Can Cre8 IT act as our Head of Cybersecurity?
No. The CMA guidelines say the cyber security department must be separate from the IT department and headed by a full-time, qualified Saudi employee. We support that person with technical controls, reports and evidence, and help them prepare for committee meetings and self-assessments.
Can a capital market firm outsource its security monitoring?
The CMA guidelines limit outsourced security operations monitoring to service providers within Saudi Arabia, and expect your cyber security department to assess the risks first. Always ask a provider, including us, where its monitoring centre is and who can access your data.
Do the SAMA framework and NCA ECC apply to CMA-licensed firms?
It depends on your licences and activities. The SAMA Cyber Security Framework covers SAMA’s member organisations, such as banks and insurers. NCA’s ECC-2:2024 covers government entities and private organisations that run critical national infrastructure. A group holding several licences may face more than one, so your compliance team should confirm which apply.
Does using Cre8 IT make us compliant with the CMA guidelines?
No provider can. You remain responsible for your obligations. We run and evidence the technical controls, help you prepare for self-assessments and reviews, and expect you to assess us as you would any provider.
Do you have an office in Riyadh?
Yes. Our Riyadh office is at Building 3074, Level 29, Tower B, Olaya Towers, Prince Mohammed Bin Abdulaziz Road, and we support firms in KAFD on site and remotely.