Who you tell depends on your sector and licence, and more than one regulator can apply. SAMA-regulated firms must inform SAMA IT Risk Supervision immediately about a medium or high incident. CMA-licensed firms report to the CMA immediately after an incident occurs or is detected. Organisations in the scope of the NCA’s Essential Cybersecurity Controls must have a process for reporting incidents to the NCA. If personal data is breached, the controller must notify SDAIA within 72 hours of becoming aware of it. SAMA and the CMA also expect a formal report after operations resume, and their agreement before any media statement.
Several of these can apply to the same incident. A bank that loses customer data may need to tell SAMA and SDAIA, each on its own timeline.
| Regulator | Who it covers | When | How |
|---|---|---|---|
| SAMA | Banks, insurers, financing companies, credit bureaus and financial market infrastructure | Immediately for a medium or high incident; formal report after operations resume | SAMA IT Risk Supervision |
| CMA | Capital market institutions | Immediately after the incident occurs or is detected; official report after operations resume | Cyber.Incident@cma.org.sa |
| NCA | Government entities and their affiliates, and private operators of critical national infrastructure | ECC requires a process for reporting incidents to the NCA | 936 or is@nca.gov.sa |
| SDAIA | Any controller of personal data under the PDPL | Within 72 hours of becoming aware of a personal data breach | National Data Governance Platform |
The SAMA Cyber Security Framework (control 3.3.15) says a member organisation should:
The formal report covers the incident’s title and classification, when it occurred and when it was detected, the information assets involved, technical details, root-cause analysis, corrective actions taken and planned, the impact (including the number of customers affected), the total estimated cost and the estimated cost of corrective actions. Our SAMA guide covers the rest of the framework.
The CMA’s Cybersecurity Guidelines for Capital Market Institutions expect firms to report to the CMA immediately after an incident occurs or is detected, and to coordinate with the CMA before any media statement. Once operations resume, an official report goes to Cyber.Incident@cma.org.sa.
The report asks for much the same as SAMA’s: classification, when the incident happened and was detected, the assets affected, technical details and root cause, fixes made and planned, the damage (including the number of customers affected) and the estimated costs. See our CMA guide.
The NCA’s Essential Cybersecurity Controls apply to government entities and their affiliates, and to private entities that own, operate or host critical national infrastructure. Subdomain 2-13 (incident and threat management) requires incident response plans and escalation procedures, a way to classify incidents, reporting of cybersecurity incidents to the NCA, and sharing incident notifications and threat intelligence with the NCA.
The NCA’s website lists phone 936 and is@nca.gov.sa for reporting an incident involving a national entity, and a separate route (Haseen) for reporting vulnerabilities. See our NCA ECC guide.
Under the Personal Data Protection Law, overseen by SDAIA, a controller must notify SDAIA through the National Data Governance Platform within 72 hours of becoming aware of a personal data breach, and tell affected individuals without undue delay. Some sectors have extra duties: a cloud service provider, for example, may also need to report to the CST.
Whether an event is a notifiable breach is a decision for your data protection lead or legal adviser, so involve them in the first hours. Our PDPL guide has the IT checklist.
Most of what makes reporting hard is decided before the incident. Our suggestions:
Last reviewed 30 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
