
For vendors
You have a Saudi customer waiting.
Know the route before you spend on one.
You sold the product; now procurement wants in-Kingdom hosting, a CST-registered provider, PDPL answers, and contracting standing you may not have. Each of those has a knowable answer — and guessing at them is how deals stall.
The objections
The questions serious vendors ask, answered in order.
These are the questions your own team should ask any intermediary. Here are our answers, in writing.
“Who are you, legally?”
An operating desk reachable at hello@cloudiarabia.com, deliberately publishing only what is verifiable. Entity details appear on the About page as they are formalised. Until then, judge the desk by the only evidence that matters at this stage: whether the facts on this site are right, sourced, and dated.
“Why not go to stc, or any provider, directly?”
You can, and sometimes the Path Note will say so. What the desk adds is the framing: which provider class your customer’s sector points to, which purchase route applies, and what the enterprise team on the other side will ask. An enquiry that arrives already framed clears qualification in days rather than weeks.
“Do you take a cut of the provider bill?”
No. No reseller margin, no capacity commitments, no billing of your customer. Introductions are made without charge to the enquirer; any engagement terms are agreed directly with the downstream party.
“Are you a lawyer or an auditor?”
No — and the site says so everywhere it could be misread. The desk orients you on the questions counsel and auditors will ask, and tells you which of those answers must come from a formally qualified party.
“What happens to our data and our customer relationship?”
Your customer relationship, product, and roadmap stay with you. Enquiry details are used to assess fit and route the conversation — the privacy notice states what is collected and where it goes. In the hosting chain itself, PDPL roles are made explicit in the downstream contracts.
“How fast, in practice?”
The published numbers are targets with dependencies stated: a reply within 4 business hours (Sunday–Thursday, Riyadh time (AST, UTC+3)), and where there is a fit, a written Path Note in about 48 hours. The long pole in most deals is the buyer’s security review — the Path Note sequences around it.
The patterns
Four ways the deal stalls.
Each pattern has a likely route and a service that applies — and each ends in the same three-minute first step.
A government SaaS pilot on AWS or Azure
The ministry wants the pilot live in Riyadh; your product runs on a hyperscaler with no live Saudi region. The tender cites a CST-registered provider and the security team has started asking about NCA controls.
Read the route →A regulated private buyer — bank or health group
The deal is commercially agreed, then the buyer’s compliance team asks whether its regulator has approved the cloud arrangement. Nobody on your side knows what SAMA expects, or in what order.
Read the route →A stack already in-Kingdom — behind a designated route
You run on Google Cloud or Alibaba Cloud, the region exists in the Kingdom, and yet the purchase stalls: nobody can tell you who actually sells it, on what paper, billed from where.
Read the route →A tender with no Saudi entity
The tender is on Etimad, your pipeline says it is winnable, and procurement asks for standing you do not have: a Saudi CR, MISA registration, local-content evidence. Someone proposes a subsidiary; someone else says it takes a year.
Read the route →Establish the route before you spend.
Subsidiary, intermediary, or simply the right provider — know which one your deal needs before you commit to any of them. The Path Check is three minutes and asks what the first provider conversation would ask anyway.