Capital market institutions · CMA

IT and cyber security built for CMA-licensed firms.

Managed IT, Microsoft 365 governance and cyber security for asset managers, brokers, investment banks, advisers and custodians licensed by the Capital Market Authority, from an ISO 27001:2022 certified team with an office in Riyadh.
Built for capital market firms

A capital market firm’s IT is more than uptime

The CMA’s Cybersecurity Guidelines for Capital Market Institutions expect a cyber security department separate from IT, documented and approved controls, 12 months of security logs, cloud services hosted in Saudi Arabia and immediate reporting of incidents to the CMA. Your compliance team should not have to chase screenshots.
Cre8 IT runs the technical controls you own and produces the records that show they work: monthly reports on multi-factor authentication, patching and backups, access reviews and incident readiness. You keep governance and accountability. We make the evidence easy to find.

What CMA-licensed firms ask us for

What the regulator expects

How we support the CMA Cybersecurity Guidelines

The guidelines have four domains. These are the areas a reviewer is likely to test and what we do for each.

Governance (4.1)

Your board is responsible for cyber security, and a cyber security department separate from IT runs it. We document the technical controls your policies rely on and report on them to your Head of Cybersecurity.

Risk, review and audit (4.2)

A live asset register and inputs from our reports, so your risk record rests on real data, plus the records an independent auditor will ask to see.

Operational controls (4.3)

Multi-factor authentication for remote and privileged access, device management, patching, vulnerability scanning, encryption, backup and logging, reported monthly.

Third parties and cloud (4.4)

You assess your providers, and we expect to be assessed like any provider: certificate and scope, contract terms, and where each service and each piece of data is hosted.

Logs and monitoring

Security event logs kept for at least 12 months and monitored around the clock. We check your Microsoft 365 audit retention and where your logs are stored and monitored.

Incident readiness

The CMA expects to hear about an incident immediately, and an official report once you resume operations. We help you write and rehearse the plan and keep the records that report needs.
Summary for orientation, checked against the CMA’s published guidelines on 30 September 2026. Confirm the current wording with the CMA. This is not legal advice.

Where we help on data protection

Data protection

The PDPL and client data

The Saudi Personal Data Protection Law (PDPL) has been fully enforceable since 14 September 2024 and is overseen by SDAIA. It covers the personal data you hold on clients and staff, and a controller must notify SDAIA of a personal data breach within 72 hours of becoming aware of it.
Access control, encryption, logging and retention are IT jobs, and we implement them. What personal data you hold, your lawful basis and your notices are legal jobs for your data protection lead or legal adviser.
How we work with you

From first assessment to steady state

1. Assess

A cyber health audit and gap assessment against the four domains of the CMA guidelines, with a prioritised plan.

2. Secure

A secure baseline: multi-factor authentication, Conditional Access, managed devices, endpoint protection, backup and recovery.

3. Evidence

Registers, reports and records collected into an evidence pack your compliance lead can use.

4. Operate

Helpdesk and regular reviews, with reports written for your management and governing body.
Why Cre8 IT

Certified, experienced and open to scrutiny

We have supported businesses since 2012. Our own information security management system is certified to ISO 27001:2022, and we can share our certificate and scope as part of your due diligence.
In Saudi Arabia we support Union Bancaire Privée KSA (UBP Saudi Arabia), which is licensed by the Capital Market Authority. In the UAE we also support a regulated advisory and investment firm, and helped it start small and grow fast.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Guides

Guides for capital market firms

Sourced to the regulator’s own text, dated and written by a named specialist.
CMA

CMA Cybersecurity Guidelines: what capital market institutions need to evidence

Who the CMA’s Cybersecurity Guidelines apply to, their four domains, the Head of Cybersecurity rule, cloud and outsourcing limits, incident reporting and the IT evidence to keep.
5 min read · Reviewed 30 September 2026
Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026
PDPL

Saudi PDPL: an IT checklist for the Personal Data Protection Law

What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
4 min read · Reviewed 20 September 2026
FAQ

CMA and capital market questions

Can Cre8 IT act as our Head of Cybersecurity?

No. The CMA guidelines say the cyber security department must be separate from the IT department and headed by a full-time, qualified Saudi employee. We support that person with technical controls, reports and evidence, and help them prepare for committee meetings and self-assessments.

Can a capital market firm outsource its security monitoring?

The CMA guidelines limit outsourced security operations monitoring to service providers within Saudi Arabia, and expect your cyber security department to assess the risks first. Always ask a provider, including us, where its monitoring centre is and who can access your data.

Do the SAMA framework and NCA ECC apply to CMA-licensed firms?

It depends on your licences and activities. The SAMA Cyber Security Framework covers SAMA’s member organisations, such as banks and insurers. NCA’s ECC-2:2024 covers government entities and private organisations that run critical national infrastructure. A group holding several licences may face more than one, so your compliance team should confirm which apply.

Does using Cre8 IT make us compliant with the CMA guidelines?

No provider can. You remain responsible for your obligations. We run and evidence the technical controls, help you prepare for self-assessments and reviews, and expect you to assess us as you would any provider.

Do you have an office in Riyadh?

Yes. Our Riyadh office is at Building 3074, Level 29, Tower B, Olaya Towers, Prince Mohammed Bin Abdulaziz Road, and we support firms in KAFD on site and remotely.

Talk to a specialist about your CMA obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.