KAFD · Riyadh

IT and cyber security for firms in the King Abdullah Financial District.

Managed IT, Microsoft 365 governance and cyber security for financial institutions, advisory firms and regional headquarters in KAFD, from an ISO 27001:2022 certified team with an office in Riyadh.
Built for KAFD

A district of financial firms and regional headquarters

The King Abdullah Financial District (KAFD) is a mixed-use financial district in Riyadh’s Al-Aqeeq neighbourhood, developed and managed by a company owned by the Public Investment Fund. It is home to the Saudi Exchange (Tadawul) and to many financial firms and regional headquarters of multinationals.
Being in KAFD does not change which rules apply to you. That depends on your licence and your activities, as it does anywhere in the Kingdom. We help firms in the district meet the expectations that apply to them: the SAMA framework where it covers you, the NCA’s controls where you are in scope, and the PDPL for personal data.

What KAFD firms ask us for

Which rules apply

What applies to a firm in KAFD, and what we do for each

The district does not set its own rules. These are the ones firms there most often ask us about.

Financial institutions (SAMA)

If SAMA’s Cyber Security Framework covers you, we help you evidence its four domains and the maturity level it expects.

Capital market firms

If you are authorised by the Capital Market Authority, your compliance team will confirm which of its requirements apply. We map the technical controls to that list and keep the evidence.

Government-linked entities (NCA)

If you are in the scope of the NCA’s ECC-2:2024, we map the technical controls to its four domains and prepare evidence for assessment.

Personal data (PDPL)

Access control, encryption, logging and a rehearsed 72-hour breach process, with the legal decisions left to your data protection lead.

Regional headquarters

Group IT policies do not replace Saudi obligations. We map your group standards to the local requirements and show where the gaps are.

Providers and suppliers

Contract terms, due diligence and periodic review for your IT and security providers, including where remote services are delivered from.
District facts come from public sources (Wikipedia’s KAFD article and the Saudi Exchange’s listed address), checked on 20 September 2026. Regulatory summaries are for orientation. Confirm the current wording with the regulator. This is not legal advice.

Where we help on data protection

Data protection

Group systems, cross-border data and the PDPL

The Saudi Personal Data Protection Law (PDPL) has been fully enforceable since 14 September 2024 and is overseen by SDAIA. A controller must notify SDAIA of a personal data breach within 72 hours of becoming aware of it.
Regional headquarters often run group-wide systems, so personal data may leave the Kingdom. The PDPL has its own rules on transfers outside the Kingdom, so map where your data goes and ask your legal adviser what applies. We build the technical measures and the map; legal decisions stay with you.
How we work with you

From first assessment to steady state

1. Assess

A cyber health audit and gap assessment against the rules that apply to your firm, with a prioritised plan.

2. Secure

A secure baseline: multi-factor authentication, Conditional Access, managed devices, endpoint protection, backup and recovery.

3. Evidence

Registers, reports and records collected into an evidence pack your compliance lead can use.

4. Operate

Helpdesk and regular reviews, with reports written for your management and governing body.
Why Cre8 IT

Certified, experienced and open to scrutiny

Our own information security management system is certified to ISO 27001:2022, and we can share our certificate and scope as part of your due diligence.
Our Riyadh office is at Olaya Towers, and we support organisations in Riyadh on site and remotely. We will tell you plainly what we can and cannot evidence, including where each service is delivered from.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Guides

Guides for firms in KAFD

Sourced to the regulator’s own text, dated and written by a named specialist.
SAMA

SAMA Cyber Security Framework: what Saudi financial institutions need to evidence

Who the SAMA Cyber Security Framework applies to, its four domains, the maturity level SAMA expects and the IT evidence a member organisation keeps.
3 min read · Reviewed 20 September 2026
PDPL

Saudi PDPL: an IT checklist for the Personal Data Protection Law

What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
4 min read · Reviewed 20 September 2026
NCA ECC

NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence

A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
6 min read · Reviewed 20 September 2026
FAQ

KAFD questions

Is KAFD a free zone like DIFC or ADGM?

KAFD is a mixed-use district of Riyadh owned by a subsidiary of the Public Investment Fund. We have not found a separate financial-services regulatory regime for it comparable to DIFC’s or ADGM’s, so the rules that apply depend on your licence and activities. Confirm the position for your own firm with your legal adviser.

Do you have an office in KAFD?

Our Riyadh office is at Building 3074, Level 29, Tower B, Olaya Towers, Prince Mohammed Bin Abdulaziz Road. We support organisations in Riyadh on site and remotely.

Which rules apply to a firm in KAFD?

It depends on your licence and activities, not your address. SAMA’s Cyber Security Framework covers banks, insurers, financing companies, credit bureaus and financial market infrastructure. The NCA’s ECC-2:2024 covers government agencies and their affiliates and private entities running critical national infrastructure. The PDPL covers personal data. See our SAMA guide and NCA guide.

Can you help a regional headquarters that follows group IT policies?

Yes. We compare your group standards with the Saudi requirements that apply, show where they differ and help you close the gaps. Group policies do not replace your Saudi obligations.

Does using Cre8 IT make us compliant?

No provider can. You remain responsible for your obligations. We run and evidence the technical controls, help you prepare for reviews, and expect you to assess us as you would any provider.

Talk to a specialist about IT for your KAFD office

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.