Why generic data-center rubrics fail in the Kingdom
The standard Uptime Institute Tier I-IV framework, the EN 50600 European certification stack, and the typical hyperscaler procurement scorecard are necessary but not sufficient when evaluating a Saudi data center. The Kingdom’s combination of climatic stress (45-degree-Celsius peak summer ambient, persistent dust loading, brackish-water cooling constraints), sovereign-cloud regulatory layering (NCA ECC, SDAIA controls, CITC licensing), grid-mix volatility (a rapidly transitioning energy stack moving from gas-peaker dominance toward NEOM-anchored renewables), and a still-young operator track record means a generic rubric will misweight several of the most important risk axes.
This guide gives an eight-axis evaluation framework specifically calibrated for Saudi facilities, then walks through how the named operators — Hexagon Data Centers, NEOM/DataVolt, Center3, and the Humain campuses — score on each axis. Use it as a procurement and due-diligence tool, not a ranking.
The stakes for getting this evaluation right are significant. A 20 MW takedown commitment is a 7-to-15-year financial obligation worth $200 million to $400 million in total occupancy cost; mistakes at evaluation become very expensive to unwind. The 2024-2026 Saudi data-center market is also bifurcating between purpose-built AI infrastructure and legacy retail colocation, with a substantial pricing and operational gap between the two tiers that is not always legible from marketing materials alone.
The eight-axis rubric
Axis 1 — Power architecture and density. What is the per-rack power envelope? In 2026, a Saudi facility claiming “AI-ready” should be supporting a minimum of 50 to 80 kW per rack with a credible roadmap to 100 to 130 kW for liquid-cooled deployments. Check the actual installed busway capacity, the redundancy topology (2N versus N+1 versus N+2), the UPS architecture (rotary versus static, lithium versus VRLA), and the diesel or gas backup runtime. A facility quoting “Tier IV” without a 2N+1 generator topology and 96+ hours of fuel autonomy is mis-positioning. Specific reference points: the NVIDIA GB200 NVL72 reference design requires 120 kW per rack; the H100 SXM5 baseline reference design supports 40 to 60 kW per rack with conventional air cooling. Map your specific workload’s per-rack envelope before evaluating.
Axis 2 — Cooling architecture. This is where the Kingdom’s climatic reality bites. Air-cooled facilities are increasingly disqualified for AI workloads above 40 kW per rack. Direct-to-chip liquid cooling is now the de facto standard for any Humain or hyperscaler GPU deployment. Evaluate the heat-rejection chain end to end: chiller plant configuration, evaporative-cooling water source and cost, dry-cooler backup capacity, the CDU (coolant distribution unit) redundancy model, and — critically — whether the facility has secured long-term industrial water-supply contracts with the Saudi Water Authority. A facility without contracted water is exposed. The split between adiabatic, full-chiller, and dry-cooler-with-supplemental-evaporative architectures has real implications for both PUE and water consumption — a Saudi facility with a documented WUE (water usage effectiveness) below 0.5 L/kWh in 2026 is best-in-class for a hot-climate deployment.
Axis 3 — Power source and net-zero posture. Where does the electricity come from, and what is the carbon intensity? In 2026, gas-peaker dominance still characterizes much of the Saudi grid, with a published carbon intensity in the 500 to 600 gCO2/kWh range. NEOM-anchored facilities are positioning toward sub-100 gCO2/kWh via dedicated solar and wind PPAs through ACWA Power. Demand a documented PPA structure, a Scope 2 carbon-accounting methodology aligned with the GHG Protocol, and a renewable-energy certificate pathway. Vague “powered by renewables” claims without auditable certificates should be treated as marketing. Hyperscaler tenants in particular are under increasing pressure from their own corporate net-zero commitments to source verifiable Scope 2 — an unverified renewable claim is increasingly unacceptable in a serious takedown.
Axis 4 — Connectivity. Subsea cable diversity (the Saudi-UAE-Egypt corridor; the Red Sea-to-Europe corridor via 2Africa, EIG, and the new Center3 builds), terrestrial fiber routes, peering points, and intra-Kingdom dark-fiber backhaul are all non-trivial. A facility with single-path connectivity is a single point of failure for any latency-sensitive deployment. Demand documented diverse-path connectivity to at least three carrier-neutral exchange points, plus direct cloud on-ramps to AWS Bahrain, Azure Saudi Arabia (where applicable), Google Cloud Dammam, and Oracle Jeddah. The latency profile from a Riyadh-based facility to AWS Bahrain (us-east-equivalent latency of 8 to 15 ms) and to Frankfurt (60 to 80 ms) is materially different from a Jeddah-based facility, and the workload’s latency requirements should drive site selection rather than the reverse.
Axis 5 — Sovereignty posture. Does the facility hold a Saudi data-classification accreditation aligned with the SDAIA personal-data and government-data tiers? Does it operate under NCA’s Essential Cybersecurity Controls and the Cloud Cybersecurity Controls? Has it been certified under the CITC cloud-licensing regime? For workloads handling Saudi government data, classified Aramco data, or PII subject to PDPL (Personal Data Protection Law), sovereignty-posture is non-negotiable. Check the actual certificates, not the marketing claims. The CITC Cloud Computing Regulatory Framework — most recently refreshed in 2024 — defines four service-level classes; mapping the facility’s actual licensing to your workload’s classification is the gating compliance exercise.
Axis 6 — Operator track record. How long has the operator run live capacity in the Kingdom? What is the documented uptime over the last 36 months? What is the bench depth of operations engineers, and what is the Saudization ratio? Has the operator successfully delivered a >20 MW AI-cooled deployment to a hyperscaler-grade tenant? Saudi data-center operations is a new discipline at scale, and operator-risk is among the most mis-priced variables in 2026 procurement decisions. Ask specifically: how many Tier 4 events (full-facility outages or near-misses) has the operator experienced in the last 24 months, and what was the mean-time-to-recovery? A facility with no documented incident history may be reassuring or may indicate a young facility without enough operational miles to surface latent failure modes.
Axis 7 — Regulatory and certification stack. Beyond NCA and CITC, an enterprise-grade Saudi facility should hold ISO 27001, ISO 22301, ISO 50001, PCI DSS where relevant, SOC 2 Type II, the Uptime Institute Tier certification (design and constructed-facility), and ideally LEED or EDGE for sustainability. Each missing certificate is a future audit-friction surface. The Saudi-specific certifications — particularly the SAMA-recognized cloud-services certification for financial-services workloads and the SDAIA-issued sovereign-classification recognitions — are increasingly important and harder to verify from outside the Kingdom.
Axis 8 — Total cost. Saudi data-center pricing in 2026 ranges from roughly $90 to $160 per kW per month for retail colocation and as low as $55 to $80 per kW per month for hyperscaler-grade wholesale takedowns of 10 MW or more, with significant variation based on power source and cooling tier. Net-zero NEOM-anchored capacity carries a 15 to 25 percent green premium. Compare on a fully loaded total-cost-of-occupancy basis including connectivity, cross-connects, remote-hands, and the Saudization-compliance overhead. Project-finance terms should also be scrutinized — facilities financed at the operator level versus facility level have different default-and-foreclosure exposure for the tenant.
How the named facilities score
Hexagon Data Centers. Hexagon operates a growing footprint in Riyadh and the Eastern Province with a focus on Tier III-equivalent retail colocation. Strong on certification stack and operator track record, mid-tier on density (still building toward >50 kW liquid-cooled), and competitive on cost. A reasonable choice for enterprise IT and mid-tier AI workloads; less suited to frontier-scale GPU deployments. The 2025-2026 expansion into liquid-cooled capacity is genuine but newer; weight it accordingly.
NEOM / DataVolt. The NEOM campus, with DataVolt as the lead operator, is the Kingdom’s flagship net-zero AI infrastructure play. Power-source axis is industry-leading thanks to dedicated ACWA Power renewables. Density and cooling are explicitly designed for 100+ kW AI racks. Operator track record is the weakness — NEOM facilities are new, and large-scale operational history at the GPU-hyperscale tier is still being built. Sovereignty-posture is strong given the NEOM-specific regulatory regime. The political-risk overlay specific to NEOM (the Crown Prince’s personal sponsorship is an asset and a single point of dependency simultaneously) is an under-discussed evaluation factor.
Center3. Center3, anchored by STC, is the dominant Saudi connectivity-and-colocation play with the strongest subsea-cable footprint in the Kingdom. Connectivity axis is best-in-class. Power-density and AI-cooling are competitive but historically not the primary product focus; the 2025-2026 capacity expansion explicitly addresses this. Strong choice for connectivity-intensive workloads and as a multi-cloud on-ramp hub. Center3’s STC parentage means the operator-track-record axis benefits from STC’s broader operational discipline and is among the most mature in the Kingdom.
Humain campuses. The Humain-direct campuses in Riyadh and the Eastern Province are purpose-built for sovereign AI workloads — frontier-grade density, liquid cooling as standard, dedicated PPAs, and the sovereignty-posture is by definition aligned with PIF and SDAIA. Operator track record is the youngest of the four, and tenant access is gated by Humain partnership structures rather than open market. The implicit cost advantage of Humain capacity is offset by the constraint that workloads on Humain are subject to Humain’s commercial-relationship dynamics in a way that hyperscaler-on-third-party-colocation is not.
How to actually run the evaluation
A serious evaluation runs across four phases. Phase one is documentary — request the design documents, certification packages, PPA contracts, water contracts, connectivity diagrams, and the last 36 months of uptime data. Phase two is on-site — walk the facility, inspect the chiller plant, the UPS room, the generator yard, and the meet-me room. Phase three is operational — interview the shift supervisor, the chief engineer, and the head of security; review the change-management runbooks; observe a generator test if possible. Phase four is contractual — review the SLA structure, the liquidated-damages clauses, the right-to-audit provisions, and the data-sovereignty language.
A complete evaluation runs eight to twelve weeks for a hyperscale takedown and four to six weeks for a retail colocation deployment. Compress it at your own risk. The most common compression failure is skipping phase three (operational interviews) — the documentary record can look strong while the operational discipline is weak, and only the on-site interview surfaces the discipline gap.
A specific operational discipline worth applying: for any facility above 5 MW, demand a tabletop disaster-recovery exercise as part of due diligence. The operator’s response to a hypothetical full-utility failure, dual-chiller failure, or major fire scenario reveals more about operational readiness than 100 pages of design documentation.
What to walk away from
Several patterns reliably indicate a facility you should not deploy into. A vendor unwilling to provide independent third-party certification documents is hiding something. A power-architecture diagram with single points of failure that the operator cannot articulate is operationally unsafe. A water-supply story without a contracted PPA-equivalent with the Saudi Water Authority is a future shutdown risk. A sovereignty-posture claim without documented NCA and SDAIA certification is regulatory exposure. An operator-team Saudization ratio below the Nitaqat band threshold for the operator’s industry classification is an imminent visa-quota and government-procurement liability. A total-cost quote that is 30 percent or more below market for comparable density-tier capacity is almost certainly mispriced and the operator will either re-trade or fail.
The Saudi data-center market is bifurcating in 2026 between a small set of frontier-grade, sovereign-aligned facilities (Humain, NEOM/DataVolt, the top Center3 sites) and a longer tail of legacy retail colocation facilities that are not credibly competing for AI workloads. Anchor evaluation in the eight-axis rubric, run the four-phase process, and walk away from anything that fails on more than one axis.
Operational red flags that experienced evaluators catch
A short checklist of red flags that experienced data-center evaluators surface during due diligence and that less-experienced evaluators miss. The chiller-plant operator who cannot articulate the specific failure mode that triggered the most recent maintenance event — operations teams that cannot speak fluently about their own incident history are not running the discipline they claim. The generator yard with visible fuel-tank corrosion or non-compliant containment — the discipline visible at the equipment yard reflects the discipline applied to the rest of the facility. The meet-me room without documented cross-connect inventory — connectivity that is not inventoried cannot be diversified. The change-management runbook with no documented evidence of recent updates — a runbook that has not been touched in 18 months is not being applied to actual operations. The security operations center without 24x7 documented staffing across both Saudi-national and expatriate engineers — coverage that depends on a single shift profile is fragile. The BMS (building management system) with default vendor passwords or visible network segmentation gaps — operational technology security is consistently the weakest layer in 2026 Saudi facilities and an attacker’s most likely entry point. Each of these red flags is individually survivable; in combination they signal an operational discipline that will not deliver the contractual SLA over the multi-year takedown period.
For deeper reading: How to invest in Saudi AI, Capital Flows, Players: NEOM, How to pick a Saudi cloud provider.