Logo
subscribe

On-Prem to Cloud in Saudi Arabia: CST Regulations, In-Kingdom Hosting & Migration Steps

Written by

On-Prem to Cloud in Saudi Arabia CST Regulations
Key Takeaways:
  • Saudi Arabia's cloud computing market is projected to reach $14.6 billion by 2030, up from $5.07 billion in 2025, a 23.6% CAGR, per MarketsandMarkets (2025).
  • CST's Cloud Computing Regulatory Framework defines four data levels (Level 1-4); Level 3 and Level 4 data must be hosted in-Kingdom by CST-licensed providers.
  • Government entity data cannot leave Saudi Arabia, even temporarily for caching or backup, unless expressly permitted by law.
  • Oracle is the most established hyperscaler in-Kingdom, live in Jeddah since 2020 and in Riyadh since October 2024, backed by a $1.5 billion investment.
  • Worldwide sovereign cloud IaaS spending will hit $80 billion in 2026, and the Middle East and Africa region is forecast to grow 89%, the fastest of any region, per Gartner (February 2026).

 

Consider the IT Infrastructure Manager at a mid-market Riyadh trading and logistics group. The board approved a data center consolidation budget after two costly on-prem outages last year. The mandate is to move core systems to the cloud within nine months. What is not yet clear is which of the group's workloads must legally stay inside Saudi Arabia.

VLink is a global IT services company. It helps CIOs, IT infrastructure managers, and compliance leaders move Saudi workloads from on-premises infrastructure to compliant cloud environments. VLink's relevant practices include cloud migration, DevOps and infrastructure management, and IT staff augmentation. Delivery teams support Saudi engagements across banking, healthcare, government, and logistics.

Cloud migration in Saudi Arabia is not a generic lift-and-shift exercise. CST's cloud regulations and in-Kingdom hosting rules shape which workloads can move where. Sector-specific compliance from SAMA and the NCA adds further constraints. This guide sets out the regulations, the provider options, and a step-by-step migration framework built for the Saudi regulatory environment. Enterprises running workloads across the Gulf can compare it with the equivalent guide to cloud migration services in the UAE, where a different residency regime applies.

On-Prem to Cloud in Saudi Arabia CST Regulations CTA1.webp

Why Are Saudi Enterprises Moving From On-Prem to Cloud in 2026?

Saudi Arabia's cloud computing market is growing fast. MarketsandMarkets' Saudi Arabia Cloud Computing Market Report 2025-2030 values it at $5,069.5 million in 2025. It projects growth to $14,608.9 million by 2030, a 23.6% compound annual growth rate. Mordor Intelligence's KSA Cloud Computing Market report puts the figure higher. It cites $15.39 billion in 2025, rising to $27.93 billion by 2030 at a 12.66% CAGR. The gap reflects differing market scope, not disagreement on direction.

Saudi Arabia Cloud Computing Market Size byTwo Independent Estimates

Saudi Arabia Cloud Computing Market Size — Two Independent Estimates

Research Firm2025 Market Size2030 Projected SizeCAGR
MarketsandMarkets$5,069.5 million$14,608.9 million23.6%
Mordor Intelligence$15.39 billion$27.93 billion12.66%

 

Three forces are driving this growth. Aging on-prem infrastructure carries rising operating costs. Vision 2030's digital transformation mandate pushes both government and private enterprises toward modern platforms. CST's own Cloud First Policy directs government entities to evaluate cloud before any new on-prem investment. Hyperscaler capital spending in-Kingdom is compounding all three.

What this means for an IT Infrastructure Manager in that position: the case for keeping aging hardware gets weaker every quarter. The harder question is not whether to move, but which workloads can legally move where.

How Does Vision 2030's Cloud First Policy Shape Migration Timelines?

Saudi Arabia's Cloud First Policy predates most enterprise cloud strategies in the region. CITC, CST's predecessor, introduced the policy in 2020. It directs government entities to evaluate cloud options before approving any new on-prem infrastructure investment.

The policy does not bind private enterprises directly. It shapes their environment in two ways. First, government cloud-first spending accelerates hyperscaler investment in-Kingdom. That is why Oracle, Microsoft, Google, and AWS have all committed capital to Saudi regions. Second, government suppliers and contractors increasingly face de facto cloud requirements to remain eligible for public-sector contracts.

What this means for a Government Digital Transformation Director: cloud migration is not optional infrastructure modernization anymore. It is a prerequisite for staying eligible on public-sector procurement lists.

What Are Saudi Arabia's CST Cloud Regulations, and Do They Apply to You?

The Communications, Space & Technology Commission (CST), formerly CITC, governs cloud computing in Saudi Arabia. It does so through its Cloud Computing Regulatory Framework (CCRF). Any provider that controls a data center or critical infrastructure used to deliver cloud services must register with CST.

CST classifies registered providers into four categories: Qualification, Class A, Class B, and Class C. Each category determines which subscriber data classification a provider may legally handle. The CCRF also defines four cloud data levels, Level 1 through Level 4. These align with the National Data Management Office's (NDMO) classification scheme.

CST Cloud Data Levels and In-Kingdom Hosting Requirements

CST Cloud Data Levels and In-Kingdom Hosting Requirements

LevelNDMO ClassificationTypical DataHosting Requirement
Level 1PublicMarketing content, public disclosuresNo residency restriction
Level 2Internal / RestrictedInternal operations, non-sensitive business dataNo mandatory in-Kingdom requirement
Level 3Confidential / SecretSensitive government and regulated-sector dataMust be hosted in-Kingdom by a CST-licensed provider
Level 4Top Secret / CriticalNational security and critical infrastructure dataMust be hosted in-Kingdom, highest control tier

 

This is not a paperwork exercise enterprise can defer. CST enforcement applies to both the cloud provider and the enterprise customer. Choosing a wrongly categorized provider for Level 3 or Level 4 data creates direct regulatory exposure. That exposure lands on the enterprise, not just the vendor.

CST Cloud Provider Registration Categories

CategoryWhat It Permits
QualificationEntry-level registration; permits handling of Level 1 and Level 2 data only
Class APermits handling of data up to Level 3, including confidential sector data
Class BPermits handling of data up to Level 3, with additional sector-specific authorizations
Class CHighest tier; permits handling of Level 4 data, including top-secret and critical infrastructure

 

A provider's category is not optional paperwork to skim past during procurement. Ask for the specific registration category in writing, not just a general CST-compliance claim, before signing any hosting agreement.

Which Data Must Stay In-Kingdom Under Saudi Cloud Regulations?

Government sector data faces the strictest rule in Saudi cloud regulation. No data belonging to a Saudi public sector entity may leave the Kingdom for any purpose, permanent or temporary. That includes caching, backup, and disaster recovery replication, unless a specific law expressly allows it.

Private-sector enterprises face a narrower but still material set of rules. Financial institutions, healthcare providers, and telecom operators each carry sector-specific residency obligations. These layer on top of the CST baseline, covered in the next section.

What this means for a Compliance & Risk Manager: do not assume a hyperscaler's regional presence alone satisfies in-Kingdom hosting. Confirm the specific data center, the provider's CST registration category, and whether backups or logs ever leave the Kingdom.

The National Data Management Office sits behind these rules as the classification authority. NDMO's national data classification policy defines the levels CST's cloud framework then applies to hosting decisions. Classify data against NDMO's policy directly, rather than guessing at CST's summary levels. That approach produces a more defensible audit trail.

On-Prem to Cloud in Saudi Arabia CST Regulations CTA2.webp

Which Cloud Providers Operate In-Kingdom in Saudi Arabia?

Three categories of provider serve the Saudi market. These are global hyperscalers with in-Kingdom regions, telecom-backed cloud subsidiaries, and specialist sovereign cloud providers. Their in-Kingdom maturity varies significantly.

Cloud Provider Options in Saudi Arabia

Cloud Provider Options in Saudi Arabia, 2026

ProviderIn-Kingdom StatusBest Fit
Oracle CloudLive: Jeddah (since 2020) and Riyadh (since October 2024), part of a $1.5B Saudi investmentEnterprises needing the longest-established in-Kingdom hyperscaler track record
Microsoft AzureSaudi Arabia East region confirmed February 2026; workloads available from Q4 2026Enterprises planning ahead for SAMA and NCA CCC-2 aligned Azure workloads
Google CloudLive region in DammamEnterprises prioritizing AI and data analytics workloads (BigQuery, Vertex AI)
AWSRegion committed with $5.3B investment and three Availability Zones; not yet generally available as of mid-2026Enterprises able to wait for GA, or using AWS from a nearby region in the interim
stc Cloud (sccc by stc)Live, in-Kingdom data centers, 100+ local cloud productsEnterprises already integrated with stc's telecom and managed-network services
Mobily CloudLive, in-Kingdom data centers via Etihad EtisalatEnterprises inside Mobily's telecom network

 

Oracle's head start matters for enterprises on a near-term timeline. Microsoft's confirmed Q4 2026 availability changes the calculus for enterprises planning a 2027 migration. Saudi Arabia's Minister of Communications and Information Technology called the Azure region a milestone. It builds "advanced, trusted AI infrastructure" for the Kingdom, he said in a February 2026 statement.

Physical region choice affects latency, not just compliance. Oracle operates in both Jeddah and Riyadh. Google's region sits in Dammam, and Microsoft's planned region sits in the Eastern Province. Each sits closer to different population and industry centers. A Riyadh-headquartered bank and a Jeddah-based logistics firm may reasonably choose different primary regions for the same workload type.

What Do Banking, Healthcare, and Government Rules Add on Top of CST?

CST sets the cloud provider baseline. Regulated sectors then layer their own requirements on top. Each sector's regulator can override CST's baseline with stricter terms.

Sector-Specific Cloud Compliance in Saudi Arabia

SectorRegulatorKey Requirement Beyond CST Baseline
Banking & FinanceSAMA (Saudi Central Bank)Primary copies of sensitive data, including PII, transaction history, and core banking configs, must stay in-Kingdom
HealthcareMOH / SFDAPatient records and clinical data hosting must meet Ministry of Health data protection standards
Government & Critical InfrastructureNCA (National Cybersecurity Authority)Cloud Cybersecurity Controls (CCC-2:2024) apply on top of the 114-control Essential Cybersecurity Controls baseline
TelecomCSTCloud infrastructure regulations apply directly to telecom-operated cloud subsidiaries

 

The NCA's CCC framework carries an unusual staffing requirement. All cybersecurity roles at in-scope organizations must now be filled by Saudi nationals. That rule now covers all roles, not just senior positions, under the latest control update. This affects which delivery partners can staff a compliant migration team.

SAMA's rules go further than a simple in-Kingdom mandate for banks. Cross-border data sharing is not banned outright, but it must be justified by a legitimate business need. It also requires encryption, access controls, and an immutable audit trail. A bank cannot simply claim a business justification without documenting it.

Healthcare carries a narrower but still binding rule. Patient records and clinical data hosted in the cloud must meet Ministry of Health data protection standards. Confirm SFDA alignment for any medical device data pipeline too. Do not stop the compliance review at the core patient record system.

A note from VLink's VP of Strategy. "A Saudi client once told us their chosen provider had a Saudi presence, so in-Kingdom hosting was covered. It was not. The provider's regional office handled sales, but the workload itself ran outside the Kingdom. We spent the first two weeks verifying data center locations and CST categories, before writing a migration plan."

What Does a CST-Compliant Migration Roadmap Look Like?

A Saudi cloud migration needs a compliance gate at every phase, not just a technical one. The standard 6Rs migration framework still applies, but each workload must also clear a data-residency check before it moves.

CST-Compliant Migration Roadmap in Saudi Arabia

  1. Assessment: Classify every workload against CST's four data levels and confirm which sector regulator applies.
  2. Planning: Match each workload's data level to a CST-licensed provider category and select a 6Rs strategy (rehost, replatform, refactor, repurchase, retire, or retain).
  3. Execution: Migrate in phases, starting with Level 1 and Level 2 workloads before tackling Level 3 and Level 4 systems.
  4. Optimization: Validate in-Kingdom hosting for backups, logs, and disaster recovery, not just primary workloads.

Most Saudi migration failures trace back to skipping the classification step. Enterprises that start with a technical 6Rs assessment often skip data residency first. They then discover mid-migration that a chosen provider cannot legally host a given workload.

The Assessment phase is where most of the real work happens. It is not a quick inventory spreadsheet. Every application, database, and integration needs a data-level tag before anyone touches a migration tool. Cloud Architects should involve compliance and legal early, not after a provider shortlist exists.

Planning benefits from running in parallel with vendor conversations, not after them. Ask each shortlisted provider for their exact CST category and the physical location of their data center in writing. Verbal assurances from a sales team are not sufficient evidence for an audit. If the partner shortlist is still forming, the category guide to IT companies in Dubai maps how consultancies, integrators, and managed services providers differ across the region.

Execution should never treat all workloads as equal-risk. A Level 1 marketing website and a Level 3 core banking database do not belong in the same migration wave. Sequencing lower-risk workloads first also gives the migration team a chance to validate its own process before the stakes rise.

Optimization is the phase enterprises most often skip entirely. A successful cutover is not the finish line. Backup locations, log retention, and disaster recovery targets need the same data-level scrutiny the primary workload received during planning.

What Do the 6Rs Mean in a Saudi Regulatory Context?

The 6Rs migration framework is well established globally. In Saudi Arabia, each strategy carries a regulatory implication most global guides skip.

The 6Rs Migration Framework, Adapted for Saudi Regulatory Constraints

StrategyWhat It MeansSaudi-Specific Note
RehostLift-and-shift a workload to cloud infrastructure with minimal changeFastest option for Level 1 or Level 2 data; verify hosting location for Level 3 or higher
ReplatformMake targeted optimizations without a full rearchitectureCommon for workloads moving to a CST-licensed in-Kingdom region
RefactorRebuild the application for cloud-native architectureBest for workloads needing tighter integration with NCA CCC controls
RepurchaseReplace the workload with a SaaS equivalentConfirm the SaaS vendor's own CST registration before adoption
RetireDecommission the workload entirelyReduces the compliance surface area enterprises must manage
RetainKeep the workload on-premises for nowOften the right call for Level 4 data pending a licensed provider match

 

Most Saudi enterprises end up running four or five of these strategies at once, not one. A single-strategy migration plan is usually a sign the classification step was skipped.

What Does On-Prem to Cloud Migration Cost in Saudi Arabia?

Migration cost in Saudi Arabia depends more on data classification than on workload size. A Level 1 or Level 2 workload can move to any registered provider. A Level 3 or Level 4 workload narrows the field to CST-licensed, in-Kingdom-hosted options. Those options typically carry a premium over globally available capacity.

Migration Cost Benchmark by Phase (KSA Enterprise Projects)

PhaseTypical Cost RangeTypical Duration
Assessment & data classification$15,000 - $60,0003-6 weeks
Migration planning & CST provider mapping$20,000 - $80,0002-4 weeks
Execution (mid-size enterprise, multi-workload)$100,000 - $600,000+3-9 months
Optimization & compliance validation$15,000 - $50,000Ongoing, first 90 days critical

 

These ranges reflect engagement patterns reviewed for this guide, not a quote from a single vendor. Sovereign cloud spending is climbing region-wide, which affects vendor pricing power. Gartner forecasts worldwide sovereign cloud IaaS spending will reach $80 billion in 2026, up 35.6% from 2025. The Middle East and Africa region is projected to grow 89% in 2026, the fastest of any region measured. Governments remain the largest sovereign cloud buyers, followed by regulated industries and infrastructure operators in energy, utilities, and telecommunications.

A Gartner senior director analyst framed the shift in a February 2026 statement. "As geopolitical tensions rise, organizations outside the US and China are investing more in sovereign cloud IaaS," he said. The investment, he added, is aimed at digital and technological independence.

How Does VLink Help Saudi Enterprises Migrate Under CST Compliance?

VLink's cloud migration practice has supported enterprise and mid-market clients through data center consolidation, hybrid cloud architecture, and regulated-sector migrations. VLink's delivery teams work within the compliance frameworks governing CST, SAMA, and NCA CCC requirements. Delivery teams pair migration work with the DevOps and staff augmentation capacity most Saudi migrations also need.

For enterprises still classifying workloads, VLink's cloud migration services cover data-level classification, provider mapping, and phased execution from day one. Where a migration needs ongoing pipeline automation, VLink's DevOps consulting services build the CI/CD infrastructure to support it. Where internal teams need embedded migration or compliance capacity, VLink's IT staff augmentation services supply it directly. Where new application logic is required during a re-architecture, VLink's custom software development practice builds and integrates it.

To commission a CST-aligned cloud migration readiness assessment for your organization, engage VLink's advisory team.

On-Prem to Cloud in Saudi Arabia CST Regulations CTA3.webp

In Summary

Cloud migration in Saudi Arabia succeeds or stalls on regulatory classification, not technical readiness. Classify every workload against CST's four data levels before choosing a provider. That single step avoids the costly mid-migration surprises that stall projects elsewhere.

  • Saudi Arabia's cloud market is projected to reach $14.6 billion by 2030, up from $5.07 billion in 2025, per MarketsandMarkets.
  • CST's four cloud data levels determine hosting requirements — Level 3 and Level 4 data must stay in-Kingdom with a CST-licensed provider.
  • Government data cannot leave Saudi Arabia for any purpose without express legal permission.
  • Oracle leads on in-Kingdom hyperscaler maturity; Microsoft Azure's Saudi Arabia East region reaches general availability in Q4 2026.
  • Sovereign cloud spending in the Middle East and Africa is forecast to grow 89% in 2026, the fastest of any global region, per Gartner.
image
Sambhavi Gopalakrishnan

Vice President, Strategy – VLink Inc.

Sambhavi Gopalakrishnan is the Vice President of Strategy at VLink Inc., bringing over a decade of experience in IT leadership, project implementation, and strategic growth. She possesses a strong foundation in technical project management and pre-sales, driving innovation and business transformation at VLink.

Frequently Asked Questions
Does every Saudi enterprise need to comply with CST cloud regulations, or only regulated sectors?-

Every enterprise using a registered cloud provider falls under CST's Cloud Computing Regulatory Framework. Sector-specific rules from SAMA, MOH/SFDA, or the NCA apply only to regulated industries. CST registration requirements themselves apply broadly.

Can a global hyperscaler with no Saudi data center still be used for non-sensitive workloads?+

Yes, for Level 1 or Level 2 data with no in-Kingdom hosting mandate. Confirm the workload's data classification first. Using an offshore provider for Level 3 or Level 4 data creates direct regulatory exposure.

What happens if an enterprise migrates Level 3 data to a provider without the right CST registration category?+

The enterprise, not just the provider, carries regulatory exposure. CST enforcement applies to both parties in the hosting relationship. Verifying provider registration is a customer responsibility, not just a vendor promises.

Is Microsoft Azure usable in Saudi Arabia before its in-Kingdom region reaches general availability?+

Azure services remain available from nearby regions today. Workloads needing in-Kingdom residency should wait for the confirmed Q4 2026 launch of Saudi Arabia East. Or use an already-live in-Kingdom provider instead.

How does the NCA's Saudization requirement affect choosing a migration partner?+

Organizations in scope for NCA's Cloud Cybersecurity Controls must staff all cybersecurity roles with Saudi nationals, not only senior positions. Confirm a migration partner's ability to meet this staffing requirement before signing a contract.

What's the difference between CST's data levels and SAMA's data classification for banks?+

CST's four levels apply across all sectors and determine general in-Kingdom hosting requirements. SAMA layers additional, finance-specific rules on top, covering transaction history, payment credentials, and core banking system configurations specifically.

Can disaster recovery backups for Level 3 data be stored outside Saudi Arabia?+

No. In-Kingdom hosting requirements extend to backups, caching, and disaster recovery replication for regulated data, not just the primary workload. Confirm this explicitly with any provider before signing.

How long does a typical CST-compliant migration take for a mid-market Saudi enterprise?+

Based on engagement patterns reviewed for this guide, assessment and planning typically take 5 to 10 weeks combined. Execution runs 3 to 9 months depending on workload count and data-level complexity.

Does using a telecom-backed provider like stc Cloud avoid CST compliance questions entirely?+

No. stc Cloud and Mobily Cloud are still CST-registered providers subject to the same data-level and category rules as global hyperscalers. Telecom backing does not exempt an enterprise from classification and compliance verification.

What is geopatriation, and why does it matter for Saudi cloud planning?+

Geopatriation is the shift of data and workloads from global public clouds to sovereign, in-country alternatives. Gartner names it a top 2026 trend. It is a direct driver behind the 89% growth Gartner forecasts for Middle East and Africa sovereign cloud spending.

Should a mid-market enterprise use one cloud provider or a multi-cloud approach in Saudi Arabia?+

Many Saudi enterprises use one provider for Level 3 and Level 4 in-Kingdom workloads. A second provider then handles less sensitive workloads or AI-specific services. Match the provider to the data level, not the other way around.

What is the single biggest mistake enterprises make in Saudi cloud migration planning?+

Running a technical 6Rs assessment before completing data-level classification. Enterprises that classify first avoid discovering mid-migration that their chosen provider cannot legally host a given workload.

Does the Cloud First Policy require private-sector enterprises to migrate to cloud?+

Not directly. The policy binds government entities to evaluate cloud before new on-prem spending. Private enterprises feel its effect indirectly, through faster hyperscaler investment in-Kingdom and tighter cloud expectations from government clients and contracts.

Can an enterprise mix a global hyperscaler and a local telecom cloud provider in one migration?+

Yes, and many mid-market Saudi enterprises do. A common pattern pairs a global hyperscaler for AI or analytics workloads with a telecom-backed provider like stc Cloud. The telecom provider handles CST-registered in-Kingdom hosting for sensitive data.

Related Posts

The Rise of Chatbots in Insurance Industry & its Future
The Rise of Chatbots in the Insurance Industry

As consumers look for more personalized experiences, insurance companies are turning to chatbots.  These computer programs use artificial intelligence and machine learning to simulate human conversation.

14 Feb 2023

8 minute

mdi_user_40d9164745_1eb2083113
subscribe
Subscribe to Newsletter

Subscribe to Newsletter

Trusted by

stanley
Trusted Logo
BlackRock Logo
Trusted Logo
Eicher and Volvo Logo
Checkwriters Logo

Book a Free Consultation Call with Our Experts Today

Phone

0/1000 characters

0 + 0 =