Do we need a Saudi company to sell cyber security services in the Kingdom?
Not today for registration: Haseen registration is the current requirement for anyone providing cyber security solutions, services or products in the Kingdom. The draft RFCS-1:2026 licensing framework would require a Saudi legal entity, and 75% Saudi ownership and SAR 10 million capital to serve government or critical infrastructure, but it had not been issued when we checked on 1 October 2026.
Can we monitor a Saudi client’s systems from our SOC abroad?
Not for clients bound by the Essential Cybersecurity Controls. Control 4-1-3 of ECC-2:2024 requires managed security operations centres that use remote access to be fully located in the Kingdom.
Can we move Saudi personal data to our home country?
Only on a lawful basis under the Personal Data Protection Law and its transfer regulation: an adequacy decision, or appropriate safeguards such as SDAIA’s standard contractual clauses, binding common rules or certification, with a risk assessment where required.
Does ECC still say data must be hosted in Saudi Arabia?
ECC-2:2024 removed the old in-Kingdom hosting control and leaves data location to the National Data Management Office’s rules. For government work, expect the client to require in-Kingdom hosting and confirm it in writing.