REGULATIONS ACROSS REGIONS / INTERMEDIATE

Saudi Arabia: SAMA's Quantum Deadlines For Banks And The NCA's Cryptography Rules

SAMA's August 2026 circular gives Saudi financial institutions dated quantum duties, built on years of binding NCA and SAMA cryptography controls. Here is what applies and when, as of October 2026.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Most post-quantum dates covered in this group are guidance or apply only to government systems. Saudi Arabia is different. On 27 August 2026 the Saudi Central Bank (SAMA) issued a circular that gives every institution it supervises two dated quantum duties: classify cryptographic assets by the end of 2026 and complete a quantum risk assessment by the end of March 2027.1 As of October 2026, research for this group found no other binding instrument that sets dated post-quantum duties for a whole financial sector.

The circular did not arrive in a vacuum. Many Saudi entities already work under binding cryptography controls from the National Cybersecurity Authority (NCA), and all SAMA member organisations under SAMA’s own Cyber Security Framework. This article explains the circular, the controls beneath it, and what the time left means in practice. It is general information, not legal advice.

What The SAMA Circular Requires

Circular 482021280, titled “Enhancement of Operational Resilience to Address Quantum Computing Risks”, is listed as in force in the SAMA Rulebook and is addressed to financial institutions under SAMA’s supervision.1 Status: Binding. It sets four measures:

  1. Quantum risk assessment. Carry out an enterprise-level assessment of quantum computing risks, aligned with the institution’s enterprise risk management, covering at least operational, legal, regulatory and strategic risks, including people-related risks, and develop action plans. Deadline: end of the first quarter of 2027.
  2. Cryptographic asset procedures. Make sure the procedures for identifying and classifying all cryptographic assets are accurate and comprehensive. That means linking data, systems and services to their cryptographic assets, classifying them by sensitivity and by priority for migration, and assessing the resilience of priority assets, including constraints and third-party dependencies. Deadline: end of the fourth quarter of 2026.
  3. Plans for priority assets. Develop plans to reach the required level of cryptographic resilience, or suitable alternatives, for all priority assets. No date is given.
  4. Governance. Put quantum risk on the agenda of the Board’s information security and risk committees as a regular item, with challenges and recommendations reported to the Board or its equivalent. No date is given.
  1. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  2. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Complete a quantum risk assessment with action plans.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

Countdowns run to the end of each deadline date (UTC) and are calculated in your browser. "Binding" means legally or contractually required; other labels describe supervisory expectations, guidance, drafts or announcements. Always check the source for the current text.

The order of the two dates is worth reading carefully. The inventory procedures come first, at the end of 2026, and the risk assessment follows a quarter later. The assessment builds on the classification: you cannot rank quantum exposure across the business without knowing which systems use which cryptography.

The Controls Underneath

SAMA’s circular sits on top of two older layers of binding cryptography controls.

NCA Essential Cybersecurity Controls. The current edition, ECC-2:2024, applies to government entities in the Kingdom and their affiliated companies, and to private sector entities that own, operate or host critical national infrastructure.2 Subdomain 2-8 covers cryptography. Entities must identify, document and approve their cryptography requirements, implement them, and review them periodically. Control 2-8-3 says those requirements must include at least the NCA’s National Cryptographic Standards, at a level chosen by the sensitivity of the data and systems, and must cover approved cryptographic solutions, key management through the lifecycle, and encryption of data in transit and at rest. Status: Binding for entities in scope.

NCA National Cryptographic Standards. NCS-1:2020, first issued in July 2020, defines two strength levels: MODERATE, which targets 128-bit security, and ADVANCED, which targets 256-bit security.3 The levels have real consequences. RSA and finite-field Diffie-Hellman need keys of at least 3,072 bits at MODERATE and are not accepted at all at ADVANCED. For TLS 1.3, the only accepted cipher suite at either level is TLS_AES_256_GCM_SHA384. The standard’s post-quantum appendix acknowledges the quantum risk to RSA, DSA and ECDSA, and states that post-quantum cryptography will be considered in upcoming versions of the standard.3 As of October 2026, no final updated edition with post-quantum algorithms was confirmed from the NCA’s site.

SAMA Cyber Security Framework. Section 3.3.9 of SAMA’s framework requires member organisations to define, approve and implement a cryptographic security standard, monitor compliance with it, and periodically evaluate the effectiveness of cryptographic controls.4 The standard must list approved solutions and their restrictions, say when they apply, and cover key management, including lifecycle, archiving and recovery. Status: Binding for SAMA member organisations.

  1. SAMA Circular 482021280 (27 August 2026)Asset classification procedures by end Q4 2026; quantum risk assessment and action plans by end Q1 2027; plans for priority assets; Board-level monitoring. Binding.
  2. SAMA Cyber Security Framework, Section 3.3.9An approved cryptographic standard, compliance monitoring, periodic evaluation and key lifecycle management. Binding.
  3. NCA Essential Cybersecurity Controls ECC-2:2024, Subdomain 2-8Documented cryptography requirements that include at least the National Cryptographic Standards. Binding for institutions in ECC scope.
  4. NCA National Cryptographic Standards NCS-1:2020MODERATE and ADVANCED levels; RSA not accepted at ADVANCED, elliptic curve algorithms still accepted; post-quantum cryptography to be considered in later versions. Binding through ECC 2-8-3 for institutions in ECC scope.
The Saudi cryptography stack for a SAMA-regulated institution in NCA ECC scope, as of October 2026. The highlighted layer carries the dates.

Why Saudi Arabia Stands Out

Two features make the Saudi position unusual. The first is the combination of a binding instrument with near-term dates. The other financial supervisors covered in this group mostly recommend: Switzerland’s FINMA recommends a roadmap by mid-2027,5 and Singapore’s MAS has said it will issue expectations with milestones later in 2026.6 The second is that the NCA standards already link the choice of algorithm to the sensitivity of the data. At the ADVANCED level, RSA and finite-field Diffie-Hellman are not accepted, but elliptic curve algorithms are, and those are just as exposed to a future quantum computer.3 Choosing ADVANCED therefore does not remove the post-quantum work.

The neighbouring comparison is the UAE, where the National Encryption Policy describes what a post-quantum transition plan should contain in more detail but sets no date. See the UAE article and the overview of post-quantum and cyber regulation in 2026.

Working Back From The Deadlines

With the end of 2026 close, the inventory duty is the immediate one. The circular asks for procedures that are accurate and comprehensive, so two kinds of evidence follow from the wording: the method for finding cryptographic assets, and the classified result, ranked by sensitivity and migration priority. Institutions that already maintain a cipher suite inventory for PCI DSS requirement 12.3.3 or a certificate register for other regimes have a starting point, though neither covers SAMA’s classification fields on its own. Which Regulators Require A Cryptographic Inventory? compares the fields each regime asks for, and Cryptography Compliance covers PCI DSS and DORA in depth.

Saudi AI rules, including SDAIA’s frameworks, are outside this article; see AI rules in the UAE and Saudi Arabia in the AI Governance group.

Footnotes

  1. Saudi Central Bank (SAMA), Circular 482021280, “Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026 (English translation in the SAMA Rulebook). rulebook.sama.gov.sa ↩ ↩2

  2. National Cybersecurity Authority, “Essential Cybersecurity Controls (ECC-2:2024)”, 2024. cdn.nca.gov.sa ↩

  3. National Cybersecurity Authority, “National Cryptographic Standards (NCS-1:2020)”, July 2020. nca.gov.sa ↩ ↩2 ↩3

  4. Saudi Central Bank (SAMA), “Cyber Security Framework, 3.3.9 Cryptography”, SAMA Rulebook. rulebook.sama.gov.sa ↩

  5. FINMA, Guidance 05/2026 “Quantum computing”, 9 July 2026. finma.ch ↩

  6. Monetary Authority of Singapore, Managing Director’s remarks on the MAS Annual Report 2025/2026, 28 July 2026. mas.gov.sg ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.