Insights · Incident reporting

Reporting a cyber incident in Saudi Arabia: who to tell and how fast

Who a Saudi organisation must tell after a cyber incident (SAMA, the CMA, the NCA and SDAIA), how fast, what the formal report covers and what to prepare now.
The short answer

Who you tell depends on your sector and licence, and more than one regulator can apply. SAMA-regulated firms must inform SAMA IT Risk Supervision immediately about a medium or high incident. CMA-licensed firms report to the CMA immediately after an incident occurs or is detected. Organisations in the scope of the NCA’s Essential Cybersecurity Controls must have a process for reporting incidents to the NCA. If personal data is breached, the controller must notify SDAIA within 72 hours of becoming aware of it. SAMA and the CMA also expect a formal report after operations resume, and their agreement before any media statement.

Key points
  • SAMA: inform SAMA IT Risk Supervision immediately about medium or high incidents, and send a formal report after operations resume.
  • CMA: report immediately after an incident occurs or is detected, and send an official report to Cyber.Incident@cma.org.sa after operations resume.
  • NCA: organisations in ECC scope must report cybersecurity incidents to the NCA (subdomain 2-13).
  • PDPL: notify SDAIA within 72 hours of becoming aware of a personal data breach, and tell affected individuals without undue delay.
  • SAMA and CMA firms need the regulator’s agreement before talking to the media about an incident.

Who to tell: a quick reference

Several of these can apply to the same incident. A bank that loses customer data may need to tell SAMA and SDAIA, each on its own timeline.

RegulatorWho it coversWhenHow
SAMABanks, insurers, financing companies, credit bureaus and financial market infrastructureImmediately for a medium or high incident; formal report after operations resumeSAMA IT Risk Supervision
CMACapital market institutionsImmediately after the incident occurs or is detected; official report after operations resumeCyber.Incident@cma.org.sa
NCAGovernment entities and their affiliates, and private operators of critical national infrastructureECC requires a process for reporting incidents to the NCA936 or is@nca.gov.sa
SDAIAAny controller of personal data under the PDPLWithin 72 hours of becoming aware of a personal data breachNational Data Governance Platform

SAMA-regulated firms

The SAMA Cyber Security Framework (control 3.3.15) says a member organisation should:

  • Inform SAMA IT Risk Supervision immediately when a medium or high classified security incident has occurred and been identified.
  • Obtain a no objection from SAMA IT Risk Supervision before any media interaction about the incident.
  • Submit a formal incident report after resuming operations.

The formal report covers the incident’s title and classification, when it occurred and when it was detected, the information assets involved, technical details, root-cause analysis, corrective actions taken and planned, the impact (including the number of customers affected), the total estimated cost and the estimated cost of corrective actions. Our SAMA guide covers the rest of the framework.

CMA-licensed firms

The CMA’s Cybersecurity Guidelines for Capital Market Institutions expect firms to report to the CMA immediately after an incident occurs or is detected, and to coordinate with the CMA before any media statement. Once operations resume, an official report goes to Cyber.Incident@cma.org.sa.

The report asks for much the same as SAMA’s: classification, when the incident happened and was detected, the assets affected, technical details and root cause, fixes made and planned, the damage (including the number of customers affected) and the estimated costs. See our CMA guide.

Organisations in the NCA’s scope

The NCA’s Essential Cybersecurity Controls apply to government entities and their affiliates, and to private entities that own, operate or host critical national infrastructure. Subdomain 2-13 (incident and threat management) requires incident response plans and escalation procedures, a way to classify incidents, reporting of cybersecurity incidents to the NCA, and sharing incident notifications and threat intelligence with the NCA.

The NCA’s website lists phone 936 and is@nca.gov.sa for reporting an incident involving a national entity, and a separate route (Haseen) for reporting vulnerabilities. See our NCA ECC guide.

Personal data breaches (PDPL)

Under the Personal Data Protection Law, overseen by SDAIA, a controller must notify SDAIA through the National Data Governance Platform within 72 hours of becoming aware of a personal data breach, and tell affected individuals without undue delay. Some sectors have extra duties: a cloud service provider, for example, may also need to report to the CST.

Whether an event is a notifiable breach is a decision for your data protection lead or legal adviser, so involve them in the first hours. Our PDPL guide has the IT checklist.

What to prepare before an incident

Most of what makes reporting hard is decided before the incident. Our suggestions:

  1. Map your regulators. Write down which of the four apply to you, and the contact for each.
  2. Agree what “medium” and “high” mean. SAMA’s duty is triggered by classification, so set the criteria now.
  3. Name the decision-makers and a deputy for each, with out-of-hours numbers.
  4. Record both times. Reports ask when the incident occurred and when it was detected, so make sure logs and tickets capture both.
  5. Keep the evidence. Logs retained, devices preserved rather than wiped, a timeline and a record of decisions.
  6. Fix your provider’s deadline. Put a short notification deadline in IT and security contracts, so their delay does not use up your time.
  7. Hold the media line. SAMA and CMA firms need the regulator’s agreement before public statements.
  8. Rehearse once a year, including drafting the formal report.

Sources and further reading

Last reviewed 30 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Do we have to report a cyber incident to more than one regulator?

Often, yes. A SAMA or CMA-regulated firm whose incident involves personal data may need to tell its financial regulator and SDAIA, each on its own timeline. Map which regulators apply to you before an incident.

What does "immediately" mean for SAMA and CMA reporting?

Neither text we reviewed sets a number of hours. Treat it as as soon as you have identified the incident, without waiting for the investigation to finish. The detailed formal report comes after operations resume.

Can we talk to the media about a cyber incident?

If you are regulated by SAMA or the CMA, not before the regulator agrees. SAMA requires a no objection from IT Risk Supervision, and the CMA expects you to coordinate with it before any media action.

Who reports if our IT provider has the incident?

You do. You remain responsible for your regulatory reporting, so put a short incident notification deadline in your provider contracts.

Is a ransomware attack a personal data breach?

It can be, if personal data was accessed or taken. Your data protection lead or legal adviser decides, so involve them in the first hours to protect the 72-hour window.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
CMA

CMA Cybersecurity Guidelines: what capital market institutions need to evidence

Who the CMA’s Cybersecurity Guidelines apply to, their four domains, the Head of Cybersecurity rule, cloud and outsourcing limits, incident reporting and the IT evidence to keep.
5 min read · Reviewed 30 September 2026
SAMA

SAMA Cyber Security Framework: what Saudi financial institutions need to evidence

Who the SAMA Cyber Security Framework applies to, its four domains, the maturity level SAMA expects and the IT evidence a member organisation keeps.
3 min read · Reviewed 20 September 2026
PDPL

Saudi PDPL: an IT checklist for the Personal Data Protection Law

What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
4 min read · Reviewed 20 September 2026

Talk to a specialist about incident readiness

We can help you map your regulators, write and rehearse your incident plan, and keep the logs a formal report needs. Or see our cyber security services.