Consider the IT Infrastructure Manager at a mid-market Riyadh trading and logistics group. The board approved a data center consolidation budget after two costly on-prem outages last year. The mandate is to move core systems to the cloud within nine months. What is not yet clear is which of the group's workloads must legally stay inside Saudi Arabia.
VLink is a global IT services company. It helps CIOs, IT infrastructure managers, and compliance leaders move Saudi workloads from on-premises infrastructure to compliant cloud environments. VLink's relevant practices include cloud migration, DevOps and infrastructure management, and IT staff augmentation. Delivery teams support Saudi engagements across banking, healthcare, government, and logistics.
Cloud migration in Saudi Arabia is not a generic lift-and-shift exercise. CST's cloud regulations and in-Kingdom hosting rules shape which workloads can move where. Sector-specific compliance from SAMA and the NCA adds further constraints. This guide sets out the regulations, the provider options, and a step-by-step migration framework built for the Saudi regulatory environment. Enterprises running workloads across the Gulf can compare it with the equivalent guide to cloud migration services in the UAE, where a different residency regime applies.
Why Are Saudi Enterprises Moving From On-Prem to Cloud in 2026?
Saudi Arabia's cloud computing market is growing fast. MarketsandMarkets' Saudi Arabia Cloud Computing Market Report 2025-2030 values it at $5,069.5 million in 2025. It projects growth to $14,608.9 million by 2030, a 23.6% compound annual growth rate. Mordor Intelligence's KSA Cloud Computing Market report puts the figure higher. It cites $15.39 billion in 2025, rising to $27.93 billion by 2030 at a 12.66% CAGR. The gap reflects differing market scope, not disagreement on direction.

Saudi Arabia Cloud Computing Market Size — Two Independent Estimates
| Research Firm | 2025 Market Size | 2030 Projected Size | CAGR |
| MarketsandMarkets | $5,069.5 million | $14,608.9 million | 23.6% |
| Mordor Intelligence | $15.39 billion | $27.93 billion | 12.66% |
Three forces are driving this growth. Aging on-prem infrastructure carries rising operating costs. Vision 2030's digital transformation mandate pushes both government and private enterprises toward modern platforms. CST's own Cloud First Policy directs government entities to evaluate cloud before any new on-prem investment. Hyperscaler capital spending in-Kingdom is compounding all three.
What this means for an IT Infrastructure Manager in that position: the case for keeping aging hardware gets weaker every quarter. The harder question is not whether to move, but which workloads can legally move where.
How Does Vision 2030's Cloud First Policy Shape Migration Timelines?
Saudi Arabia's Cloud First Policy predates most enterprise cloud strategies in the region. CITC, CST's predecessor, introduced the policy in 2020. It directs government entities to evaluate cloud options before approving any new on-prem infrastructure investment.
The policy does not bind private enterprises directly. It shapes their environment in two ways. First, government cloud-first spending accelerates hyperscaler investment in-Kingdom. That is why Oracle, Microsoft, Google, and AWS have all committed capital to Saudi regions. Second, government suppliers and contractors increasingly face de facto cloud requirements to remain eligible for public-sector contracts.
What this means for a Government Digital Transformation Director: cloud migration is not optional infrastructure modernization anymore. It is a prerequisite for staying eligible on public-sector procurement lists.
What Are Saudi Arabia's CST Cloud Regulations, and Do They Apply to You?
The Communications, Space & Technology Commission (CST), formerly CITC, governs cloud computing in Saudi Arabia. It does so through its Cloud Computing Regulatory Framework (CCRF). Any provider that controls a data center or critical infrastructure used to deliver cloud services must register with CST.
CST classifies registered providers into four categories: Qualification, Class A, Class B, and Class C. Each category determines which subscriber data classification a provider may legally handle. The CCRF also defines four cloud data levels, Level 1 through Level 4. These align with the National Data Management Office's (NDMO) classification scheme.

CST Cloud Data Levels and In-Kingdom Hosting Requirements
| Level | NDMO Classification | Typical Data | Hosting Requirement |
| Level 1 | Public | Marketing content, public disclosures | No residency restriction |
| Level 2 | Internal / Restricted | Internal operations, non-sensitive business data | No mandatory in-Kingdom requirement |
| Level 3 | Confidential / Secret | Sensitive government and regulated-sector data | Must be hosted in-Kingdom by a CST-licensed provider |
| Level 4 | Top Secret / Critical | National security and critical infrastructure data | Must be hosted in-Kingdom, highest control tier |
This is not a paperwork exercise enterprise can defer. CST enforcement applies to both the cloud provider and the enterprise customer. Choosing a wrongly categorized provider for Level 3 or Level 4 data creates direct regulatory exposure. That exposure lands on the enterprise, not just the vendor.
CST Cloud Provider Registration Categories
| Category | What It Permits |
| Qualification | Entry-level registration; permits handling of Level 1 and Level 2 data only |
| Class A | Permits handling of data up to Level 3, including confidential sector data |
| Class B | Permits handling of data up to Level 3, with additional sector-specific authorizations |
| Class C | Highest tier; permits handling of Level 4 data, including top-secret and critical infrastructure |
A provider's category is not optional paperwork to skim past during procurement. Ask for the specific registration category in writing, not just a general CST-compliance claim, before signing any hosting agreement.
Which Data Must Stay In-Kingdom Under Saudi Cloud Regulations?
Government sector data faces the strictest rule in Saudi cloud regulation. No data belonging to a Saudi public sector entity may leave the Kingdom for any purpose, permanent or temporary. That includes caching, backup, and disaster recovery replication, unless a specific law expressly allows it.
Private-sector enterprises face a narrower but still material set of rules. Financial institutions, healthcare providers, and telecom operators each carry sector-specific residency obligations. These layer on top of the CST baseline, covered in the next section.
What this means for a Compliance & Risk Manager: do not assume a hyperscaler's regional presence alone satisfies in-Kingdom hosting. Confirm the specific data center, the provider's CST registration category, and whether backups or logs ever leave the Kingdom.
The National Data Management Office sits behind these rules as the classification authority. NDMO's national data classification policy defines the levels CST's cloud framework then applies to hosting decisions. Classify data against NDMO's policy directly, rather than guessing at CST's summary levels. That approach produces a more defensible audit trail.
Which Cloud Providers Operate In-Kingdom in Saudi Arabia?
Three categories of provider serve the Saudi market. These are global hyperscalers with in-Kingdom regions, telecom-backed cloud subsidiaries, and specialist sovereign cloud providers. Their in-Kingdom maturity varies significantly.

Cloud Provider Options in Saudi Arabia, 2026
| Provider | In-Kingdom Status | Best Fit |
| Oracle Cloud | Live: Jeddah (since 2020) and Riyadh (since October 2024), part of a $1.5B Saudi investment | Enterprises needing the longest-established in-Kingdom hyperscaler track record |
| Microsoft Azure | Saudi Arabia East region confirmed February 2026; workloads available from Q4 2026 | Enterprises planning ahead for SAMA and NCA CCC-2 aligned Azure workloads |
| Google Cloud | Live region in Dammam | Enterprises prioritizing AI and data analytics workloads (BigQuery, Vertex AI) |
| AWS | Region committed with $5.3B investment and three Availability Zones; not yet generally available as of mid-2026 | Enterprises able to wait for GA, or using AWS from a nearby region in the interim |
| stc Cloud (sccc by stc) | Live, in-Kingdom data centers, 100+ local cloud products | Enterprises already integrated with stc's telecom and managed-network services |
| Mobily Cloud | Live, in-Kingdom data centers via Etihad Etisalat | Enterprises inside Mobily's telecom network |
Oracle's head start matters for enterprises on a near-term timeline. Microsoft's confirmed Q4 2026 availability changes the calculus for enterprises planning a 2027 migration. Saudi Arabia's Minister of Communications and Information Technology called the Azure region a milestone. It builds "advanced, trusted AI infrastructure" for the Kingdom, he said in a February 2026 statement.
Physical region choice affects latency, not just compliance. Oracle operates in both Jeddah and Riyadh. Google's region sits in Dammam, and Microsoft's planned region sits in the Eastern Province. Each sits closer to different population and industry centers. A Riyadh-headquartered bank and a Jeddah-based logistics firm may reasonably choose different primary regions for the same workload type.
What Do Banking, Healthcare, and Government Rules Add on Top of CST?
CST sets the cloud provider baseline. Regulated sectors then layer their own requirements on top. Each sector's regulator can override CST's baseline with stricter terms.
Sector-Specific Cloud Compliance in Saudi Arabia
| Sector | Regulator | Key Requirement Beyond CST Baseline |
| Banking & Finance | SAMA (Saudi Central Bank) | Primary copies of sensitive data, including PII, transaction history, and core banking configs, must stay in-Kingdom |
| Healthcare | MOH / SFDA | Patient records and clinical data hosting must meet Ministry of Health data protection standards |
| Government & Critical Infrastructure | NCA (National Cybersecurity Authority) | Cloud Cybersecurity Controls (CCC-2:2024) apply on top of the 114-control Essential Cybersecurity Controls baseline |
| Telecom | CST | Cloud infrastructure regulations apply directly to telecom-operated cloud subsidiaries |
The NCA's CCC framework carries an unusual staffing requirement. All cybersecurity roles at in-scope organizations must now be filled by Saudi nationals. That rule now covers all roles, not just senior positions, under the latest control update. This affects which delivery partners can staff a compliant migration team.
SAMA's rules go further than a simple in-Kingdom mandate for banks. Cross-border data sharing is not banned outright, but it must be justified by a legitimate business need. It also requires encryption, access controls, and an immutable audit trail. A bank cannot simply claim a business justification without documenting it.
Healthcare carries a narrower but still binding rule. Patient records and clinical data hosted in the cloud must meet Ministry of Health data protection standards. Confirm SFDA alignment for any medical device data pipeline too. Do not stop the compliance review at the core patient record system.
A note from VLink's VP of Strategy. "A Saudi client once told us their chosen provider had a Saudi presence, so in-Kingdom hosting was covered. It was not. The provider's regional office handled sales, but the workload itself ran outside the Kingdom. We spent the first two weeks verifying data center locations and CST categories, before writing a migration plan."
What Does a CST-Compliant Migration Roadmap Look Like?
A Saudi cloud migration needs a compliance gate at every phase, not just a technical one. The standard 6Rs migration framework still applies, but each workload must also clear a data-residency check before it moves.

- Assessment: Classify every workload against CST's four data levels and confirm which sector regulator applies.
- Planning: Match each workload's data level to a CST-licensed provider category and select a 6Rs strategy (rehost, replatform, refactor, repurchase, retire, or retain).
- Execution: Migrate in phases, starting with Level 1 and Level 2 workloads before tackling Level 3 and Level 4 systems.
- Optimization: Validate in-Kingdom hosting for backups, logs, and disaster recovery, not just primary workloads.
Most Saudi migration failures trace back to skipping the classification step. Enterprises that start with a technical 6Rs assessment often skip data residency first. They then discover mid-migration that a chosen provider cannot legally host a given workload.
The Assessment phase is where most of the real work happens. It is not a quick inventory spreadsheet. Every application, database, and integration needs a data-level tag before anyone touches a migration tool. Cloud Architects should involve compliance and legal early, not after a provider shortlist exists.
Planning benefits from running in parallel with vendor conversations, not after them. Ask each shortlisted provider for their exact CST category and the physical location of their data center in writing. Verbal assurances from a sales team are not sufficient evidence for an audit. If the partner shortlist is still forming, the category guide to IT companies in Dubai maps how consultancies, integrators, and managed services providers differ across the region.
Execution should never treat all workloads as equal-risk. A Level 1 marketing website and a Level 3 core banking database do not belong in the same migration wave. Sequencing lower-risk workloads first also gives the migration team a chance to validate its own process before the stakes rise.
Optimization is the phase enterprises most often skip entirely. A successful cutover is not the finish line. Backup locations, log retention, and disaster recovery targets need the same data-level scrutiny the primary workload received during planning.
What Do the 6Rs Mean in a Saudi Regulatory Context?
The 6Rs migration framework is well established globally. In Saudi Arabia, each strategy carries a regulatory implication most global guides skip.
The 6Rs Migration Framework, Adapted for Saudi Regulatory Constraints
| Strategy | What It Means | Saudi-Specific Note |
| Rehost | Lift-and-shift a workload to cloud infrastructure with minimal change | Fastest option for Level 1 or Level 2 data; verify hosting location for Level 3 or higher |
| Replatform | Make targeted optimizations without a full rearchitecture | Common for workloads moving to a CST-licensed in-Kingdom region |
| Refactor | Rebuild the application for cloud-native architecture | Best for workloads needing tighter integration with NCA CCC controls |
| Repurchase | Replace the workload with a SaaS equivalent | Confirm the SaaS vendor's own CST registration before adoption |
| Retire | Decommission the workload entirely | Reduces the compliance surface area enterprises must manage |
| Retain | Keep the workload on-premises for now | Often the right call for Level 4 data pending a licensed provider match |
Most Saudi enterprises end up running four or five of these strategies at once, not one. A single-strategy migration plan is usually a sign the classification step was skipped.
What Does On-Prem to Cloud Migration Cost in Saudi Arabia?
Migration cost in Saudi Arabia depends more on data classification than on workload size. A Level 1 or Level 2 workload can move to any registered provider. A Level 3 or Level 4 workload narrows the field to CST-licensed, in-Kingdom-hosted options. Those options typically carry a premium over globally available capacity.
Migration Cost Benchmark by Phase (KSA Enterprise Projects)
| Phase | Typical Cost Range | Typical Duration |
| Assessment & data classification | $15,000 - $60,000 | 3-6 weeks |
| Migration planning & CST provider mapping | $20,000 - $80,000 | 2-4 weeks |
| Execution (mid-size enterprise, multi-workload) | $100,000 - $600,000+ | 3-9 months |
| Optimization & compliance validation | $15,000 - $50,000 | Ongoing, first 90 days critical |
These ranges reflect engagement patterns reviewed for this guide, not a quote from a single vendor. Sovereign cloud spending is climbing region-wide, which affects vendor pricing power. Gartner forecasts worldwide sovereign cloud IaaS spending will reach $80 billion in 2026, up 35.6% from 2025. The Middle East and Africa region is projected to grow 89% in 2026, the fastest of any region measured. Governments remain the largest sovereign cloud buyers, followed by regulated industries and infrastructure operators in energy, utilities, and telecommunications.
A Gartner senior director analyst framed the shift in a February 2026 statement. "As geopolitical tensions rise, organizations outside the US and China are investing more in sovereign cloud IaaS," he said. The investment, he added, is aimed at digital and technological independence.
How Does VLink Help Saudi Enterprises Migrate Under CST Compliance?
VLink's cloud migration practice has supported enterprise and mid-market clients through data center consolidation, hybrid cloud architecture, and regulated-sector migrations. VLink's delivery teams work within the compliance frameworks governing CST, SAMA, and NCA CCC requirements. Delivery teams pair migration work with the DevOps and staff augmentation capacity most Saudi migrations also need.
For enterprises still classifying workloads, VLink's cloud migration services cover data-level classification, provider mapping, and phased execution from day one. Where a migration needs ongoing pipeline automation, VLink's DevOps consulting services build the CI/CD infrastructure to support it. Where internal teams need embedded migration or compliance capacity, VLink's IT staff augmentation services supply it directly. Where new application logic is required during a re-architecture, VLink's custom software development practice builds and integrates it.
To commission a CST-aligned cloud migration readiness assessment for your organization, engage VLink's advisory team.
In Summary
Cloud migration in Saudi Arabia succeeds or stalls on regulatory classification, not technical readiness. Classify every workload against CST's four data levels before choosing a provider. That single step avoids the costly mid-migration surprises that stall projects elsewhere.
- Saudi Arabia's cloud market is projected to reach $14.6 billion by 2030, up from $5.07 billion in 2025, per MarketsandMarkets.
- CST's four cloud data levels determine hosting requirements — Level 3 and Level 4 data must stay in-Kingdom with a CST-licensed provider.
- Government data cannot leave Saudi Arabia for any purpose without express legal permission.
- Oracle leads on in-Kingdom hyperscaler maturity; Microsoft Azure's Saudi Arabia East region reaches general availability in Q4 2026.
- Sovereign cloud spending in the Middle East and Africa is forecast to grow 89% in 2026, the fastest of any global region, per Gartner.

Vice President, Strategy – VLink Inc.
Sambhavi Gopalakrishnan is the Vice President of Strategy at VLink Inc., bringing over a decade of experience in IT leadership, project implementation, and strategic growth. She possesses a strong foundation in technical project management and pre-sales, driving innovation and business transformation at VLink.

























