fees and termination terms, treatment of subscriber content, applicable SLAs, complaints procedures and governing law. It further provides that the choice of governing law cannot nullify the Cloud Regulations or other mandatory Saudi laws. For an international provider, localisation therefore requires more than inserting a Saudi governing-law clause into its global terms; the contractual package itself must be reviewed against the mandatory Saudi requirements.
Paragraph 3-7 addresses responsibility for agents, subcontractors and employees and limit the extent to which CSPs can contractually exclude liability in specified circumstances. In particular, it provides that a contractual “best endeavours” standard does not exempt a CSP from liability to individual subscribers for intentional acts or omissions or those resulting from gross negligence. It also requires customers to be given an opportunity to retrieve their cloud content following termination.
Therefore, standard liability caps, exclusions, subcontracting provisions and exit terms should be reviewed against these requirements, together with the operational processes used to implement them.
Responsibilities of customers
The Cloud Regulations also place responsibilities on cloud customers. As a practical matter, customers should verify the CSP’s CST registration, confirm that it is appropriate for the proposed service and comply with any requirements applicable to their use of the cloud. Engagement of a CST-registered provider does not relieve the customer of obligations that apply to it under other Saudi laws or sector-specific requirements.
Cloud First and public-sector demand
Saudi Arabia’s Cloud First Policy, introduced by MCIT in 2019, directs government entities to consider cloud solutions when making new technology investments. This approach has since been reinforced by the Digital Government Authority (DGA), through its cloud-adoption programmes, guidance and Digital Transformation Standards.
For CSPs, Cloud First is significant because it creates sustained public-sector demand for cloud services and makes cloud a starting point for many government technology procurements. However, the policy does not displace the regulatory requirements applicable to a particular deployment: providers seeking government work must still ensure that their registration, service offering and contracting model are suitable for the relevant procurement.
The Cloud Computing Maturity Index
On 3 September 2026, CST launched the Cloud Computing Market Maturity Index. The Index applies to CSPs registered with CST and is intended to assess the maturity of their cloud offerings across six principal dimensions: the diversity and comprehensiveness of cloud services; technical expertise and capabilities; customer satisfaction; strategic partnerships; service-delivery efficiency; and sales and marketing. Those six dimensions are further divided into 33 sub-indicators addressing technical, operational and commercial aspects of cloud-service provision.
The inaugural results ranked participating cloud service providers across the assessed categories, with a separate recognition for providers in the small and medium-sized enterprise category.
Although the Index does not, at present, determine whether a CSP may provide a particular service, its practical relevance may extend beyond CST’s market monitoring. Published rankings provide government and private-sector customers with an additional benchmark when evaluating providers and may, over time, influence procurement criteria and competitive positioning within the Saudi cloud market. For CSPs, this means that regulatory engagement is increasingly concerned not only with satisfying the conditions for entry, but also with demonstrating the quality and maturity of the services offered once in the market.
These developments show a Saudi cloud market moving from an initial focus on establishing a regulatory framework towards a more developed model covering market access, adoption and provider performance.
Cloud Computing and Data Privacy
Cloud adoption necessarily involves decisions concerning how data is hosted, processed, accessed, transferred and ultimately returned or disposed of. KSA’s framework in this area operates through several complementary regulatory instruments.
In parallel to the Cloud Regulations, the Saudi Data and AI Authority (SDAIA), including through the National Data Management Office (NDMO), has developed a broader national data-governance framework addressing matters including data classification, data sharing, and data management. The Personal Data Protection Law (PDPL), its Implementing Regulations and the Regulation on Personal Data Transfer outside the Kingdom form a further part of that landscape where cloud workloads involve personal data.
Government data classification
Data classification has a direct bearing on the selection of CSPs under the Saudi cloud framework. Under SDAIA’s Data Classification Policy, government data is classified into four levels according to the nature and sensitivity of the information and the potential impact of unauthorised disclosure: Public, Confidential, Secret and Top Secret. Public Data is information in respect of which unauthorised disclosure would cause no or negligible adverse impact; Confidential, Secret and Top Secret classifications apply progressively where unauthorised disclosure could result in increasingly serious adverse consequences.
The Cloud Regulations then link government cloud services to the CSP’s registration category: Class A is limited to Public Data, Class B extends to Confidential Data, and Class C extends to Secret and Top Secret Data. The Qualifying Category, by contrast, does not extend to government customers.
The practical consequence is that classification of the relevant workload should precede CSP selection.
Personal data and cloud computing
Where cloud workloads contain personal data, the PDPL, its Implementing Regulations and the Regulation on Personal Data Transfer outside the Kingdom impose an additional set of requirements.
Where the customer determines the purposes and means of processing, it will generally remain the controller under the PDPL, with the CSP acting as processor on its behalf.
Article 17 of the PDPL Implementing Regulations is particularly relevant to cloud arrangements. It requires controllers to satisfy themselves as to the processor’s ability to comply with the PDPL and addresses matters that commonly arise in cloud contracts, including the scope and duration of processing, subprocessors and the application of foreign laws. It also requires periodic assessment of the processor’s compliance. These requirements are particularly relevant where a CSP relies on a large or changing network of affiliates and subprocessors, as is common in global cloud service models.
Data location and international transfers
As a general principle, the Cloud Regulations contemplate that subscriber content may be transferred, stored or processed outside the Kingdom. Under Article 3-3-7, a CSP registered with CST must notify its subscribers in advance and obtain their consent where their content will be transferred, stored or processed outside the Kingdom, whether permanently or temporarily.
Where personal data is involved, Article 29 of the PDPL and the Regulation on Personal Data Transfer outside the Kingdom permit personal data to be transferred outside Saudi Arabia where the applicable conditions and safeguards are satisfied. In a cloud context, the relevant analysis turns on the actual processing and access arrangements, rather than the location of the primary cloud infrastructure alone. Hosting data in Saudi Arabia may still give rise to a cross-border transfer where personal data is accessed or processed by overseas affiliates, support teams or subprocessors.
The position is different for Saudi government data. Article 3-3-5 of the Cloud Regulations specifically provides that CSPs and subscribers must not transfer content comprising data of Saudi government agencies outside the Kingdom for any purpose or in any form, whether permanently or temporarily, including for temporary storage or backup, unless such transfer is expressly permitted under another law or regulation in the KSA.
Cloud customers should therefore assess the nature of the relevant data at the outset, as well as the CSP’s data flows, processing locations and access arrangements, in order to determine the applicable restrictions and, where international transfers are permitted, the relevant transfer requirements and safeguards.
Cloud Computing and Cybersecurity
Cybersecurity forms a central part of the regulatory framework governing cloud computing in Saudi Arabia. The National Cybersecurity Authority (NCA), the primary cybersecurity regulator in the Kingdom, has developed a suite of cybersecurity controls that apply according to the nature of the relevant entity, the systems involved and, in the cloud context, the role played by the entity as either a cloud service provider or cloud service customer.
The Essential Cybersecurity Controls
The starting point is the NCA’s Essential Cybersecurity Controls (ECC-2:2024) (ECC). The ECC establish the minimum cybersecurity requirements applicable to government entities in the Kingdom, including their affiliated companies and entities inside and outside Saudi Arabia, as well as private-sector entities that own, operate or host Critical National Infrastructure (CNI). Other entities are encouraged to adopt the ECC as best practice. The ECC include specific controls relating to cloud computing and hosting, which apply to entities within scope that use or intend to use cloud or hosting services.
The Cloud Cybersecurity Controls
For cloud computing specifically, the NCA has issued the Cloud Cybersecurity Controls (CCC-2:2024) (CCC). The CCC were first introduced in 2020 and were updated in 2024 as an extension to the broader NCA cybersecurity framework. They establish cloud-specific minimum requirements from the perspective of both CSPs and Cloud Service Tenants (“Tenant(s)”). The CCC are structured around four principal domains: Cybersecurity Governance, Cybersecurity Defence, Cybersecurity Resilience and Third-Party Cybersecurity. The current framework contains separate control sets for CSPs and Tenants, comprising 37 main controls and 94 sub-controls for CSPs, and 18 main controls and 26 sub-controls for Tenants.
On the Tenant side, the controls apply to government entities and private-sector entities owning, operating or hosting CNI that use, or intend to use, cloud services. The Tenant-specific controls under the CCC operate as an extension of, and complement to, the controls set out in the ECC, such that in-scope Tenants are required to maintain continuous compliance with both frameworks. On the CSP side, the CCC apply to CSPs providing cloud services to those in-scope Tenants. The CSP-specific controls similarly complement the ECC, and CSPs falling within the scope of the CCC are required to maintain continuous compliance with both the ECC and the CCC, regardless of whether they would otherwise fall within the standalone scope of the ECC. The NCA also strongly encourages other entities in KSA that fall outside the mandatory scope of the CCC to leverage the controls as best practice to strengthen their cloud cybersecurity posture.
One of the more notable changes introduced by CCC-2:2024 concerns data localisation. The previous version of the controls contained specific requirements relating to the provision of certain cloud services from within KSA. Those specific sub-controls were removed in the 2024 version. The current CCC therefore no longer constitute the sole basis for determining whether particular data must be hosted or processed within KSA. Data residency must instead be assessed by reference to the wider Saudi legal and regulatory framework, including applicable data-governance, data-protection and sector-specific requirements.
Implementation guidance
The NCA has supplemented the CCC with separate implementation guidance for Tenants and CSPs. In 2023, the NCA issued the Guide to Cloud Cybersecurity Controls – Cloud Service Tenants Implementation (GCCC-CST-1:2023). The guide is intended to assist Tenants in implementing the CCC requirements applicable to them by providing practical guidance against individual controls, together with examples of relevant cybersecurity tools and expected compliance deliverables.
More recently, in 2026, the NCA issued the Guide to Cloud Cybersecurity Controls – Cloud Service Providers Implementation (GCCC-CSP-2:2026). The CSP guide serves a similar purpose from the provider perspective, translating the applicable CCC requirements into practical implementation guidance and identifying the types of evidence and deliverables that may be used to demonstrate compliance. The NCA states more generally that its implementation guides are intended to enable targeted entities to implement the requirements necessary for compliance and to identify the relevant cybersecurity tools developed by the NCA.
Cybersecurity controls for the wider private sector
The wider NCA cybersecurity framework has also expanded beyond the government and CNI perimeter. In December 2025, the NCA introduced the Cybersecurity Controls for Private Sector Entities Without CNI, establishing a separate cybersecurity baseline for private-sector entities that do not own, operate or host CNI. The introduction of these controls is significant because it brings a wider category of private-sector entities within a more structured NCA cybersecurity framework, while preserving the distinction between those entities and government or CNI entities subject to the ECC and, where relevant, the CCC.
The result is therefore a differentiated regulatory structure. Government entities and private-sector entities within the CNI perimeter are subject to the ECC and, where they use cloud services, the applicable CCC requirements. Private-sector entities outside the CNI perimeter are subject to a separate baseline cybersecurity framework. Determining the cybersecurity requirements applicable to a particular cloud arrangement therefore requires an assessment of the status of the CST, the nature of the systems involved and the scope of the cloud service being provided.
Sector-specific requirements
The NCA framework does not operate in isolation. Entities operating in regulated sectors may be subject to additional cybersecurity and outsourcing requirements imposed by their sector regulator. A prominent example is the Saudi Central Bank (SAMA) Cyber Security Framework, which contains specific requirements governing the use of hybrid and public cloud services by entities within its scope. Before adopting a cloud service, the relevant institution must undertake a cybersecurity risk assessment and due diligence on the proposed CSP and its services. SAMA approval must also be obtained before the institution uses the cloud service or enters into the relevant cloud contract.
Accordingly, the cybersecurity analysis for cloud services in KSA is increasingly entity-specific. The applicable requirements may arise from the NCA’s general and cloud-specific controls, from newer cybersecurity requirements applying to the wider private sector, and from additional sector-specific rules imposed by regulators such as SAMA. Cloud providers and customers must therefore identify the relevant regulatory perimeter at the outset of the arrangement rather than assuming that compliance with a single national cybersecurity framework is sufficient.
Cloud Computing Special Economic Zone
Perhaps one of the most notable recent developments in KSA’s cloud computing landscape is the establishment of a dedicated Special Economic Zone (SEZ) for Cloud Computing and Information Technology (“Cloud Computing SEZ”). The zone is one of four special economic zones created pursuant to Cabinet Resolution No 233 of 1444H (2022), alongside Jazan, Ras Al-Khair, and King Abdullah Economic City. However, 2026 has been the year in which the regulatory architecture for the Cloud Computing SEZ has truly taken shape.
Governance and licensing
The Cloud Computing SEZ is supervised by the CST in co-ordination with the Royal Commission for Riyadh City, under the overall governance of the Economic Cities and Special Economic Zones Authority (ECZA). The CST serves as the sole licensing authority and is exclusively responsible for issuing the licences, permits, and approvals that entities need to operate within such SEZ.
A developing regulatory framework
In January 2026, the Council of Ministers approved the regulatory frameworks for the Cloud Computing and Information Technology SEZ, pursuant to Cabinet Resolution No 468 dated 10/7/1447H. The approval formed part of a broader effort to kickstart the SEZ regime and establish a distinct legal framework for entities licensed to operate within those zones.
The regulatory framework has continued to develop since then. In April 2026, ECZA published a separate draft regulation for the Cloud Computing SEZ for public consultation. The draft is intended to regulate the management and operation of the zone in greater detail and to tailor the applicable framework to the particular characteristics of cloud computing and information technology activities.
Corporate and registration framework
In July 2026, separate rules were issued governing companies established in SEZs, together with corresponding rules on the companies register and trade names. Under these rules, companies established in a Cloud Computing SEZ must take the form of a limited liability company and are treated as Saudi companies with their headquarters in the SEZ. The framework also permits Saudi, GCC and foreign companies to register branches in the SEZ. ECZA maintains a dedicated electronic companies register, separate from the Ministry of Commerce’s commercial register, while trade names may be registered in Arabic, English or another language and must include the designation “SEZ” or its Arabic equivalent.
Economic substance and incentives
These measures were supplemented in August 2026 by the issuance of the Economic Substance Requirements Regulations for Special Economic Zones, which require qualifying entities to maintain an appropriate level of substantive activity in the relevant zone, including adequate premises and assets, personnel and operating expenditure. The requirements are intended to ensure that entities benefiting from the SEZ regime maintain a genuine operational presence rather than merely establishing a formal legal presence in the zone.
This is particularly relevant given that the Cloud Computing SEZ is intended to offer a more favourable operating environment for qualifying cloud businesses. ECZA identifies, among the incentives associated with the zone, special tax treatment designed, in line with OECD principles, to avoid double taxation and accommodate CSP operating models, together with exemptions from expatriate levies for employees and their families and preferential network connectivity and electricity pricing.
Implications for cloud providers
For cloud providers, the significance of the emerging framework is therefore twofold. It offers a more tailored corporate, regulatory and fiscal environment for establishing cloud operations in the Kingdom, while at the same time imposing its own establishment, licensing and substance requirements. The framework is, however, still developing. In particular, the detailed regulation governing the management and operation of the Cloud Computing SEZ remains in draft form. Its finalisation will be important in determining how the special regime interacts with KSA’s wider cloud, cybersecurity, data protection and sector-specific regulatory requirements.
Offices number 9-10-11
Home Offices Complex
PO Box 245555
Riyadh 11312
Saudi Arabia
+966 11 484 4448
+966 11 281 6611
mail@aldhabaan.eversheds.com www.eversheds-sutherland.com/en/saudi-arabia/locations/offices/riyadh