Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

Saudi Arabia CST/CITC Cloud Computing Regulatory Framework (CCRF)

The Cloud Computing Regulatory Framework (CCRF) is Saudi Arabia's national cloud regulation administered by the Communications, Space and Technology…

What Saudi Arabia CST/CITC Cloud Computing Regulatory Framework (CCRF) requires

The Cloud Computing Regulatory Framework (CCRF) is Saudi Arabia's national cloud regulation administered by the Communications, Space and Technology Commission (CST, formerly the Communications and Information Technology Commission / CITC). The CCRF establishes the regulatory regime for Cloud Service Providers (CSPs) operating in Saudi Arabia or serving Saudi customers, the data classification levels used to determine residency and CSP eligibility, the registration requirements for CSPs, and the relationship between cloud governance and the Personal Data Protection Law (PDPL) administered by the Saudi Data and AI Authority (SDAIA). The framework classifies customer data into four levels based on impact: Level 1 (Public, no confidentiality required), Level 2 (Confidential, low impact if disclosed), Level 3 (Confidential, medium impact, typical of regulated industry data), and Level 4 (Highly Confidential, high impact, including critical national infrastructure and sovereign data classifications). Level 3 and 4 data are subject to data residency requirements (typically Saudi-located data centres) and CSP eligibility constraints including local registration, data protection officer designation, incident reporting to CST and to the National Cybersecurity Authority (NCA) where the customer is a government or critical infrastructure entity, and adherence to NCA Essential Cybersecurity Controls (ECC-1:2018 updated 2022) and Cloud Cybersecurity Controls (CCC-1:2020). The CCRF intersects the National Data Management Office (NDMO) data classification policy issued by SDAIA which provides the cross-government data categorisation taxonomy that maps into CCRF residency tiers. The framework also intersects sectoral cloud regulations including the Saudi Central Bank (SAMA) Cybersecurity Framework cloud provisions for banks and insurance entities and the Saudi Health Information Exchange policies for healthcare cloud workloads. CCRF-licensed providers include the major global hyperscalers via Saudi region launches (AWS Middle East Bahrain / Saudi, Microsoft Azure Saudi, Google Cloud Saudi via local partnership, Oracle Cloud Infrastructure Saudi, IBM Cloud) and several Saudi national providers including stc cloud, Mobily Cloud, Sahara Net, and the strategic government cloud initiatives under Vision 2030.

Pillar: Cloud & SaaS · Authority: Communications, Space and Technology Commission (CST, formerly CITC), Kingdom of Saudi Arabia · Version: 1.0.0 · Last updated:

Primary source: https://www.cst.gov.sa/

SHA-256 integrity: f74e00eb081e8765131bdc4fc809a609df4fcfc76377025a08f735d46b6d13cf

Primary Citations — 10 traced to source

  • Communications, Space and Technology Commission (CST, formerly CITC) Cloud Computing Regulatory Framework (CCRF) - Saudi national cloud regulation establishing CSP registration, data classification, and residency requirements
  • National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC-1:2018 updated 2022) - mandatory baseline for Saudi government and critical infrastructure entities

+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.