Regional headquarters · Riyadh

IT for regional headquarters in Riyadh.

Office IT, Microsoft 365, devices and cyber security for multinationals setting up or running a regional headquarters in Riyadh, from an ISO 27001:2022 certified team with an office in the city.
Built for regional headquarters

A new headquarters, a group IT estate and Saudi rules

Saudi Arabia’s Regional Headquarters Program, licensed by the Ministry of Investment (MISA), has attracted around 600 multinationals since it launched in 2021, most of them to Riyadh. Since 1 January 2024, multinationals that want to do business with Saudi government entities have generally needed a regional headquarters in the Kingdom.
An RHQ licence comes with deadlines. Operations are expected to start within six months of the licence, with at least 15 full-time employees in the first year, including three senior executives. That means an office, a network, devices and accounts ready on time, and a group IT estate that also meets the Saudi requirements that apply to you.

What regional headquarters ask us for

What an RHQ needs

The IT jobs behind a regional headquarters

Every RHQ is different, but these are the areas we are asked about most.

Office set-up and moves

Network, Wi-Fi, firewalls, meeting-room technology and printing, planned with your fit-out team and ready before people arrive.

People and devices

Laptops and phones enrolled, encrypted and managed, with accounts and access ready for each new starter, so your hiring targets are not held up by IT.

Group systems and Microsoft 365

Whether you join the group tenant or run your own, we set identity, Conditional Access, sharing and retention to meet group standards and the Saudi requirements that apply.

Personal data (PDPL)

Group systems often move personal data across borders. We map where it goes and build the technical measures. Transfer decisions stay with your legal adviser.

Government customers

If your group sells to Saudi government entities, expect cyber security terms in those contracts: the NCA’s ECC-2:2024 requires entities in its scope to set requirements for their third parties. We help you meet and evidence them.

Providers and suppliers

Contract terms, due diligence and periodic review for your IT and security providers, including where remote services are delivered from.
Programme facts come from the Saudi Press Agency (March 2025) and Mayer Brown’s summary of the RHQ rules, checked on 30 September 2026. Confirm current requirements with MISA and your advisers. This is not legal advice.

Where we help on data protection

Data protection

Group systems, cross-border data and the PDPL

The Saudi Personal Data Protection Law (PDPL) has been fully enforceable since 14 September 2024 and is overseen by SDAIA. A controller must notify SDAIA of a personal data breach within 72 hours of becoming aware of it.
Regional headquarters often run group-wide systems, so personal data may leave the Kingdom. The PDPL has its own rules on transfers outside the Kingdom, so map where your data goes and ask your legal adviser what applies. We build the technical measures and the map; legal decisions stay with you.
How we work with you

From first assessment to steady state

1. Assess

A review of your group IT standards, office plans and hiring timeline against the Saudi requirements that apply, with a prioritised plan.

2. Set up

Office network, devices, accounts and a secure Microsoft 365 baseline, ready for your first hires.

3. Evidence

Registers, reports and records collected into an evidence pack your compliance lead can use.

4. Operate

Helpdesk and regular reviews, with reports written for your management and governing body.
Why Cre8 IT

Certified, experienced and open to scrutiny

Our own information security management system is certified to ISO 27001:2022, and we can share our certificate and scope as part of your due diligence.
Our Riyadh office is at Olaya Towers, and we support organisations in Riyadh on site and remotely. We will tell you plainly what we can and cannot evidence, including where each service is delivered from.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Guides

Guides for regional headquarters

Sourced to the regulator’s own text, dated and written by a named specialist.
PDPL

Saudi PDPL: an IT checklist for the Personal Data Protection Law

What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
4 min read · Reviewed 20 September 2026
Cloud and Microsoft 365

Microsoft 365 and cloud governance for Saudi organisations

What the NCA’s cloud controls say, where data localisation now sits, what Microsoft’s Saudi region means and a Microsoft 365 governance baseline.
3 min read · Reviewed 20 September 2026
Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026
FAQ

Regional headquarters questions

What IT does a new regional headquarters in Riyadh need?

An office network and Wi-Fi, managed devices, accounts and Microsoft 365, printing and meeting-room technology, local support, and security that meets both group standards and the Saudi requirements that apply. Plan it alongside the fit-out and your hiring, because operations are expected to start within six months of the licence.

Can our regional headquarters use the group’s Microsoft 365 tenant?

Often, yes. What matters is how it is configured and where data is stored. Ask your legal adviser whether any of your data is subject to Saudi localisation or transfer rules, and confirm with Microsoft or your licensing partner which services are hosted where.

Do group IT policies meet Saudi requirements?

Not automatically. We compare your group standards with the Saudi requirements that apply to your activities, show where they differ and help you close the gaps. Group policies do not replace your Saudi obligations.

Where is your Riyadh office?

Building 3074, Level 29, Tower B, Olaya Towers, Prince Mohammed Bin Abdulaziz Road, Riyadh. We support regional headquarters across the city, including in KAFD, on site and remotely.

Does using Cre8 IT make us compliant?

No provider can. You remain responsible for your obligations. We run and evidence the technical controls, help you prepare for reviews, and expect you to assess us as you would any provider.

Talk to a specialist about IT for your regional headquarters

Tell us about your licence timeline, your office and your group systems, and we will suggest a practical first step.