
On June 28, 2026, Saudi Arabia's SASO put a revised interoperability whitelist for biometric readers into effect, replacing the previous acceptance basis tied to older certification results. The change matters because the new list only accepts devices certified to ISO/IEC 30107-3:2025 Level 3, which directly affects product eligibility in KSA government procurement and large infrastructure tenders. For manufacturers, exporters, procurement teams, certification-related service providers, and project delivery partners, this is not simply a technical update; it changes the compliance threshold that determines whether a device can remain commercially usable in key public-sector buying scenarios.
The confirmed change is that SASO activated a new interoperability whitelist for biometric readers at 00:00 on June 28, 2026.
Under this update, all products relying on ISO/IEC 30107-3:2017 certification were removed from the whitelist.
The new whitelist includes only devices that have obtained ISO/IEC 30107-3:2025 Level 3 certification, described in the provided event summary as covering liveness detection, multimodal fusion, and resistance to adversarial samples.
The event summary also states that about 37% of existing models from leading Chinese manufacturers were removed from the list, with a direct effect on bidding eligibility for KSA government procurement and large infrastructure projects.
From an industry perspective, the most immediate effect for device makers is at the model qualification level. If a product was previously positioned for KSA projects on the basis of ISO/IEC 30107-3:2017 certification, that basis no longer supports whitelist inclusion under the updated rule. The practical concern is not only certification status, but whether each specific model intended for sale, tender participation, or shipment remains aligned with the current whitelist requirement.
What deserves closer attention is the linkage between certification and market access. Product planning, model portfolio decisions, and bid support documentation may all need to be checked against the new Level 3 requirement before commercial commitments are made.
For procurement entities and bidding teams, the rule change affects pre-bid screening and technical compliance review. Because the event summary explicitly links whitelist status to eligibility in KSA government procurement and large infrastructure tenders, any mismatch between a proposed device and the current whitelist could affect tender participation at the qualification stage or during technical evaluation.
Analysis shows that buyers, EPC participants, and bid coordinators should pay closer attention to whether tender files, technical schedules, and compliance submissions reference the updated whitelist basis rather than legacy certification language.
For certification-related companies and testing service institutions, the change raises the importance of document control and evidence alignment. The issue is no longer whether a device once held a recognized anti-spoofing certification, but whether the documentation package now matches ISO/IEC 30107-3:2025 Level 3 as required for whitelist inclusion.
Observably, this can affect technical files, compliance statements, laboratory reports, model declarations, and any submission materials used to support procurement, import coordination, or project acceptance. The operational risk lies in using outdated references in documents that still circulate internally or across channel partners.
Channel partners, supply-chain service providers, and after-sales teams may also need to reassess which models can still be supplied into affected projects. Where a model has been removed from the whitelist, the impact may extend beyond new sales discussions into delivery scheduling, substitution planning, and installed-base support expectations tied to project contracts.
Analysis shows that the main point to watch is whether commercial and delivery teams continue offering configurations that no longer match procurement-facing compliance requirements. In practice, this turns a standards update into a coordination issue across sales, logistics, service, and project execution.
It is more appropriate to understand this update as a model eligibility issue rather than a broad brand-level issue. Companies active in the KSA market should review each biometric reader model intended for quotation, bid participation, or delivery and confirm whether its certification basis matches ISO/IEC 30107-3:2025 Level 3 and current whitelist inclusion.
What deserves closer attention is the consistency of tender documents and technical annexes. Where internal templates, distributor materials, or project files still cite ISO/IEC 30107-3:2017-based recognition, those references may no longer support the intended use case in KSA public procurement or large project bidding. Companies should therefore review compliance statements, technical datasheets, test references, and bid attachments for outdated wording.
The provided information confirms the whitelist change and its immediate procurement relevance, but it does not provide detailed downstream enforcement procedures. For that reason, companies should continue monitoring official wording, procurement notices, qualification requirements, and project-side technical specifications to see how the new threshold is described and applied in practice.
Analysis shows that firms already engaged in KSA opportunities should review whether pending bids, planned shipments, or supplier commitments involve models removed from the whitelist. Even without further confirmed details on transitional handling, this is the point where compliance review, procurement planning, and delivery risk begin to intersect.
Observably, this development is better read as an execution-level market access signal than as a general policy discussion. The reason is straightforward: the change is already tied to whitelist inclusion and to bidding eligibility in defined procurement scenarios. That makes it more concrete than a draft rule or a broad regulatory direction.
At the same time, analysis shows that the market still needs to watch how the requirement is reflected in bid documents, project qualification checks, and supporting technical evidence. The confirmed facts establish the new threshold, but the consistency of downstream execution will determine how much operational disruption different suppliers actually face.
From an industry perspective, the significance of this event is that a standards reference has become a direct commercial filter. The move from acceptance of ISO/IEC 30107-3:2017-based products to a whitelist limited to ISO/IEC 30107-3:2025 Level 3 devices changes how suppliers should approach compliance readiness for the KSA market.
It is more appropriate to understand this not as a theoretical standards revision, but as a landed rule change with immediate relevance for procurement access, bid eligibility, and model selection. The broader market effect still requires continued observation, especially in relation to execution language, tender practice, and industry response.
This article is based on the user-provided news title, event date, and event summary. For events of this type, commonly relevant source categories include official notices, releases from regulatory authorities, trade or customs-related information, industry association updates, standards organization documents, and reporting by authoritative media.
No specific official source link was provided in the input, so the exact official publication path still needs to be verified on an ongoing basis. Observably, the main follow-up points worth monitoring are detailed implementation language, certification acceptance practice, changes in tender documents, market feedback, and how affected companies adjust execution and product positioning.
Related News
Thermal Sensing
Popular Tags
Related Industries
Weekly Insights
Stay ahead with our curated technology reports delivered every Monday.