The Technology Edition
Vol. 19 — For Tech & SaaS Founders
MCIT activities, data-residency obligations under PDPL, NCA cybersecurity controls, the talent stack in Riyadh and KAFD — what it actually takes to operate a foreign-owned technology company inside the Kingdom.
Direct answer. Setting up a foreign-owned technology or SaaS company in Saudi Arabia is a 90-day MISA Services-LLC build (SAR 500K capital) with three sector-specific overlays: MCIT activity selection that determines which technology services you can sell, PDPL data-residency obligations that decide whether your customer data can leave the Kingdom, and NCA Essential Cybersecurity Controls (ECC-1) compliance that decides whether you can sell to government and regulated entities. The talent market is concentrated in Riyadh (KAFD, ITCC), Jeddah and Dhahran, with Saudi-national engineering hires running SAR 18,000–35,000/month. Sector Saudization for ICT runs at 25–30% depending on Nitaqat band. The procurement realities — government-first market, 90-day payment terms from public buyers, RHQ requirement above SAR 1M public-sector contracts — decide whether your Saudi unit is a sales office or a real operating subsidiary.
01 · The licence
The MISA Services-LLC is the wrapper. The MCIT activity codes are what decide your business.
Every foreign-owned tech company in Saudi Arabia is built on a MISA Services-LLC at SAR 500K capital — the same licence used by management consultancies and design firms. What separates a SaaS company from a consultancy, in regulatory terms, is the MCIT (Ministry of Communications and Information Technology) activity codes embedded in the MISA application and the Commercial Registration.
The activities that matter: Computer programming activities (ISIC 6201) for custom software and SaaS development; Computer consultancy activities (ISIC 6202) for implementation and integration; Data processing, hosting and related activities (ISIC 6311) for cloud infrastructure and managed hosting; Web portals (ISIC 6312) for marketplaces and aggregators; Software publishing (ISIC 5820) for licensed software products. Each unlocks a different set of customer contracts and a different MCIT compliance regime.
Get this wrong and you cannot bid for the contract you set up the company to win. Pick narrowly and you protect the licence; pick broadly and you trip MCIT scrutiny on activities you don't actually run. We cover the activity-selection mechanics in Volume 16 — MISA Activities & ISIC4.
02 · Data residency
The Personal Data Protection Law decides whether your customer data can sit on AWS Frankfurt — or whether it has to live in Riyadh.
The Personal Data Protection Law (PDPL), fully effective from September 2024, governs how personal data of Saudi residents is collected, processed and transferred. It is enforced by SDAIA (Saudi Data and AI Authority).
For a foreign SaaS company, three obligations matter most: (1) Lawful basis — you need explicit consent or a recognised legal basis to process Saudi resident data. (2) Data localisation — sensitive data (health, financial, biometric, children's data) must be processed inside Saudi Arabia unless an explicit cross-border transfer mechanism applies. (3) Cross-border transfer — non-sensitive personal data can leave the Kingdom only with an adequacy determination, an approved transfer mechanism, or explicit consent for each transfer.
In practice this drives a hosting decision early: AWS Middle East (Bahrain), Google Cloud Dammam, Oracle Jeddah, STC Cloud, Mobily Cloud or Microsoft Azure (KSA region, live since 2024). Selling to government, banking, healthcare or any sector with sensitive data effectively forces in-Kingdom hosting plus NCA Cloud Cybersecurity Controls (CCC-1) compliance.
Penalties under PDPL run to SAR 5M per violation, with criminal liability for the Managing Director on knowing breaches. This is not a year-two problem.
03 · Cybersecurity
If you want to sell to government, banking or critical infrastructure, NCA controls are not optional.
The National Cybersecurity Authority (NCA) issues two control frameworks that bind foreign technology suppliers operating in Saudi Arabia: ECC-1 (Essential Cybersecurity Controls) for organisations handling government data, and CCC-1 (Cloud Cybersecurity Controls) for cloud service providers and customers in regulated sectors.
ECC-1 covers 114 controls across five domains: governance, defence, resilience, third-party risk and industrial-control systems. CCC-1 layers cloud-specific obligations: data classification, encryption, key management (with the Saudi-resident Key Management Service requirement for Tier 3 and 4 data), and incident notification within four hours.
Compliance is evidenced through annual self-assessment plus, for higher-tier customers, an independent audit by an NCA-licensed assessor. Without a clean ECC-1 posture, you do not pass the procurement gate at any government entity, SAMA-regulated bank or NUPCO healthcare contract.
04 · Talent
Saudi technology talent is real — and priced like London. Plan compensation accordingly.
The Saudi technology talent stack runs through three institutions: KAUST (King Abdullah University of Science and Technology, Thuwal — graduate engineering and AI research); KFUPM (King Fahd University of Petroleum and Minerals, Dhahran — undergraduate engineering, especially data and software); and Misk Academy / Tuwaiq Academy (Riyadh — bootcamp pipelines for software engineering, product, design and data).
Compensation benchmarks for Saudi nationals in 2026: Senior software engineer SAR 28,000–45,000/month; Mid-level engineer SAR 18,000–28,000/month; Junior engineer SAR 10,000–16,000/month; Product manager SAR 25,000–40,000/month. Expat compensation runs 10–20% higher to offset Iqama, dependant levy and housing differential. See Cost of Hiring in Saudi Arabia for the full benchmark and the Saudization & Nitaqat Volume 14 for the headcount math.
The geography matters: KAFD (King Abdullah Financial District, Riyadh) is the default address for SaaS, fintech and product teams; ITCC (IT & Communications Complex, Riyadh) for cloud and infrastructure firms; Dhahran Techno Valley for industrial-tech and Aramco-adjacent suppliers.
05 · The market
Saudi tech revenue is concentrated in the public sector. The RHQ Programme decides whether you can chase it.
The Saudi technology market in 2026 is dominated by the public sector and PIF-owned giga-projects. NEOM, ROSHN, Diriyah, Red Sea Global, Qiddiya, the Saudi Tourism Authority, the Ministry of Health, the Ministry of Education, NUPCO, SDAIA and the General Authority for Statistics together control the majority of greenfield enterprise IT spend.
All of them — by Royal Decree from January 2024 — require any foreign supplier bidding for contracts above SAR 1M to either operate from a Regional Headquarters licence inside the Kingdom or accept procurement disadvantage and ZATCA withholding tax penalties. The RHQ Programme is therefore the gating decision for any tech company chasing public-sector revenue.
The trade-off: RHQ gives you 30 years of 0% corporate tax and 0% withholding on RHQ activities, but the licence prohibits generating commercial revenue from operating activities inside Saudi Arabia. Most foreign tech firms therefore run a two-vehicle structure: an RHQ for regional coordination and public-sector qualification, plus an operating MISA Services-LLC for commercial Saudi sales. We cover the architecture in Volume 15 — The RHQ Programme.
Payment terms from public buyers run 60–90 days from invoice acceptance; from PIF-owned giga-projects, often longer. Working capital planning is not optional.
A Saudi tech company is not a Saudi sales office. The companies that win here are the ones that treat MCIT activity selection, PDPL hosting and NCA controls as product decisions — not compliance afterthoughts.
For non-sensitive personal data and B2B SaaS targeting private-sector customers, yes — with a documented PDPL cross-border transfer mechanism. For sensitive data, government, banking or healthcare customers, no — you need an in-Kingdom region (AWS Bahrain, Azure KSA, Google Cloud Dammam, Oracle Jeddah, STC Cloud).
Not before incorporation, but yes before you can complete enterprise procurement at any government, banking or critical-infrastructure customer. Plan a 6–9 month roadmap from MISA licence to ECC-1 readiness.
SAR 500,000 paid-in capital for a standard MISA Services-LLC. Capital sits in a Saudi escrow account during incorporation and is then released to the company's operating account.
Mandatory only if you intend to bid for Saudi public-sector contracts above SAR 1M. For pure private-sector SaaS, an LLC alone is sufficient — though most international players still set up an RHQ for the 30-year tax holiday and regional coordination role.
60–90 days for a clean MISA-LLC build with Tamra. Add 4–8 weeks for ECC-1 readiness and 2–6 weeks for in-Kingdom cloud onboarding before you can sell to regulated customers.
ICT-sector Nitaqat targets sit at 25–30% Saudi-national headcount weighted, depending on company size band. Below the band, your work-visa pipeline is throttled or frozen. See Volume 14 for the operational mechanics.
Tamra runs MISA, MCIT activities, PDPL hosting and NCA readiness as one workstream. 30 minutes to brief us.
Talk to Tamra