The CMA’s Cybersecurity Guidelines for Capital Market Institutions apply to firms licensed by the Capital Market Authority, such as asset managers, brokers, investment banks, advisers and custodians. They are issued as guidelines, but the CMA can apply them to any institution it supervises and checks implementation through periodic self-assessments. They have four domains: governance; risk management, review and audit; operational controls; and third parties. Key expectations include a cyber security department separate from IT and headed by a full-time, qualified Saudi employee, multi-factor authentication for remote and privileged access, security logs kept for at least 12 months, cloud services hosted in Saudi Arabia, and reporting incidents to the CMA immediately.
The guidelines are addressed to all capital market institutions: the firms the Capital Market Authority licenses to carry on securities business. The CMA licenses five activities:
The CMA describes the document as guidelines, and says it may apply them to any entity it supervises. Implementation is checked through periodic self-assessment questionnaires, in a way the CMA decides. In practice, treat them as the standard the CMA will measure you against.
Other rules can apply alongside them. The PDPL covers the personal data you hold. If your group also holds a SAMA licence, or runs critical national infrastructure, the SAMA framework or NCA’s ECC may apply too. Ask your compliance team which apply to your licence.
| Domain | What it covers |
|---|---|
| 4.1 Cybersecurity Governance | Board responsibility, the cyber security department and committee, data governance, strategy and policies, awareness and training, and cyber security in human resources. |
| 4.2 Cybersecurity Risk Management, Review and Audit | A risk management method, a single record of cyber security risks, and periodic review and independent audit of controls. |
| 4.3 Operational Cybersecurity Controls | Day-to-day controls, from asset management, access control and change management to logging, incident management, encryption, e-trading services, physical security, business continuity and BYOD. |
| 4.4 Third Party Cybersecurity | Contracts and suppliers, outsourcing and cloud computing. |
Most of the IT department’s daily work sits in 4.3. Domains 4.1 and 4.2 decide whether that work is documented, owned and reviewed.
The guidelines make the board fully responsible for cyber security, with the option to delegate to a committee. Beneath the board they expect:
This matters when you choose an IT provider. A provider can run and evidence technical controls, but it cannot be your Head of Cybersecurity, and your cyber security department should not simply be your IT team under another name.
These are the operational controls where reviewers most often ask the IT team for proof. The evidence column is our suggestion, not a CMA checklist.
| Control | What the guidelines ask | Typical evidence |
|---|---|---|
| Multi-factor authentication (4.3.4) | Multi-factor authentication for all remote access, and for sensitive systems and privileged accounts according to risk. | Conditional Access policies, coverage reports, a list of privileged accounts and access reviews. |
| Security event logs (4.3.8) | Logs kept for at least 12 months, monitored 24/7, with central analysis such as a SIEM. | Retention settings, SIEM coverage and monitoring reports. Microsoft 365’s standard audit log keeps 180 days, so 12 months usually needs a higher licence or a SIEM. |
| Vulnerabilities and testing (4.3.3, 4.3.12, 4.3.13) | Regular scanning of all assets, patch timelines by severity, security testing of changes, and penetration testing of online services at least once a year. | Scan and patch reports, change records, penetration test reports and records of fixes. |
| Business continuity (4.3.15) | A business impact analysis and policy review every year, and continuity and recovery plans tested periodically or after major changes. | The impact analysis, recovery objectives, test reports and lessons learned. |
| Bring your own device (4.3.16) | A BYOD policy, firm data kept separate from personal data, and mobile device management. | Intune or other device management policies, app protection settings and enrolment reports. |
| Encryption and disposal (4.3.11, 4.3.6) | Encryption in transit and at rest according to classification, key management, and secure disposal that leaves data unrecoverable. | Encryption status reports, key management records and disposal certificates. |
Domain 4.4 expects third parties to give the same level of protection you apply yourself. Before using a cloud service, the guidelines expect a risk assessment of the provider and a contract setting out cyber security controls, and they list data hosting location, meaning cloud services within Saudi Arabia. The contract should also give you rights to audit the provider, to terminate, to recover your data in a usable form and to have it deleted.
For outsourcing, the guidelines limit outsourced security operations monitoring to providers within Saudi Arabia, after your cyber security department has assessed the risks.
Check where your Microsoft 365 and other cloud data are stored today. Microsoft has announced that its Saudi Arabia East datacenter region will be available in November 2026, so ask which services will be hosted in the Kingdom and when. Our third-party risk guide sets out the questions to ask a provider.
The guidelines expect an incident management process with a trained team, a way to classify incidents, protection of evidence and forensic analysis. For reporting, they say to:
The official report covers the incident’s classification, when it happened and when it was detected, the assets affected, the root cause, the fixes made and planned, the damage (including the number of customers affected) and the estimated cost. Logs, a timeline and a record of decisions make that report possible, so keep them from the first hour. A personal data breach may also need reporting to SDAIA within 72 hours.
Last reviewed 30 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
