A Saudi tender says the workload must sit with a "CST Class C registered provider" and half your deal team starts searching for what that means. Here is the working explanation for a foreign vendor — what the classes are, what each permits, and how to ask a provider the right question. Facts checked 30 Aug 2026.
The regulatory frame
Saudi Arabia's cloud regime is set by the Communications, Space and Technology Commission (CST) — the regulator formerly known as CITC — under the Cloud Computing Services Provisioning Regulations, in force since 10 October 2023. The core rule: any provider that controls the data centre or critical infrastructure of a cloud system must register with CST. (CST Regulation 1482, registration service)
Registration is not a rubber stamp; it comes in classes — Qualifying, A, B, and C — and the class determines two things:
- Which data classifications the provider may process, from public data up through the government classification ladder (the NDMO policy classifies government data as Top Secret, Secret, Confidential, or Public — NDMO policies).
- Which sectors the provider may serve: individuals, private sector, non-profit, and government.
Why tenders cite Class C
Class C is the registration that covers the government sector and the higher data classifications. That is why a government-linked buyer's procurement or security team writes it into requirements: it is the shorthand for "a provider registered to hold our class of data."
A concrete example of what evidence looks like: Huawei Cloud publishes its KSA Class C registration, describing it as qualification to process "public, confidential, secret, and top-secret data related to individuals, private sector, non-profit sector, and government sector." (Huawei's compliance page)
How to ask a provider the right question
Three disciplines keep this honest:
- Ask for the current registration class in writing. CST publishes the authoritative register of cloud providers; a provider's own published registration (as Huawei does) is the next-best evidence. A verbal assurance is not evidence.
- Read the class against your customer's sector and data classification. The question is never "is the provider registered" in the abstract — it is "does this registration cover a government-sector workload holding Confidential-class data," or whatever your specific combination is.
- Expect the class question alongside the controls question. Buyers in scope of the NCA's ECC-2:2024 and CCC-2:2024 flow those controls down to suppliers by contract (NCA CCC); the CST class qualifies the provider, and the controls conversation covers your side of the flow-down.
Where this bites a foreign vendor
The class requirement is a provider requirement — you do not register with CST to sell software. But it constrains your architecture: if your product currently runs on infrastructure with no live in-Kingdom region, and the buyer requires a Class C provider, then your route runs through one of the providers that holds that registration, and the porting question is on your critical path.
Whether that is your situation — and which provider class your specific customer's sector points to — is what the Path Check establishes in three minutes.
