Skip to main content
Blog

Saudi Hosting and CITC Requirements Explained

28/03/1448 AH

09/09/2026

Every Saudi proposal eventually hits the same question. Where will data live, and are you compliant with CITC, PDPL, and NCA. Get this wrong and procurement stalls. Get it right and you close faster than cheaper competitors.

This is the full guide to Saudi hosting decisions for software houses building for SMEs, enterprise, and government.

1. The three rulebooks

PDPL is the Personal Data Protection Law enforced by SDAIA. Personal data of Saudi residents should remain in the Kingdom unless you have adequate safeguards, consent, and documented transfer impact. Sensitive data like health and biometrics has tighter rules. Government data under the National Data Management Office rules often must stay in Saudi cloud with no foreign replication.

CITC, now CST, licenses hosting and telecom providers. As a software client you do not need a license, but your hosting vendor must have proper licensing for data centers and cloud services. Ask for their license numbers and data center locations in writing. Large buyers will request this in RFPs.

NCA Essential Cybersecurity Controls ECC-1 and ECC-2 apply when you supply government or critical infrastructure. They cover governance, asset management, access control, cryptography, logging, backups, network security, and incident response. You do not need full certification for every SME project, but you should align your baseline so enterprise deals do not require rework.

2. What data must stay in Saudi

Tier one that must stay is government records, banking core data under SAMA, and health data under MOH. These require Saudi cloud like STC Cloud, Elm Cloud, Aramco Cloud, or Oracle Jeddah. No EU replica unless explicitly approved.

Tier two that should stay by default is SME customer PII, employee records under Qiwa and Muqeem, and Fatoora invoices which must be archived six years and be retrievable for audit. You can use EU hosting with Saudi backup plus a DPA for early stage, but offer Saudi region as an upsell. Many Dammam and Riyadh SMEs now ask for it.

Tier three that can live globally is anonymized analytics, public marketing content, and CDN cache. Use Cloudflare with Saudi PoPs for speed while origin stays compliant.

Document your tiering in your MSA. One paragraph that names regions, backup locations, and retention periods saves weeks of legal back-and-forth.

3. Practical hosting options in 2026

For government, use Elm Cloud or STC Cloud with local support and audit logs. Do not propose Hetzner or Vercel alone. You will be disqualified.

For enterprise SMEs, use Oracle Cloud Jeddah, STC Cloud Dammam and Riyadh, or AWS Bahrain with a Saudi region failover plan. Pair with Cloudflare for DNS, WAF, and DDoS. Keep database in one region with encrypted daily snapshots to a second Saudi zone.

For startups and MVPs, Hetzner Germany or Finland plus Cloudflare plus daily S3 backup to Saudi-compatible storage is acceptable if you disclose it and sign a DPA. Migrate to Saudi region when revenue passes 500k SAR yearly or when the client asks. This balances cost and compliance.

For Next.js frontends, Vercel in EU plus Saudi API origin works well. Set cache headers carefully so personal data never caches at edge. Use server-side sessions in your Saudi region.

4. Network, DNS, and operations

Keep sa. domains with Hawsabah registrars like SaudiNIC partners. Use Cloudflare for DNS with DNSSEC. Sync NTP to Saudi time servers for Fatoora timestamp accuracy. Enable Arabic-capable logging with UTF-8 throughout so support can search by customer name.

Backups need encryption at rest with keys you control, tested restore monthly, and retention aligned to VAT six years and PDPL minimization. Monitor disk, memory, cert expiry, and ZATCA queue age from the same dashboard as app metrics.

Incident response must include a 24-hour Arabic notification template for clients, plus internal runbooks for region failover. NCA expects documented roles, not ad hoc WhatsApp.

5. How to sell compliance

Include a one-page compliance annex in every proposal. Name your data centers by city, state backup frequency, list sub-processors, attach your PDPL policy and NCA alignment checklist, and provide CR and VAT certificate links. This closes deals in Dammam industrial and Riyadh fintech where procurement is strict.

Price Saudi hosting as a separate line. It costs more than Hetzner. Clients accept it when they see audit readiness and faster support. Offer EU versus Saudi tiers and let them choose in writing.

Bottom line is residency is a feature. Build it once with infrastructure as code for both regions, and you can serve startups and ministries from the same codebase.

Innovative Solutions, Exceptional Results
Sikka Software © 2026
v2.18.3
madavisamastercardapple_paypaypalbank_transfer