Skip to content

Regulation · checked 30 Aug 2026

CST cloud provider classes explained for a foreign vendor

A Saudi tender says the workload must sit with a "CST Class C registered provider" and half your deal team starts searching for what that means. Here is the working explanation for a foreign vendor — what the classes are, what each permits, and how to ask a provider the right question. Facts checked 30 Aug 2026.

The regulatory frame

Saudi Arabia's cloud regime is set by the Communications, Space and Technology Commission (CST) — the regulator formerly known as CITC — under the Cloud Computing Services Provisioning Regulations, in force since 10 October 2023. The core rule: any provider that controls the data centre or critical infrastructure of a cloud system must register with CST. (CST Regulation 1482, registration service)

Registration is not a rubber stamp; it comes in classes — Qualifying, A, B, and C — and the class determines two things:

  • Which data classifications the provider may process, from public data up through the government classification ladder (the NDMO policy classifies government data as Top Secret, Secret, Confidential, or Public — NDMO policies).
  • Which sectors the provider may serve: individuals, private sector, non-profit, and government.

Why tenders cite Class C

Class C is the registration that covers the government sector and the higher data classifications. That is why a government-linked buyer's procurement or security team writes it into requirements: it is the shorthand for "a provider registered to hold our class of data."

A concrete example of what evidence looks like: Huawei Cloud publishes its KSA Class C registration, describing it as qualification to process "public, confidential, secret, and top-secret data related to individuals, private sector, non-profit sector, and government sector." (Huawei's compliance page)

How to ask a provider the right question

Three disciplines keep this honest:

  1. Ask for the current registration class in writing. CST publishes the authoritative register of cloud providers; a provider's own published registration (as Huawei does) is the next-best evidence. A verbal assurance is not evidence.
  2. Read the class against your customer's sector and data classification. The question is never "is the provider registered" in the abstract — it is "does this registration cover a government-sector workload holding Confidential-class data," or whatever your specific combination is.
  3. Expect the class question alongside the controls question. Buyers in scope of the NCA's ECC-2:2024 and CCC-2:2024 flow those controls down to suppliers by contract (NCA CCC); the CST class qualifies the provider, and the controls conversation covers your side of the flow-down.

Where this bites a foreign vendor

The class requirement is a provider requirement — you do not register with CST to sell software. But it constrains your architecture: if your product currently runs on infrastructure with no live in-Kingdom region, and the buyer requires a Class C provider, then your route runs through one of the providers that holds that registration, and the porting question is on your critical path.

Whether that is your situation — and which provider class your specific customer's sector points to — is what the Path Check establishes in three minutes.