Skip to content
Saudi Arabia · Delivery record

Engineering for Saudi companies.

Saudi digital investment is running well ahead of local engineering supply, and regulatory expectations have tightened at the same rate. Both facts favour a supplier that can hold in-Kingdom data residency, contract under PDPL, and work six and a half hours of your day rather than a two-hour window at the edge of it.

Working with us from Saudi ArabiaSA
Daily overlap
09:00–15:30 AST
Contract currency
SAR or USD
Data regime
Personal Data Protection Law (PDPL) and its implementing regulations
Regulator
Saudi Data and AI Authority (SDAIA)
Working language
English
§ 01Working with Saudi Arabia

Hours, money,
and paperwork.

The three things that decide whether a cross-border engagement works, answered before you ask. Everything here is specific to Saudi Arabia rather than a global average.

Time overlap

09:00–15:30 AST

Arabia Standard Time is two and a half hours behind IST. Your 09:00 is our 11:30, and our day closes at your 15:30 — six and a half hours of shared working day, with the last part of your afternoon outside it. That is enough for same-day iteration on everything. Because we work Monday to Friday and much of the Kingdom works Sunday to Thursday, the engagement fixes which days carry the shared window and which run asynchronously, so a Sunday deadline is never a surprise.

Currency and tax

SAR or USD

Quoted and invoiced in riyals or US dollars. Services exported from India carry no tax at source, so the invoice shows the fee alone. As a non-resident supplier we do not charge Saudi VAT; you account for it under the reverse charge where applicable. Withholding tax is the one that catches people — the rate and treatment are confirmed in the agreement before the first invoice, not discovered when a payment arrives short.

Data protection

Governing law
Personal Data Protection Law (PDPL) and its implementing regulations
Authority
Saudi Data and AI Authority (SDAIA)
Our role
Processor, on your instructions

Named sub-processors, written consent before any addition.

PDPL sets a default expectation of in-Kingdom processing for personal data, with transfers permitted only on defined grounds. We treat residency as an architectural constraint from the first phase rather than a deployment detail, contract as processor on your instructions, and name every sub-processor. Where a sector regulator — SAMA for financial services, NCA for cybersecurity controls — imposes additional requirements, those are scoped explicitly before build.

§ 02What your procurement will ask

Answered
before you ask.

The questions we are asked most often from Saudi Arabia, answered straight. Where we do not hold something, it says so.

In-Kingdom data residency

Supported and designed for. Cloud regions inside the Kingdom are available, and residency is written into the agreement. Where personal data cannot leave, the architecture reflects that from the diagnose phase — including where build and test environments sit.

NCA Essential Cybersecurity Controls alignment

Our ISO 27001:2022 information security management system maps substantially onto the ECC control families. We provide the mapping rather than claiming NCA compliance, which is a determination for your own assessor.

Local presence and Saudization

We have neither, and say so up front. For work requiring an in-Kingdom supplier or contributing to Saudization targets, we operate as a subcontracted engineering capability behind a local prime, or decline.

Arabic-first product work

Right-to-left interfaces, Arabic typography and bilingual data models are engineered properly. Arabic content authorship is commissioned through a specialist partner and named in the engagement.

  • ISO 9001:2015 Quality Management System — certified company. Certificate 706564/2026/R, issued by Robust Certifications Pvt. Ltd.Quality Management SystemsCertified CompanyISO9001:2015
  • ISO 27001:2022 Information Security Management System — certified company. Certificate 25-07-21156763, issued by Anglia Compliance Group.Information Security ManagementCertified CompanyISO27001:2022
  • ISO 20000-1:2018 IT Service Management System — certified company. Certificate 25-07-21156764, issued by Anglia Compliance Group.IT Service Management SystemsCertified CompanyISO20000-1:2018

Certificate numbers, accreditation status and the verification route are published on our trust page. Check them without asking us.

§ 03What Saudi Arabia asks us for

The problems
that arrive.

The work that comes to us from Saudi Arabia most often. If one of these is yours, send us the brief.

01

Vision 2030 programme delivery

Platform work inside larger transformation programmes, where the constraint is engineering capacity against a fixed political timeline and an audit expectation.

02

Logistics and industrial operations

Freight, warehousing and plant-floor visibility, where the data exists but no system reads it. We operate our own logistics platform, so the domain is familiar.

03

Data platforms and applied AI

Consolidating fragmented operational data into something a decision can be made from, with in-Kingdom residency and traceable model outputs.

Why Saudi Arabia works with us

  • In-Kingdom residency treated as an architectural constraint from the first phase, not a hosting choice made at deployment.
  • ISO 27001:2022 mapped to NCA Essential Cybersecurity Controls, supplied as a document for your assessor rather than asserted as compliance.
  • Six and a half hours of shared working day, which matters more than it sounds on a programme with weekly political reporting.
Where we are not the right answer

No in-Kingdom entity, no local office, no contribution to Saudization targets. For prime contracts that require any of those, we are a subcontracted engineering capability or nothing. We also do not claim NCA or SAMA compliance — we supply control mappings and let your assessor decide.

§ 04Saudi Arabia · Questions

Asked from
Saudi Arabia.

Answers open with the answer. The general set — pricing, process, IP, security — is on the FAQ.

Can you keep our data inside Saudi Arabia?
Yes, and PDPL means we plan for it from the start rather than at deployment. Cloud regions inside the Kingdom are available, residency is written into the agreement, and the architecture — including where build and test environments sit — reflects the constraint from the diagnose phase. Transfers outside the Kingdom happen only on grounds permitted by PDPL and agreed in writing.
Are you compliant with NCA Essential Cybersecurity Controls?
We hold ISO 27001:2022, which maps substantially onto the ECC control families, and we supply that mapping as a document. We do not claim NCA compliance: that is a determination for your own assessor or a licensed consultancy, and a supplier asserting it directly should be treated with suspicion.
Do you have a presence in the Kingdom?
No. We are an Indian LLP with no in-Kingdom entity, office or Saudization contribution. For prime contracts requiring a local supplier, we work as a subcontracted engineering capability behind a local prime. Where that structure is not possible, we decline rather than obscure our standing.
§ 05Other markets

Where else
we work.

Working hours, currency and data protection, covered for every market we serve.

Working with Saudi Arabia.

Contracted in SAR or USD, governed by Personal Data Protection Law (PDPL) and its implementing regulations, delivered inside the 09:00–15:30 AST overlap window.

Cognimit Technologies LLP · Monday to Friday, 10:00–18:00 IST · IST (UTC+5:30)

WhatsAppStart a chat