A data centre business is not the same as a normal IT company. It may provide hosting, managed servers, colocation, cloud infrastructure, backup, disaster recovery or secure enterprise services. Each model has different capital, site, power, fibre, security and licence needs.
Oman now has a specific regulation for cloud computing and data centre services. A company should define its exact model before it registers activities, signs a property lease, orders equipment or promises a service level to customers.
A small cloud reseller may start without building a facility. A colocation operator or large data centre needs a much deeper project plan. The correct route depends on who owns the servers, where the data is stored, who provides connectivity and which customers will use the service.
Start with the service model
- Will you resell another provider’s cloud service?
- Will you manage customer servers in a rented rack?
- Will you sell colocation space in your own facility?
- Will you operate an IaaS, PaaS or private-cloud platform?
- Will you host government or regulated-sector data?
- Will you operate an international hosting area or telecom interconnection service?
The answers change the permit, facility, contract, workforce and investment plan.
Data centre and cloud business models at a glance
| Model | What the business sells | Main investment area | Main regulatory question |
|---|---|---|---|
| Cloud agent | Introductions or sales support for one or more cloud providers | Sales, contracts and customer support | Which cloud-provider category applies? |
| Cloud reseller or aggregator | Resold or combined cloud packages | Platform, billing, support and supplier agreements | TRA permit and clear responsibility to subscribers |
| Managed hosting | Managed servers, storage, backup and technical support | Rented racks, hardware, staff and monitoring | Hosting permit, data location and service contract |
| Colocation | Secure rack, cage, power and connectivity space | Facility, power, cooling, fire safety and security | Data centre category, permit and open access |
| Cloud infrastructure | IaaS, private cloud, storage, compute and network services | Compute platform, automation, security and operations | Cloud permit, data classification and customer sector |
| Disaster recovery | Backup site, replicated systems and recovery services | Second site, replication links and recovery operations | Whether data may be copied to the proposed location |
What makes this different from an ordinary IT company?
A normal software company builds or supports digital products. A data centre or cloud provider stores, processes, transports or protects customer content through infrastructure that it controls or manages.
The difference is important. Software development, IT consulting and office-network support do not automatically cover cloud hosting, colocation or data centre operations. Read the separate guide to IT and software business activities in Oman when the planned company is mainly a software or support business.
Small provider
A smaller provider may rent space from an existing data centre, lease servers, use a wholesale cloud platform or resell a principal provider’s services. This lowers the building cost, but it does not remove the need to identify the correct regulated model.
Large infrastructure project
A large project may own the building, utility connection, cooling plant, fire systems, security controls, carrier rooms, racks and cloud platform. The project must coordinate company, TRA, MTCIT, land, construction, utility, environmental, civil-protection and workforce requirements.
Core legal and approval pathway
TRA Decision 1152/2/19/2024-20 regulates cloud computing and data centre services in Oman. Except for licensed fixed public telecommunications providers, a legal person cannot establish, operate or provide these services without the required TRA permit.
The regulation also states that the applicant’s commercial registration must be focused on telecommunications and information-technology services and related activities identified by the TRA. A broad company with unrelated trading activities should not be assumed to fit this permit.
| Stage | Authority or party | What to confirm |
|---|---|---|
| Company structure and activities | MOCIIP / Oman Business Platform | Legal form, focused ICT activities and foreign-ownership position |
| Cloud or data centre permit | Telecommunications Regulatory Authority | Provider category, data centre category, documents, fee and operating model |
| Government cloud accreditation | MTCIT | Required before serving state administrative units and public legal persons |
| Personal data compliance | MTCIT | PDPL role, notices, consent, special-data permits, security and transfers |
| Property and construction | Municipality, zone authority or Madayn | Land use, building plans, structural, electrical and mechanical approvals |
| Fire and civil protection | Civil Protection and Ambulance Authority | Preliminary plan approval, final inspection and operating safety |
| Power and utilities | Relevant electricity and utility companies | Available capacity, connection cost, tariff and delivery schedule |
| Environmental classification | Environment Authority | Whether generators, fuel, cooling or construction require an environmental permit |
| Labour and staffing | Ministry of Labour and TRA requirements | Omanisation plan, legal professions and non-Omani workforce caps |
Important: A commercial registration is not the operating permit. A property lease is not a data centre approval. MTCIT accreditation for government work is also separate from the TRA permit.
TRA cloud-provider types
The regulation recognises four cloud-provider types. The business should identify the correct type before it prepares its application and contracts.
- Main cloud service provider: provides cloud services to the public.
- Cloud service aggregator: combines cloud services into one or more packages.
- Cloud service reseller: resells products or services from a main provider, alone or inside a package.
- Cloud service agent: acts as an intermediary between one or more providers and subscribers.
This classification allows an asset-light business to enter the market, but it does not mean that a reseller or agent can ignore the permit and subscriber-protection rules.
Hosting and managed servers
Managed hosting normally combines server space with monitoring, patching, backup, security, support and incident handling. The provider may own the servers or manage customer equipment inside a third-party data centre.
The contract should make the responsibility clear. It should state who owns the hardware, who controls administrator access, where backups are stored, who approves changes, what support is included and what happens when the service ends.
- Define managed and unmanaged responsibilities.
- List included operating systems, licences and security tools.
- Set backup frequency, retention and restoration testing.
- State maintenance windows and emergency-change rules.
- Explain remote access and privileged-account controls.
- Identify every subcontractor and external cloud platform.
Colocation business
A colocation operator sells secure space, power, cooling, connectivity and physical access. Customers normally keep ownership of their servers and network equipment.
The commercial plan should separate cabinet space, power allocation, cross-connects, remote-hands support, access requests, storage, installation work and additional security. Power should not be priced only as a simple monthly estimate. The contract should explain metering, reserved capacity, overuse and future expansion.
If the facility includes an international hosting area, telecom traffic covered by the regulation must pass through a licensed fixed public telecommunications provider. A data centre permit does not by itself create a public telecom licence.
Cloud infrastructure
A cloud infrastructure provider may sell virtual machines, storage, networking, backup, private-cloud environments or managed platforms. The business needs more than servers. It needs provisioning, billing, monitoring, capacity management, identity controls, customer isolation and a clear support model.
Before launch, the operator should test how it will handle a failed host, a storage problem, a network incident, a security event, a customer exit and a sudden increase in demand. The service catalogue should not promise capacity that is not reserved or tested.
Disaster recovery services
Disaster recovery can include backup storage, replicated virtual machines, standby infrastructure, recovery testing and an alternate work location. The customer should choose a recovery-time objective and recovery-point objective that match its real business risk.
A second site is useful only when it is independent enough from the first site. Review power, fibre, flood, access, supplier and regional risks. A second room in the same building is not a full disaster-recovery location.
Cross-border replication is not automatically allowed. Data classification, the TRA regulation, the Personal Data Protection Law, customer-sector rules and government-cloud standards may require local storage or prior approval.
Site, power, cooling and fire protection
Do not choose a site only because rent or land is cheap. A data centre can become unusable if the required power, fibre route, cooling design or safety approval is not available.
| Area | Questions to answer before commitment |
|---|---|
| Land and building use | Is the activity allowed at the site? Can the building support the equipment, plant and security zones? |
| Grid capacity | How much firm capacity is available, when can it be delivered and what network work is required? |
| Backup power | What generator, fuel, switchgear, maintenance and test plan supports the promised service? |
| Cooling | Can the design handle Oman’s heat, dust and humidity at the planned IT load? |
| Fire protection | Are detection, suppression, escape, compartment and emergency plans accepted by the authority? |
| Water and drainage | Does the cooling method need water? How will leaks, drainage and water risk be controlled? |
| Flood and weather | Is the site exposed to wadi flow, surface water, coastal risk or access problems during severe weather? |
| Maintenance access | Can heavy equipment, fuel, parts and technicians reach the site without affecting secure areas? |
| Future capacity | Can power, cooling, floor space and fibre grow without rebuilding the whole facility? |
Oman’s national building code and the relevant municipality or zone procedures apply to building design and construction. Civil-protection approval should be built into the plan from the start, not added after the server rooms are complete.
For a large facility, compare suitable technology and industrial locations before signing. Industrial location advisory in Oman can help structure the location review. A regional or export-led model may also need a free-zone investment assessment in Oman.
No universal 2N rule: Do not copy one operator’s power or cooling design and present it as the legal minimum for every project. The design should match the selected data centre category, ISO/IEC 22237, customer risk, service level and authority approvals.
Electricity cost and capacity
Power is normally one of the largest operating costs. The Authority for Public Services Regulation states that cost-reflective tariffs apply to government, commercial and industrial customers whose electricity use exceeds 100 MWh per year. A serious data centre project should model energy use by month and by load level before it agrees customer prices.
- Obtain a written capacity and connection review.
- Separate IT load from cooling and building load.
- Model the tariff, demand and network charges.
- Include generator testing and fuel cost.
- Include power losses and unused reserved capacity.
- Test the effect of low early occupancy on the unit cost.
Fibre and connectivity
Connectivity should be planned before the building is final. The project should confirm which licensed carriers can reach the site, how the fibre enters the property, whether two routes are physically separate and how long new construction may take.
- Use more than one carrier where the service requires it.
- Check that routes do not share the same duct, bridge or exchange point.
- Reserve space for carrier equipment and cross-connects.
- Define who owns and maintains the internal fibre.
- Plan internet, private circuits, cloud connections and customer cross-connects separately.
- Confirm international traffic and interconnection duties with the TRA and licensed telecom providers.
Muscat and Salalah already host major data centre infrastructure. This does not make either city automatically correct. Choose the location after studying customers, carriers, grid capacity, land, climate, access and disaster-recovery strategy.
Physical and cyber security
The TRA regulation requires data centre providers to apply security, IT-service and business-continuity measures based on ISO 27001, ISO 20000 and ISO 22301. Category-four providers must also obtain the international accreditation stated for ISO/IEC 22237 facilities.
The regulation requires internal and independent external security audits at least once each year. It also requires access control, protection of equipment and buildings, staff training and records for CCTV, entry, exit and unauthorised-access detection.
Physical controls
- Secure perimeter and controlled entry
- Visitor approval and escort
- Separate customer and plant areas
- CCTV and access records
- Equipment delivery and removal control
- Fire, leak and environment monitoring
Cyber controls
- Privileged-access management
- Network separation and secure administration
- Logging and security monitoring
- Patch and vulnerability management
- Backup and restoration tests
- Incident response and evidence handling
Data classification and location
The TRA regulation uses four information-security levels. These levels affect which category of data centre may process the content and whether the content may be transferred outside Oman.
| Security level | General content type | Permitted data centre category |
|---|---|---|
| Level 1 | Non-sensitive private content and open data | Categories 1, 2, 3 or 4 |
| Level 2 | Sensitive private content and non-sensitive public-entity content | Categories 2, 3 or 4 |
| Level 3 | Regulated private-sector content, including listed energy, utility, telecom and insurance content | Categories 3 or 4 |
| Level 4 | Highly sensitive public content and listed financial, banking and health content | Category 4 |
Cloud content at Levels 3 and 4 cannot be moved outside Oman without TRA approval. A data centre provider also needs TRA approval before moving data outside Oman. The Personal Data Protection Law and customer-sector rules may add further limits.
For government cloud services, the MTCIT Cloud and Hosting Services Standard states that government data, including backups, must remain inside Oman. The customer and provider should agree the classification before service starts.
Personal data protection
Oman’s Personal Data Protection Law was issued by Royal Decree 6/2022. Its Executive Regulation was issued by Ministerial Decision 34/2024. A provider should identify whether it is a controller, processor or both for each service.
- Use a clear privacy notice and lawful processing basis.
- Obtain the required consent where consent is used.
- Check whether a permit is needed before processing data listed in Article 5 of the law.
- Define controller and processor duties in writing.
- Control subcontractors and remote support access.
- Set retention, return and secure-deletion rules.
- Review every international transfer before it starts.
- Keep evidence of security and incident handling.
Customer contracts, SLA and incidents
The TRA regulation requires clear information on service conditions, service levels, payment and any available civil-liability insurance. The service contract must include the provider’s address and contact details, service description, term, tariff, payment, termination terms and SLA details.
The contract cannot remove the provider’s responsibility for customer-content loss or damage, failure to meet service quality, or information-security breaches. This makes careful risk control, insurance review and realistic SLA wording important.
- Notify affected subscribers within 72 hours of an information-security breach or data leak that may affect their content or service.
- Notify the TRA within 12 hours of an incident or technical fault that affects the service.
- Notify the TRA and the Cyber Defence Centre within 12 hours for the security events defined in the regulation.
- Report actual SLA performance every 12 months or when the subscriber asks.
- At contract end, provide or transfer the customer content within seven days after request.
- After handover, delete and destroy the content, metadata and backups so they cannot be recovered.
Government and public-sector customers
A TRA permit is not enough to serve government administrative units and other public legal persons. The provider must obtain MTCIT accreditation under the ministry’s cloud and hosting services programme.
The MTCIT process includes a technical assessment and service documents. The ministry publishes an accredited-provider register. A company should not market itself as government-accredited until its name and approved service scope are confirmed.
Workforce and Omanisation
Data centre and cloud operations need technicians, network staff, security staff, facilities engineers, customer support and commercial staff. The TRA regulation sets specific maximum percentages for non-Omani workers.
| Time from permit effective date | Maximum total non-Omani workforce |
|---|---|
| From the effective date | 20% |
| After 24 months | 18% |
| After 36 months | 13% |
| After 48 months | 10% |
The annex also sets lower role-based limits over time for management, marketing, finance, IT, operations and technical work. Build the Omani recruitment and training plan before the permit becomes active. For practical planning, use workforce compliance support in Oman.
Short company, residence and banking pathway
- Write a one-page service and infrastructure model.
- Identify the correct cloud-provider and data centre categories.
- Search the commercial activities and confirm that the CR can meet the TRA focus requirement.
- Check the restricted activities for foreign investors in Oman.
- Select a legal form and location.
- Register the company and complete the required foreign-investment steps.
- Apply for the TRA permit with the required documents.
- Complete property, utility, fire, environmental and construction approvals where applicable.
- Build the privacy, security, SLA and workforce systems.
- Apply for MTCIT accreditation if public-sector customers are in scope.
For the wider company process, use Oman company setup advisory. Owner residence and specialist staff residence are separate applications. See residency services for company owners for the immigration sequence.
Bank review is important because the business may have large capital payments, imported equipment, recurring subscriptions, customer deposits and cross-border supplier contracts. Prepare a clear source-of-funds file, project budget, customer model, shareholder structure and transaction forecast. Business banking preparation support can help organise this file, but final approval belongs to the bank.
Permit fees and cost planning
The TRA regulation lists the following permit fees. These are only the TRA regulatory fees. They do not include company registration, property, construction, power, fibre, equipment, audits, insurance, staff or professional work.
| TRA fee item | Listed fee |
|---|---|
| Permit application study | OMR 100 |
| Issue or renew a cloud-services permit | OMR 500 |
| Cloud-services permit for an eligible SME with an Entrepreneurship Card | OMR 250 |
| Issue or renew a Category 1 or 2 data centre permit with cloud services | OMR 500 |
| Issue or renew a Category 3 or 4 data centre permit with cloud services | OMR 1,000 |
Main capital and operating cost groups
- Land, lease, building and fit-out
- Grid connection, transformers, switchgear, UPS and generators
- Cooling, ventilation, controls and water systems
- Fire detection, suppression and civil-protection works
- Racks, cabling, carrier rooms and cross-connects
- Servers, storage, network and cloud software
- Security, monitoring, NOC and SOC systems
- Certifications, audits, legal work and insurance
- Omani staffing, training and specialist support
- Electricity, carrier, maintenance and spare-parts costs
Use the search Oman commercial activity codes tool to begin the activity review. It does not prove that the activity is open to foreign ownership or that the TRA will approve it.
You can also estimate company and investor residence costs. The estimator does not calculate land, data centre construction, electricity infrastructure, fibre, hardware, certifications, audits, environmental studies or sector permits.
Tax, VAT, withholding tax and imported-equipment treatment should be checked before supplier contracts are signed. Review Oman tax rules for companies as a separate planning step.
Common mistakes
- Registering a normal IT activity and assuming it covers hosting.
- Mixing unrelated trading activities into a CR intended for the TRA permit.
- Signing a building lease before checking grid and fibre capacity.
- Copying another data centre’s technical design as a legal minimum.
- Offering public telecom services without the correct licensed provider.
- Promising government hosting before MTCIT accreditation.
- Sending backups abroad without a data-classification and transfer review.
- Using an SLA that removes responsibility prohibited by the regulation.
- Ignoring the 12-hour and 72-hour incident-notification duties.
- Planning a mainly foreign technical workforce despite the TRA caps.
- Using the general company-cost calculator as a full project budget.
- Building one site without a tested recovery and customer-exit plan.
Practical pre-investment checklist
- Define the exact services and target customers.
- Choose the cloud-provider type and proposed data centre category.
- List every service that will appear on contracts and invoices.
- Confirm the commercial activities and ownership position.
- Prepare an initial TRA discussion file.
- Decide whether government accreditation is required.
- Classify the expected customer data.
- Map local and cross-border data flows.
- Complete a power-capacity and tariff study.
- Complete a fibre-route and carrier study.
- Compare land, building and zone options.
- Ask for civil-protection and environmental classification advice.
- Prepare a concept design and expansion plan.
- Build the Omani recruitment and training plan.
- Prepare customer contracts, SLA, privacy terms and exit rules.
- Prepare capital, operating and low-occupancy financial models.
- Confirm all live requirements again before payment or construction.
Frequently asked questions
Does a small cloud reseller need a TRA permit?
The regulation covers main providers, aggregators, resellers and agents. The exact permit route should be confirmed with the TRA before the service is offered.
Can a normal software company sell hosting?
Do not assume so. Software work and hosting are different activities. Hosting and cloud services may need the focused commercial activities and TRA permit required by the regulation.
How long is the TRA permit valid?
The regulation states that the permit is valid for three years and renews automatically unless the permit holder asks to cancel it before expiry. Fees must still be paid within the required period.
Is MTCIT accreditation required for private customers?
The specific accreditation rule applies before providing cloud or data centre services to government administrative units and other public legal persons. Private clients may still require sector, security or contractual standards.
Can customer backups be stored outside Oman?
Not automatically. The answer depends on the TRA security level, provider type, data centre duties, the Personal Data Protection Law, the customer sector and any government-cloud rule.
Does every data centre need the same power design?
No. The design should match the selected category, ISO/IEC 22237, the customer risk, the SLA and authority approvals. A design used by one existing facility is not automatically the legal minimum for all projects.
Can the company use mainly foreign technical staff?
The TRA regulation sets low and reducing limits for non-Omani staff. The total cap starts at 20% and falls to 10% after 48 months, with separate role-based limits.
How much capital is needed?
There is no reliable single amount. A reseller may need a limited operating budget. A colocation or data centre project may require major spending on land, power, cooling, fire safety, fibre, security, equipment and staff. Build a project-specific model.
Related Oman Verified guides
Omanisation basics
Understand the wider employment framework around the sector-specific TRA caps.
Oman Vision 2040
See how digital infrastructure fits within Oman’s wider investment and economic priorities.
Conclusion
A data centre, hosting or cloud infrastructure business in Oman can start as an asset-light reseller or as a large facility project. The first step is to define the exact service model. The next steps are activity selection, TRA permitting, data classification, location, power, fibre, security, contracts and Omani workforce planning.
Do not begin with the building or equipment order. Begin with the regulatory and commercial design. This reduces the risk of an unsuitable CR, an unusable site, a weak SLA or a service that cannot legally host the intended customer data.
Official sources
- Ministry of Justice and Legal Affairs — TRA Decision 1152/2/19/2024-20
- MTCIT — Cloud and hosting services accreditation
- MTCIT — Register of accredited service providers
- MTCIT — Cloud and Hosting Services Standard
- MTCIT — Cloud Computing First Policy
- MTCIT — Personal Data Protection Law and Executive Regulation
- Gov.om — Preliminary civil-protection approval for facility plans
- Ministry of Housing and Urban Planning — Oman Building Code
- Authority for Public Services Regulation — Electricity grid connection
- Authority for Public Services Regulation — Permitted electricity tariffs
- Environment Authority — Environmental permit service
- MTCIT — Data centre establishment investment opportunity
Official public information reviewed on 1 August 2026. Confirm the current requirements in the live government systems before submission.

