العربية

Guide · Saudi Arabia · 1 October 2026

Selling cyber, cloud or IT services into Saudi Arabia: the three gates a foreign supplier meets first

Most foreign suppliers discover the Saudi rules one contract clause at a time. Here they are in the order you will meet them: registration, the controls your client must pass to you, and where data may go.

The short version

  1. Registration. If you provide cyber security solutions, services or products in the Kingdom, register on the NCA’s Haseen platform. It has been mandatory since 1 August 2022.
  2. Your client’s controls become your contract. Government entities and critical infrastructure operators must apply the Essential Cybersecurity Controls (ECC-2:2024), and the third-party controls oblige them to write those requirements into your contract.
  3. Data. Personal data falls under the Personal Data Protection Law and its transfer regulation. Government data location is set by the National Data Management Office’s rules, and your client will usually require it to stay in the Kingdom.

Gate 1: registration, and what is coming

NCA

Haseen registration

Mandatory since 1 August 2022

Any entity providing cyber security solutions, services or products in the Kingdom must register. Managed SOC licensing runs on top, with Saudi ownership thresholds and a regional headquarters requirement at tier 1. Legal analysis concludes that firms previously delivering in-scope cyber services into the Kingdom from overseas can no longer lawfully do so.

Who signsNo assessment regime; registration then per licence
NCA

Licensing framework for cyber security services

RFCS-1:2026 · draft

Consulted on from 25 February to 26 March 2026. As drafted it covers more than a hundred services, explicitly including consulting and assessments, and would require a Saudi legal entity, with 75% Saudi ownership and SAR 10 million capital to serve government or critical infrastructure, and full in-Kingdom data residency. Not issued when we checked on 1 October 2026.

StatusDraft: plan for it, do not build around it yet

If you run a security operations centre abroad

For clients bound by ECC, control 4-1-3 requires managed security operations centres that use remote access to be fully located in the Kingdom. Remote monitoring from Dubai, London or Bangalore will not meet it, whatever the contract says.

Gate 2: the controls your client must pass to you

ECC-2:2024 applies to government agencies and their affiliated companies, inside and outside the Kingdom, and to private-sector owners, operators and hosts of critical national infrastructure. Its third-party subdomain (4-1) obliges them to put minimum terms in your contract:

  • non-disclosure, and secure removal of the client’s data when the service ends;
  • procedures for telling the client about a cyber security incident;
  • an obligation to apply the client’s own cyber security policies and requirements;
  • for outsourced IT and security services, a cyber security risk assessment before signing.

Cloud and hosting providers also meet the Cloud Cybersecurity Controls (CCC-2:2024), which apply to providers and tenants alike, and the ECC hosting controls (4-2): protection of the client’s data according to its classification, return of data in a usable form at the end of service, and separation from other customers’ environments. Cloud providers operating in the Kingdom should also check CST’s cloud registration guide (Decision 506/1445).

Gate 3: where the data may go

The Personal Data Protection Law has been fully enforceable since 14 September 2024, with fines up to SAR 5 million, doubled for repeat violations. Transfers outside the Kingdom need a lawful basis under SDAIA’s amended transfer regulation (1 September 2024): an adequacy decision, or appropriate safeguards such as SDAIA’s standard contractual clauses, binding common rules or a certificate of accreditation, with a transfer risk assessment in some cases.

ECC-2:2024 dropped the old control requiring hosting in the Kingdom and leaves data location to the National Data Management Office’s rules. In practice, government clients expect their data to stay in the Kingdom. Get the hosting location agreed in writing before you price the work.

Before your first Saudi contract

  • Register on Haseen if any part of what you sell is a cyber security service or product.
  • Ask the client which NCA control sets bind them (ECC, CCC, CSCC, OTCC) and request the clauses they will flow down to you.
  • Confirm that any remote access and monitoring can be delivered from inside the Kingdom.
  • Map every flow of Saudi personal data out of the Kingdom, and choose its transfer basis.
  • Agree hosting location and data return in writing.
  • Track RFCS-1:2026. If it is issued as drafted, foreign-owned providers may need a Saudi entity to serve government or critical infrastructure.

Where we fit

We give suppliers an independent readiness assessment against the controls their Saudi client will flow down, before the client’s own assessment does. We never assess work we have advised on, and we never sell the fix for anything we assess. And if the honest answer is that a licensed in-Kingdom provider must do the work, you will hear it on the call.

Questions we are asked

Do we need a Saudi company to sell cyber security services in the Kingdom?

Not today for registration: Haseen registration is the current requirement for anyone providing cyber security solutions, services or products in the Kingdom. The draft RFCS-1:2026 licensing framework would require a Saudi legal entity, and 75% Saudi ownership and SAR 10 million capital to serve government or critical infrastructure, but it had not been issued when we checked on 1 October 2026.

Can we monitor a Saudi client’s systems from our SOC abroad?

Not for clients bound by the Essential Cybersecurity Controls. Control 4-1-3 of ECC-2:2024 requires managed security operations centres that use remote access to be fully located in the Kingdom.

Can we move Saudi personal data to our home country?

Only on a lawful basis under the Personal Data Protection Law and its transfer regulation: an adequacy decision, or appropriate safeguards such as SDAIA’s standard contractual clauses, binding common rules or certification, with a risk assessment where required.

Does ECC still say data must be hosted in Saudi Arabia?

ECC-2:2024 removed the old in-Kingdom hosting control and leaves data location to the National Data Management Office’s rules. For government work, expect the client to require in-Kingdom hosting and confirm it in writing.

Primary sources

Checked 1 October 2026. SDAIA does not publish directly linkable copies of the Personal Data Protection Law and its transfer regulation on its own domain; see our regulations register. This guide is not legal advice.

Planning a Saudi bid?

Tell us what you sell and who the client is. We will tell you which gates apply before you commit to a price.