Saudi Arabia - Cloud Computing Regulation (CCRF v3)

Cloud Computing Regulatory Framework (CCRF) — Version 3

Saudi Arabia

RAI-SA-NA-CCRCVXX-2020
Repealed(No longer in effect)
RegulationGovernance and OversightConformity Assessment and RegistrationData Protection and Privacy
Export PDF

The Cloud Computing Regulatory Framework (CCRF) v3 was issued by the Saudi telecommunications regulator (formerly the Communications and Information Technology Commission — CITC, now the Communications, Space & Technology Commission — CST) and came into effect on 3 December 2020. CCRF v3 defined registration categories for cloud service providers (CSPs), introduced a two-tier subscriber data classification (Saudi Government Data and Non-Government Data) with sub-levels for government data, imposed data residency restrictions for certain government data, and set out obligations for incident reporting, telecom infrastructure use and cooperation with national cybersecurity authorities.

Summary

The Cloud Computing Regulatory Framework (CCRF) Version 3 was issued by the Communication and Information Technology Commission (CITC) of the Kingdom of Saudi Arabia and came into effect in December 2020. CCRF v3 updated the scope and definitions of cloud services, introduced revised registration categories for Cloud Service Providers (CSPs), clarified customer-content classification rules (including distinct treatment for Saudi Government Data and Non-Government Data), and set out obligations for both CSPs and cloud customers regarding security, breach reporting and restrictions on transfers of government data outside the Kingdom. ([dlapiper.com](https://www.dlapiper.com/en-gb/insights/publications/2021/04/saudi-arabia-releases-version-3-of-its-cloud-computing-regulatory-framework?utm_source=openai))

CCRF v3 remained an important national instrument to regulate cloud services offered to customers with a residence or address in Saudi Arabia until it was superseded by updated Cloud Computing Service Provisioning Regulations (version 4) approved by the Communications, Space & Technology Commission (CST) in October 2023. The CST decision formally superseded CCRF v3 and brought a renewed regulatory structure for cloud service provisioning and registration in the Kingdom. ([cst.gov.sa](https://www.cst.gov.sa/en/RulesandSystems/RegulatoryDocuments/Documents/CCRF_En.pdf))

Full article

Read full text ↗

Overview

The Cloud Computing Regulatory Framework (CCRF) Version 3 was prepared and published under the authority of the Communication and Information Technology Commission (CITC) of the Kingdom of Saudi Arabia and came into effect on 3 December 2020 (18/04/1442 H). CCRF v3 updated earlier versions to reflect evolving cloud models (IaaS, PaaS, SaaS), reorganized Cloud Service Provider (CSP) registration categories, and clarified obligations for both CSPs and cloud customers—particularly in relation to customer-content classification and transfers of Saudi Government Data. The framework applied to cloud services provided to customers with a residence or address in Saudi Arabia and to CSPs exercising direct or effective control over data centres or critical cloud infrastructure hosted or used in the Kingdom. Many provisions were designed to promote secure adoption of cloud services while protecting national interests and sensitive government information. (Practitioner summaries at the time included commentary; see, for example, https://www.dlapiper.com/en-gb/insights/publications/2021/04/saudi-arabia-releases-version-3-of-its-cloud-computing-regulatory-framework?utm_source=openai)

Definitions

Key definitions used and clarified under CCRF v3 included the following: Cloud Service (explicitly includes IaaS, PaaS and SaaS); Cloud Service Provider (CSP) — any natural or legal person providing cloud services, with specific rules where CSPs exercise direct or effective control over local data centres or critical cloud infrastructure; Cloud Customer / Subscriber — the entity that consumes cloud services and is responsible for classifying customer content; and Saudi Government Data — customer content classified under government categories (e.g., top secret / secret / confidential / public) that is subject to residency and transfer restrictions. CCRF v3 expanded scope and definitions to expressly cover SaaS, IaaS and PaaS and services provided to customers having a residence or address in the Kingdom.

Governance and Institutional Framework

CCRF v3 was issued under the authority of the Communications regulator (then the Communication and Information Technology Commission — CITC). Subsequent institutional change transferred regulatory responsibility to the Communications, Space & Technology Commission (CST), which approved updated Cloud Computing Service Provisioning Regulations (version 4) on 8 October 2023 and brought a new provisioning and registration regime that formally superseded CCRF v3 as of 10 October 2023. Enforcement, oversight and coordination under CCRF v3 involved the communications regulator working with other national authorities (including national cybersecurity entities) when Saudi Government Data or national-security-related incidents were implicated. The regulator retained powers to register, deny or revoke registration, require remediation and coordinate notifications to relevant national entities.

Key Focus Areas

  • Scope and Definitions: Expanded to expressly cover SaaS, IaaS and PaaS and to apply to services provided to customers having a residence or address in Saudi Arabia.
  • Registration Regime: Introduced tiered registration categories (commonly described as A/B/C levels) based on CSP activities, control of local infrastructure and conformance to technical standards.
  • Customer-Content Classification: Replaced prior classification schema with a two-tier framework separating “Saudi Government Data” (with sub-levels such as top secret / secret / confidential / public) from “Non-Government Data,” and clarified responsibilities for customers to select classifications reflecting confidentiality, integrity and availability needs.
  • Data Residency and Localization for Government Data: Imposed restrictions on transfers of Saudi Government Data outside the Kingdom unless otherwise permitted by law or regulation and placed obligations on responsible parties to prevent unauthorized transfers.
  • Security and Incident Reporting: Required incident reporting to the regulator(s), clarified responsibilities for breach notification—particularly where government data or significant numbers of users are affected—and required CSPs to meet minimum technical and security standards.
  • Telecommunications Infrastructure Use: CSPs exercising control over Saudi-hosted cloud infrastructure were required to use telecommunications infrastructure through operators licensed by the regulator.

Implementation Framework

Implementation under CCRF v3 combined registration, documentation, technical conformance and contractual duties. CSPs exercising direct or effective control over local cloud infrastructure were required to register with the regulator in the appropriate tier and to demonstrate compliance with applicable technical controls and operational requirements, including alignment with recognized information-security standards and maintenance of documentation for assessment. Contracts between CSPs and cloud customers were expected to reflect customer-content classification, security requirements, data-handling restrictions and responsibilities for breach management. Cloud customers bore responsibility for accurate classification of their data and for selecting appropriately registered CSPs where required (for example, when handling government-classified content). Transfer and handling of Saudi Government Data were restricted and required lawful basis or regulatory permission for transfers outside the Kingdom.

Monitoring and Evaluation

Monitoring and evaluation under CCRF v3 relied on a combination of registration oversight, documentation and audit-ready evidence of technical controls, mandatory incident reporting and regulator-led assessments. The regulator exercised authority to require corrective measures, to coordinate with other national authorities (such as national cybersecurity agencies) when incidents implicated government data or national security, and to enforce registration and compliance obligations. CCRF v3 anticipated follow-on guidance and assessment mechanisms to validate CSP conformance to technical standards and procedures for incident escalation and reporting.

Penalties, Liability, and Appeals

Enforcement mechanisms under CCRF v3 included registration denial or revocation, administrative actions and obligations to remediate non‑compliance. The regulator retained authority to require corrective measures and to coordinate notifications to relevant national entities where incidents affected Saudi Government Data or a significant number of customers. The framework described administrative enforcement actions and remediation requirements; specific monetary fines, judicial remedies or appeal procedures were governed by the regulator’s broader enforcement rules and any applicable national administrative law provisions. (The public text of CCRF v3 provided for administrative measures; parties seeking detail on appeals or detailed liability regimes should consult the regulator’s enforcement rules and accompanying regulatory documents.)

Relationship to Other Instruments

CCRF v3 operated alongside sectoral data-protection and cybersecurity controls (including controls established by the National Cybersecurity Authority) that intersect with cloud-security requirements. CCRF v3 was subsequently superseded by the Communications, Space & Technology Commission’s Cloud Computing Service Provisioning Regulations (version 4), approved on 8 October 2023 and entering into force on 10 October 2023. Version 4 consolidated and updated the provisioning and registration regime to streamline registration and market operation while preserving protections for government data. For registration and operational details, the regulator’s registration and regulatory documents pages provide primary guidance (see CST regulatory documents at https://www.cst.gov.sa/en/RulesandSystems/RegulatoryDocuments/Documents/CCRF_En.pdf).

International Alignment

CCRF v3 reflected global trends toward sector-specific cloud regulation that emphasize data protection, localization for sensitive government data and clear operator registration. The Kingdom’s approach aligned regulatory oversight of cloud services with national-security and data-governance priorities, while also attempting to enable market development. CCRF v3’s classification, residency and registration themes were comparable to practices in other jurisdictions that combine cybersecurity, data-governance and telecom/regulatory oversight. Subsequent CST updates continued to emphasize alignment with technical standards and market facilitation. Practitioner and industry analyses at the time discussed these alignments (see, for example, https://www.dlapiper.com/en-gb/insights/publications/2021/04/saudi-arabia-releases-version-3-of-its-cloud-computing-regulatory-framework?utm_source=openai).

Implementation Timeline

DateEvent
2020-12-03CCRF v3 came into effect following issuance by the Communication and Information Technology Commission (commonly cited effective date: 3 December 2020 / 18/04/1442 H).
2020-12-31CITC published a comparative study on cloud computing (referenced in practitioner analyses).
2023-10-10The Communications, Space & Technology Commission (CST) decision and related regulatory updates (Cloud Computing Service Provisioning Regulations v4) entered into force, superseding CCRF v3.

Sources and References

SourceURL
Communications, Space & Technology Commission (CST) — CCRF / Cloud regulatory documentshttps://www.cst.gov.sa/en/RulesandSystems/RegulatoryDocuments/Documents/CCRF_En.pdf
Communications, Space & Technology Commission (CST) — main sitehttps://www.cst.gov.sa

Requirements for a company

What an organisation has to do under Saudi Arabia - Cloud Computing Regulation (CCRF v3), at a glance. Not legal advice.

No current requirements. This instrument is repealed; it imposes nothing today.

© Regulations.AI · updated on 13-Jun-2026