Insights · CMA

CMA Cybersecurity Guidelines: what capital market institutions need to evidence

Who the CMA’s Cybersecurity Guidelines apply to, their four domains, the Head of Cybersecurity rule, cloud and outsourcing limits, incident reporting and the IT evidence to keep.
The short answer

The CMA’s Cybersecurity Guidelines for Capital Market Institutions apply to firms licensed by the Capital Market Authority, such as asset managers, brokers, investment banks, advisers and custodians. They are issued as guidelines, but the CMA can apply them to any institution it supervises and checks implementation through periodic self-assessments. They have four domains: governance; risk management, review and audit; operational controls; and third parties. Key expectations include a cyber security department separate from IT and headed by a full-time, qualified Saudi employee, multi-factor authentication for remote and privileged access, security logs kept for at least 12 months, cloud services hosted in Saudi Arabia, and reporting incidents to the CMA immediately.

Key points
  • The guidelines apply to capital market institutions licensed by the CMA: firms that deal, manage investments, arrange, advise or provide custody.
  • They are issued as guidelines, but the CMA can apply them to any institution it supervises and checks them through periodic self-assessments.
  • A cyber security department, separate from IT, must be headed by a full-time, qualified Saudi employee.
  • Cloud services should be hosted in Saudi Arabia, and outsourced security monitoring is limited to providers in the Kingdom.
  • Incidents are reported to the CMA immediately, with an official report once operations resume.

Who the guidelines apply to

The guidelines are addressed to all capital market institutions: the firms the Capital Market Authority licenses to carry on securities business. The CMA licenses five activities:

  • Dealing (brokerage)
  • Managing investments and operating funds (asset management)
  • Arranging (investment banking)
  • Advising
  • Custody

The CMA describes the document as guidelines, and says it may apply them to any entity it supervises. Implementation is checked through periodic self-assessment questionnaires, in a way the CMA decides. In practice, treat them as the standard the CMA will measure you against.

Other rules can apply alongside them. The PDPL covers the personal data you hold. If your group also holds a SAMA licence, or runs critical national infrastructure, the SAMA framework or NCA’s ECC may apply too. Ask your compliance team which apply to your licence.

The four domains

DomainWhat it covers
4.1 Cybersecurity GovernanceBoard responsibility, the cyber security department and committee, data governance, strategy and policies, awareness and training, and cyber security in human resources.
4.2 Cybersecurity Risk Management, Review and AuditA risk management method, a single record of cyber security risks, and periodic review and independent audit of controls.
4.3 Operational Cybersecurity ControlsDay-to-day controls, from asset management, access control and change management to logging, incident management, encryption, e-trading services, physical security, business continuity and BYOD.
4.4 Third Party CybersecurityContracts and suppliers, outsourcing and cloud computing.

Most of the IT department’s daily work sits in 4.3. Domains 4.1 and 4.2 decide whether that work is documented, owned and reviewed.

The Head of Cybersecurity and governance

The guidelines make the board fully responsible for cyber security, with the option to delegate to a committee. Beneath the board they expect:

  • A cyber security department separate from the IT department.
  • A Head of Cybersecurity Department who is a full-time, qualified Saudi employee.
  • A cyber security committee, including the Head of Cybersecurity and relevant department heads, reporting to the CEO or their representative.
  • Periodic review and audit of cyber security controls by a party independent of the cyber security department.

This matters when you choose an IT provider. A provider can run and evidence technical controls, but it cannot be your Head of Cybersecurity, and your cyber security department should not simply be your IT team under another name.

Controls that need IT evidence

These are the operational controls where reviewers most often ask the IT team for proof. The evidence column is our suggestion, not a CMA checklist.

ControlWhat the guidelines askTypical evidence
Multi-factor authentication (4.3.4)Multi-factor authentication for all remote access, and for sensitive systems and privileged accounts according to risk.Conditional Access policies, coverage reports, a list of privileged accounts and access reviews.
Security event logs (4.3.8)Logs kept for at least 12 months, monitored 24/7, with central analysis such as a SIEM.Retention settings, SIEM coverage and monitoring reports. Microsoft 365’s standard audit log keeps 180 days, so 12 months usually needs a higher licence or a SIEM.
Vulnerabilities and testing (4.3.3, 4.3.12, 4.3.13)Regular scanning of all assets, patch timelines by severity, security testing of changes, and penetration testing of online services at least once a year.Scan and patch reports, change records, penetration test reports and records of fixes.
Business continuity (4.3.15)A business impact analysis and policy review every year, and continuity and recovery plans tested periodically or after major changes.The impact analysis, recovery objectives, test reports and lessons learned.
Bring your own device (4.3.16)A BYOD policy, firm data kept separate from personal data, and mobile device management.Intune or other device management policies, app protection settings and enrolment reports.
Encryption and disposal (4.3.11, 4.3.6)Encryption in transit and at rest according to classification, key management, and secure disposal that leaves data unrecoverable.Encryption status reports, key management records and disposal certificates.

Cloud, outsourcing and your IT provider

Domain 4.4 expects third parties to give the same level of protection you apply yourself. Before using a cloud service, the guidelines expect a risk assessment of the provider and a contract setting out cyber security controls, and they list data hosting location, meaning cloud services within Saudi Arabia. The contract should also give you rights to audit the provider, to terminate, to recover your data in a usable form and to have it deleted.

For outsourcing, the guidelines limit outsourced security operations monitoring to providers within Saudi Arabia, after your cyber security department has assessed the risks.

Check where your Microsoft 365 and other cloud data are stored today. Microsoft has announced that its Saudi Arabia East datacenter region will be available in November 2026, so ask which services will be hosted in the Kingdom and when. Our third-party risk guide sets out the questions to ask a provider.

Reporting an incident to the CMA

The guidelines expect an incident management process with a trained team, a way to classify incidents, protection of evidence and forensic analysis. For reporting, they say to:

  • Report to the CMA immediately after an incident occurs or is detected.
  • Coordinate with the CMA before any media statement about the incident.
  • Send an official report after operations resume, to [email protected].

The official report covers the incident’s classification, when it happened and when it was detected, the assets affected, the root cause, the fixes made and planned, the damage (including the number of customers affected) and the estimated cost. Logs, a timeline and a record of decisions make that report possible, so keep them from the first hour. A personal data breach may also need reporting to SDAIA within 72 hours.

Sources and further reading

Last reviewed 30 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Are the CMA Cybersecurity Guidelines mandatory?

The CMA issues them as guidelines, but it can apply them to any institution it supervises and checks implementation through periodic self-assessments. Most capital market institutions treat them as the expected standard. Your compliance team should confirm how they apply to your licence.

How quickly must we report a cyber incident to the CMA?

Immediately after it occurs or is detected, followed by an official report once operations resume. Coordinate with the CMA before any media statement about the incident.

How long must a capital market institution keep security logs?

At least 12 months, under the guidelines’ controls for security event logs, which also expect 24/7 monitoring.

Can we use cloud services hosted outside Saudi Arabia?

The guidelines list data hosting location, meaning cloud services within Saudi Arabia, among the controls to agree before using a cloud service. Take advice from your compliance team before hosting data abroad.

How often do we need a penetration test?

The guidelines expect penetration testing of all online services at least once a year, and security testing as part of significant changes.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
SAMA

SAMA Cyber Security Framework: what Saudi financial institutions need to evidence

Who the SAMA Cyber Security Framework applies to, its four domains, the maturity level SAMA expects and the IT evidence a member organisation keeps.
3 min read · Reviewed 20 September 2026
Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026
PDPL

Saudi PDPL: an IT checklist for the Personal Data Protection Law

What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
4 min read · Reviewed 20 September 2026

Talk to a specialist about your CMA obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support. Or see how we support CMA-licensed firms.