Two paths called the same name
The phrase “Saudi cloud region” covers two operationally different decisions. Path one is dedicated in-Kingdom data center capacity with PDPL-compliant residency, sovereign-cloud-eligible infrastructure, and a build-out timeline of 24-36 months and capital outlay of $500M-$2B. Path two is a Saudi-serving region that means regional capacity (Bahrain, UAE) wrapped in PDPL-compliant commercial and legal structures, deployable in 6-9 months at modest capital expense. Most foreign cloud operators conflate the two during initial planning and lose 12 months on alignment when the architecture team and the legal team realize they have been building toward different targets.
This guide covers the genuine in-Kingdom path — what it takes to stand up a real Saudi cloud region with sovereign-cloud-eligible status. It walks through site, power, build, compliance, and the buy-versus-build decision that most foreign operators get wrong on the first attempt.
Phase 1 — Site, power, permits (months 0-9)
The first phase determines whether the project is real. Pick the cluster: Riyadh metro is the safe default for first-region launches, with the densest customer base, the densest engineering talent pool, and the most mature regulatory familiarity. Eastern Province (Dammam-Khobar) is Aramco-adjacent and energy-belt-anchored, which makes it the right answer for energy-sector and Aramco-portfolio workloads. NEOM/Oxagon is greenfield, net-zero positioned, and the right answer for first-of-kind workloads with sustainability mandates and willingness to take build-out risk. Each cluster has different power availability, fiber-backbone density, and customer-proximity profiles.
Lock the land. Cloud SEZ designation is increasingly the preferred path because it bundles regulatory clarity with permitting acceleration. Modon (Saudi industrial-properties authority) is the counterparty for industrial-cluster siting; the relevant municipal authority handles permitting. Cloud SEZ designation typically takes 4-7 months for footprints that exceed the threshold and align with strategic priorities; smaller or generic-purpose deployments take longer through standard channels.
Lock the power. Saudi Electricity Company (SEC) interconnection studies and the formal power purchase agreement (PPA) typically take 6-9 months for sites under 100 MW, longer for larger sites. Hyperscale GPU loadouts (the 50-200 MW per site range that Blackwell-class deployments require) face longer interconnection timelines because grid-impact studies and capacity allocations become non-trivial. ACWA Power and Aramco Digital are common renewable-power counterparties for net-zero positioning and ESG-anchored sovereignty narratives. Power locking is the most common timeline killer for Saudi cloud region projects; without confirmed power, the timeline does not start, and customer commitments signed ahead of PPA confirmation are routinely the source of expensive failures.
Local-content requirements affect bidding pools and timelines from the earliest phase. Saudi local-content rules for major infrastructure projects mandate minimum local participation in EPC, professional services, and operations. Foreign-led project structures that under-weight local content face extended approval timelines or outright rejection in the Cloud SEZ designation review.
Phase 2 — Build (months 6-30)
Tier IV data center construction with hyperscale GPU loadout (10-50K+ H100/H200/B100/B200 footprint) is an EPC engagement, not a real-estate development. The viable bidding pool includes: Bechtel (US-based with established Saudi practice), Black & Veatch (US-based with established Saudi infrastructure work), the major Saudi consortia (Saudi Electric Construction, Almabani General Contractors, several others), and increasingly the regional players (China State Construction, Korean engineering houses with Saudi presence). EPC contracts in KSA include local-content requirements that affect the bidding pool and the timeline; foreign-only EPC structures are typically not viable.
Connectivity engineering is parallel-track. Dual-homed fiber to STC and Mobily backbones is table-stakes; international connectivity through 2Africa, SeaMeWe-6, and Peace Cable matters for global-traffic workloads. Subsea cable landing rights and dark-fiber leases require 6-9 months of pre-procurement; sites without confirmed connectivity at construction milestone face deployment delays after physical readiness.
GPU procurement runs in parallel with construction and is the most operationally complex stream. BIS export-licensing for the GPU loadout (per the Blackwell export license guide) takes 14-26 weeks; sequencing the licensing in phase with the ship-ready milestone is the difference between deployment-ready capacity and stranded infrastructure. Vendors and end-users routinely under-resource the licensing stream, which produces the worst-case scenario: completed data center sitting empty waiting for hardware that has not cleared review.
Operations build-out is the fourth parallel stream. Hyperscale data center operations require 50-150 specialized operators per site (network, systems, security, facility, GPU-specific operations). Hiring and training this operations team in Saudi Arabia takes 6-12 months for a green-field site without an existing operations base; partnering with an established Saudi operator (Center3, Hexagon team, the major hyperscaler regional teams) compresses to 3-6 months but trades equity and operational control.
Phase 3 — Compliance and launch (months 24-36)
PDPL registration with the appropriate Saudi authority is the foundational compliance milestone. KSA-RoD designation as a sovereign-cloud-eligible operator is the differentiating milestone for government and regulated-customer eligibility. CITC licensing applies if voice or connectivity services are part of the offering. NCA cybersecurity certification is required for critical-infrastructure customer eligibility. ISO 27001/27017/27018, SOC 2 Type II, Tier IV physical certification, and PCI DSS where applicable round out the certification stack.
None of these can run before the physical site is materially complete; they are the long tail of go-live. Compliance filings sequenced in parallel with construction (paperwork ready and pre-reviewed by regulators) compress the go-live timeline; compliance filings started after construction completion add 6-9 months to launch. The right operational posture is paper-ready 6 months before physical-ready.
Customer commercial onboarding is the final phase. The first customers signed during construction are anchor customers, often with significant pricing and SLA concessions in exchange for being first-mover references. Commercial customer ramp typically begins 2-3 months before formal launch with pilot deployments and references-buildout, scaling to general availability at launch.
What blows up timelines
The recurring failure modes:
- Power not pre-locked. Six-month slips are routine; longer slips occur when grid-capacity allocations are constrained.
- EPC bidding without local-content alignment. Re-bid required, adding 3-6 months.
- BIS export-control sequencing for the GPU loadout out of phase with the ship-ready milestone. Stranded infrastructure for 3-9 months.
- Compliance filings sequenced after physical readiness rather than in parallel. 6-9 month launch delay.
- Anchor customer signed before PPA confirmed. Customer expects a hard launch date that the construction reality cannot support; relationship damage and sometimes commercial concessions follow.
- Operations team built too late. Site physically ready but operationally under-resourced; soft launch fails.
- Sovereign-cloud designation pursued reactively rather than proactively. Government-customer eligibility delayed, sometimes by 12+ months.
Worked example — the cost stack for a 100 MW Riyadh region
Putting numbers on the genuine in-Kingdom path clarifies the buy-versus-build decision that follows. For a 100 MW AI-ready build in the Riyadh cluster in 2026:
Construction. AI-ready Tier III+/IV hyperscale capacity in the Kingdom runs $9.8M-14.5M per MW of IT load all-in — roughly $1.0B-1.45B for the 100 MW facility. The shell alone is $2.8M-4.6M per MW, with the lower bound achievable on pre-permitted Modon land in the Riyadh metro and the upper bound reserved for bespoke builds. The Saudi premium over US benchmarks ($8.5M-13M per MW) has compressed materially since 2023 but has not disappeared; UAE builds price at $9.5M-13.5M.
Power. At SEC’s high-voltage industrial tariff of $0.038-0.057/kWh for 115 kV+ connections, 100 MW of continuous draw costs roughly $42M annually at a blended $0.048 rate. This is the structural operating advantage that justifies building here at all — but it only becomes real after the 6-9 month interconnection and PPA process completes, which is why power-not-pre-locked heads the failure-mode list above.
Silicon. The GPU loadout dwarfs the building. GB200 NVL72 racks land in the Kingdom at $2.8M-3.6M per rack for sovereign-anchor deployments; B200-class GPUs at $28,000-36,000 each for VEU-covered buyers versus $36,000-48,000 for non-VEU commercial buyers. Licensing tier is therefore worth 25-35% of silicon capex and one to two quarters of schedule (2-4 month procurement for VEU-covered buyers against 6-9 months for specific licenses) — the financial expression of the BIS-sequencing failure mode.
Revenue. In-Kingdom H100-class capacity clears at $2.40-4.20 per GPU-hour on-demand, with 1-year reserved at $1.55-2.40 effective and 3-year reserved at $1.10-1.70. Newly commissioned Saudi capacity is priced aggressively at the reserved tiers to defend utilization, which compresses early-year margins on exactly the capacity a new region needs to fill. Model the region’s break-even on 3-year-reserved pricing, not on-demand, and treat anything above it as upside.
The buy-versus-build implication in one line: the colocation path converts the $1.0B-1.45B construction stack and the power-interconnection risk into an operating expense inside someone else’s completed facility, at the cost of margin share.
How the 2025-2026 entrants actually structured it
Every major foreign cloud entrant in the 2025-2026 window took a partner-anchored path rather than a solo greenfield build, and the pattern is instructive. AWS structured its $5.3B Riyadh region with Humain as the Saudi counterpart, targeting 2026 service. Google Cloud anchored its $10B global AI hub in Dammam to a Humain partnership, with the 300 MW campus (NVIDIA silicon plus Google TPU) targeting 2027. Microsoft’s $1.5B Azure expansion runs through the same Humain partnership architecture. xAI took the JV route outright — a 500 MW Riyadh campus with Humain, the company’s first non-US facility, with Grok deployed country-wide as the workload anchor. Groq entered without building at all, deploying LPU inference capacity under a $1.5B Humain commitment with the Aramco Digital cluster serving EMEA and South Asia as the operational anchor. Qualcomm’s 200 MW inference play (AI200/AI250 rack services from 2026) follows the same partner-hosted pattern.
For operators below hyperscaler scale, the colocation base is real and growing: Center3’s carrier-neutral Riyadh campus (100 MW, operational, stc-backed), Gulf Data Hub’s Riyadh build (200 MW, under construction for 2026, inside KKR’s $2B program), Alfanar’s operational commercial capacity, and — for green-mandate workloads on longer horizons — DataVolt’s net-zero AI factory at NEOM Oxagon (1.5 GW, planned 2028). The Humain campuses and the Hexagon-anchored sovereign infrastructure (480 MW, operational early 2026) define the sovereign tier that government-adjacent workloads gravitate toward.
The reading is blunt: if AWS, Google, and xAI — organizations with unlimited EPC experience and balance sheet — chose partner-anchored structures for market entry, a foreign operator proposing a solo greenfield first region should be able to articulate precisely why its situation differs.
Anchor tenant archetypes
Three anchor-tenant archetypes underwrite new Saudi regions, each with different concession economics. Government and sovereign-adjacent (SDAIA workloads and the National Data Lake ecosystem spanning 430+ government systems): the highest strategic value and the gateway to sovereign-cloud-designated revenue, but it requires the full compliance stack before a single workload lands, and procurement cycles run long. Energy-belt enterprise (Aramco Digital and the Eastern Province industrial base): large, technically sophisticated, and the natural anchor for Dammam-Khobar sited capacity. Financial services (the major banks’ AI programs): substantial inference demand, SAMA-regulated residency requirements that in-Kingdom capacity uniquely satisfies, and the most commercially conventional contracting of the three. A launch plan without at least one named anchor from these archetypes at PPA-execution time is a speculative build, whatever the pitch deck says.
Site-selection decision checklist
Before committing the land: Does the cluster match the anchor-tenant archetype — Riyadh for government and banks, Eastern Province for energy, NEOM/Oxagon for net-zero mandates? Is SEC interconnection capacity confirmed in writing for the full loadout, not just the first phase? Does the site sit inside a Cloud SEZ designation path with Modon as counterparty? Is dual-homed fiber to STC and Mobily backbones physically available, and is international routing (2Africa, SeaMeWe-6, Peace Cable) relevant to the workload mix? Does the local-content plan survive EPC procurement review? And is the BIS licensing calendar for the GPU loadout phased to the construction milestone schedule? A no on any of these is a timeline slip already booked; two or more noes means a different site.
The buy-vs-build decision
For most foreign cloud operators, the right answer in 2026 is not to build a region from scratch but to anchor a colocation footprint inside a Saudi-operated facility (Center3, SDAIA Hexagon, future Humain campuses) and run a virtual region over partner-owned physical capacity. This compresses the 24-36 month timeline to 9-12 months, eliminates EPC and power-procurement risk, and accelerates compliance because the underlying facility has already cleared most certifications.
The trade-off is less infrastructure differentiation versus competitors and lower margin on the underlying capacity. For most enterprise-cloud operators, the speed-to-market and risk-reduction outweigh the differentiation cost. For hyperscale operators with $1B+ committed Saudi opportunity and global-scale operating capability, full build-out is sometimes justified by the long-term margin economics.
The hybrid path — partner-anchored launch followed by purpose-built second-region build-out — is increasingly the dominant pattern. Year one and year two run on partner capacity to validate market demand and earn customer references. Year three through year five build out dedicated capacity once the demand picture is clear and the operations team is mature. This phasing reduces the all-or-nothing risk of greenfield first-region build-out.
Operational checklist for genuine in-Kingdom build
Day 0: site cluster decision, EPC shortlist, Saudi-side counsel engagement. Day 60: land secured, Cloud SEZ designation initiated, SEC interconnection study commissioned. Day 180: PPA executed, EPC contract signed, GPU procurement initiated with BIS licensing in parallel. Day 360: structural construction complete on first phase, compliance filings paper-ready, operations team hiring underway. Day 540: facility power-up, GPU deployment, certification audits scheduled. Day 720-1080: certifications received, first anchor customers onboarded, general availability launched.
This is the disciplined timeline. The undisciplined timeline routinely runs 36-48 months and burns customer relationships in the slip.
For deeper reading: How to build Saudi data center · How to evaluate Saudi data center · How to pick Saudi cloud provider · Infrastructure.