SAMA Makes Quantum Risk a Standing Item for Saudi Bank Risk Committees. Its December 31 Inventory Deadline Is Too Tight for Banks Starting From Zero.
Table of Contents
On August 27, 2026, the Saudi Central Bank (SAMA) ordered banks and the other financial institutions it supervises to prepare for the risks of quantum computing, starting with their cryptography. The circular sets two deadlines: December 31, 2026, for cryptographic inventory procedures, and March 31, 2027, for an enterprise-level quantum risk assessment and its action plans.
Circular No. 482021280, Enhancement of Operational Resilience to Address Quantum Computing Risks, is dated 14/03/1448 AH and was signed by Yazeed AlSheikh, SAMA’s Deputy Governor for Supervision. SAMA issued it under its powers in the Saudi Central Bank Law, Royal Decree No. M/36 of 11/04/1442 AH, and lists the circular as in force in its rulebook.
SAMA said in the circular that it issued the measures as an extension of its supervisory work on operational resilience in the financial sector, given the importance of raising preparedness for the risks and threats associated with quantum computing.
The Four Requirements in SAMA’s Circular
The first requirement is an enterprise-level assessment of quantum computing risk, aligned with each institution’s enterprise risk management procedures, with action plans for the risks identified. The assessment must cover, without limitation, operational, legal, regulatory and strategic risks, including those related to human resources. It is due by the end of the first quarter of 2027.
Under the second, each institution must ensure the accuracy and comprehensiveness of its procedures for identifying and classifying all of its cryptographic assets by the end of the fourth quarter of 2026. At a minimum, institutions must identify the data, systems and services associated with those assets and classify them by sensitivity and by priority for migration to quantum-resistant cryptography. They must also assess the cryptographic resilience of priority assets and identify constraints, challenges and dependencies on third parties.
Institutions must also develop plans and initiatives, under the third requirement, to reach the required level of cryptographic resilience, or appropriate alternative solutions, for all priority assets, in line with the outcomes of the second requirement. SAMA set no separate date for it.
Quantum computing risk must become a standing item, under the fourth requirement, for periodic monitoring by each institution’s Information Security Supervisory Committee and by its board risk committee, where applicable. Challenges and recommendations are to be reported to the board or its equivalent.
Who the Circular Covers and Who Sets the Algorithms
The circular is addressed to all banks, finance and payment services companies operating in the Kingdom, to credit information companies, and to financing support entities licensed by SAMA. The circular names no cryptographic algorithm and sets no requirement to submit outputs to SAMA. Questions go to SAMA’s Executive Department of Operational Resilience Control.
In Saudi Arabia, national cryptographic algorithm requirements are set by the National Cybersecurity Authority (NCA) through its National Cryptographic Standards. The NCA put a draft update, NCS-2:2025, to public consultation in December 2025. The draft includes post-quantum algorithms, among them the key-encapsulation mechanism ML-KEM (CRYSTALS-Kyber) and the signature algorithm ML-DSA (CRYSTALS-Dilithium).
SAMA’s circular follows a January 2025 directive from the Bank of Israel that gave banks a year to submit quantum preparedness plans, and July 2026 guidance from Switzerland’s FINMA recommending that supervised institutions have a post-quantum roadmap by mid-2027.
My Analysis
SAMA’s circular contains most of what I would have asked a supervisor to write. SAMA put quantum risk inside enterprise risk management and made it a standing item on the agendas of two committees. The inventory comes before the migration plan, and no algorithm is named. Assets that cannot reach the required level can be given an appropriate alternative. Item Second also contains the two tests every cryptographic inventory should pass: accuracy and comprehensiveness.
SAMA then gave banks four months to meet those tests, and the inventory a bank can most easily buy in four months, one assembled from interviews and questionnaires, can demonstrate neither.
What I hear from clients and former colleagues is that some banks have already commissioned exactly that: large advisory firms running workshops and questionnaires with application owners, with a report bearing a recognizable name on the cover at the end. From what I hear, the banks know the result will not be accurate. They expect the report to satisfy the supervisor for a while, and since the circular requires no submission, it may.
Disclosure: Applied Quantum sells cryptographic discovery and PQC migration services, including to clients in the Middle East. I have argued against interview-based inventories since 2022, years before this circular.
What SAMA Got Right
Quantum risk becomes a standing item under item Fourth for the board risk committee and the Information Security Supervisory Committee, with challenges and recommendations going to the board. The Bank of Israel asked boards and management to discuss an initial preparedness plan before submitting it. It also asked them to revisit quantum developments and preparedness at least once every two years. A committee that sees quantum risk at every periodic review will ask why the numbers moved since the last one. For board oversight of a migration that runs for years, I have recommended four to six risk indicators, reported to the board quarterly. I have argued that boards fund obligations, not threats, and under item Fourth, both committees monitor that obligation as a standing item, where applicable.
The item First risk assessment follows each institution’s own enterprise risk management procedures and covers legal, regulatory, strategic and human-resources risk alongside operational risk. The human-resources line names a constraint I see in every market I work in. The people who can run cryptographic discovery and plan a migration are scarce, and an action plan that assumes them has to say where they will come from.
Institutions classify all their cryptographic assets by sensitivity and migration priority under item Second and assess the priority assets in depth. That is the risk-driven approach I recommend when a complete inventory is years away. Priority assets that cannot reach the required level can have “appropriate alternative solutions” under item Third. Some appliances will never receive post-quantum firmware. Isolating, replacing or retiring such an appliance can be an appropriate alternative under this text, depending on the risk that remains.
Third-party dependencies are inside the inventory. For a bank, the hardest constraints come from core banking platforms, card processors, HSMs and cloud services whose cryptography the bank cannot change on its own schedule. A bank cannot govern those vendors until it knows which of them are on its critical path. SAMA named no algorithm. National algorithm requirements come from the NCA’s cryptographic standards.
The Arabic Wording Raises a Crypto-Agility Question
SAMA signed the circular in Arabic. Its rulebook, which carries the English translation, says it has no legal effect and still contains documents under review, including translated versions. SAMA says content circulated through its official channels remains in force. In the signed text, المتانة (al-matāna) appears in the title, in the preamble and in the name of the department that enforces the circular, each time for operational resilience. In items Second and Third, the property banks must assess in their priority assets and then bring to a required level is a different term, المرونة التشفيرية (al-murūna al-tashfīriyya). The English translation renders both as resilience.
The literal meaning of al-murūna is flexibility, and the word is also used for resilience, including in Saudi government texts. Applied to cryptography, flexibility is close to what NIST calls crypto-agility, which its CSWP 39 describes as the capability to replace and adapt cryptographic algorithms while preserving security and ongoing operations. The signed text uses al-matāna each time it refers to operational resilience and a different word for the cryptographic property. The circular defines neither term, though, and the contrast alone does not establish that SAMA meant crypto-agility in NIST’s sense.
If the flexibility reading is right, item Second asks banks to assess how readily each priority asset can change its cryptography. On the same reading, item Third asks for plans to reach the required level of that capability, or an alternative. That would match what I have argued in my own work, where crypto-agility is the goal and the PQC migration is its first test. SAMA could settle the question by saying how it wants cryptographic resilience assessed.
The Arabic is also more direct about the inventory. Where the English text has procedures for “identifying” cryptographic assets, the Arabic has حصر (ḥaṣr), the ordinary word for an inventory or a census, applied to all (كافة) of an institution’s cryptographic assets. In both texts, the December 31 date applies to procedures whose output is an inventory.
Four Months for a Cryptographic Inventory
On a literal reading, item Second contains three requirements for December 31: accurate and comprehensive procedures, a classification of the data, systems and services that depend on cryptography, and an assessment of the priority assets. Most of the bankers and advisers I hear from treat December 31 as the date for a complete inventory of every cryptographic asset an institution has.
The literal reading is achievable for a bank that was already underway. In my PQC Migration Framework, the discovery targets are 30–60 days for internet-facing systems that handle trust anchors or data with long confidentiality requirements, 60–120 days for the next tier of internal critical systems, and 6–12 months for everything else. They are planning targets, and meeting them assumes discovery tooling is already in place.
Saudi banks should also have foundations to build on. SAMA has required an accurate, up-to-date asset register since 2017 under its Cyber Security Framework, along with a cryptographic standard covering the lifecycle management of encryption keys. The asset register gives a bank a starting scope for its inventory, one that still has to be reconciled and validated, and its key and certificate records describe the cryptography it manages on purpose. Neither source shows the cryptography nobody manages deliberately: libraries compiled into applications, protocols inside appliance firmware, and the internals of vendor and cloud services.
A bank starting from zero faces a different calendar, with fewer than three months of the window now left. If it needs new discovery tooling, that time also has to cover procurement, security review and change approvals before the first scan runs. No large bank starting from zero produces a finished census of all its cryptographic assets in that time.
The supervisors and agencies that have put a number on comparable work allow more time, though their deliverables differ. The UK’s National Cyber Security Centre expects large organizations to need two to three years for discovery and assessment, a migration strategy and an initial plan. It sets 2028 for completing discovery and assessment and an initial migration plan. The Bank of Israel gave banks a year to submit an initial preparedness plan and tied the mapping of their encrypted information assets to their existing Directive 364 obligations, with no separate date. FINMA recommends a roadmap by mid-2027, roughly a year after its guidance. In 2024 I wrote that a truly complete inventory may take years of effort in a big organization, and nothing I have seen since has shortened that.
The inventory is also only the first step. The G7 Cyber Expert Group, which advises G7 finance ministers and central bank governors, suggests in a roadmap it describes as non-prescriptive that the financial sector address its most critical systems around 2030–32, within an overall 2035 target that matches many of the national deadlines I track.
SAMA has not said publicly which reading its examiners will apply. The circular requires no submission, so SAMA will see a bank’s inventory, classifications and priority-asset assessments when its examiners ask for them. Banks will build to whatever they expect those examiners to ask for. With no stated standard of evidence, the cheapest answer to “accurate and comprehensive” is an interview-based report.
Interview-Based Inventories and SAMA’s Two Tests
An interview-based inventory is assembled from what people say. Consultants run workshops with application owners and infrastructure teams and send questionnaires about protocols, certificates and encryption. The answers go into a register with sensitivity classifications and a priority list. The exercise needs no tools, no deployment approvals and no access to production systems, and the result has the same headings as SAMA’s minimum list.
The people interviewed rarely know all the cryptography their systems use, so their answers alone cannot establish that an inventory is accurate. Much of the cryptography in a bank runs inside libraries, frameworks, operating systems, appliance firmware and vendor services, chosen by someone else and invisible to the application owner. My 2022 article on manual cryptographic inventories, updated in April, says that relying on asset owners, developers or IT personnel to report every use of cryptography in interviews or survey responses “is not just impractical; it rarely yields a complete or durable picture at enterprise scale.”
Comprehensiveness needs a denominator: the list of systems, services and connections the inventory was meant to cover, drawn up before anyone started looking. A questionnaire program can report how many application owners replied. It cannot report how much of the cryptography inside their applications anyone has found, because its findings are the answers that came back.
Interviews have a place. In my framework they are part of the fifth layer of discovery, manual investigation, alongside four layers in which tools analyze network traffic, scan code, scan configurations and certificates, and analyze running processes and binaries. Teams use them to find the custom protocols and undocumented integrations that tools miss. No single tool covers all five layers either. Tool vendors who imply complete coverage are selling the same shortcut from the other side. The failure is an inventory built from interviews alone.
Items First, Third and Fourth Depend on the Inventory
Banks will draw on their item Second inventories for their item Third plans and their item First risk assessments. SAMA requires item Third plans to be “in line with the outcomes of item ‘Second’,” so a priority list drawn from interviews becomes the migration plan’s priority list. In the item First risk assessment, due three months after the inventory, a risk team should say which data is exposed to harvest-now, decrypt-later collection and which signatures must stay trustworthy for years. Systems the inventory missed become blind spots in that assessment.
Committees and the board then monitor progress against that baseline under item Fourth. If the baseline came from questionnaires, the committees will be measuring progress against questionnaire answers, and a board can approve every report without seeing the bank’s cryptography.
Once the bank’s engineers start on item Third’s plans, they are likely to find payment HSMs, appliance firmware and compiled-in libraries that nobody mentioned in a workshop, and the bank may end up commissioning discovery anyway. It would then pay twice to establish the same facts.
What SAMA Should Accept as Evidence on December 31
SAMA can fix this without a new rule, by saying what evidence of accuracy and comprehensiveness its examiners will accept. With three measures, examiners could check both tests:
- An evidence grade on every finding. In my framework, findings are graded by how they are known: observed at runtime, confirmed in the deployed binary, declared in a CMDB or certificate manager, attested by a vendor, or inferred from documentation. An interview answer is a declaration at best. If the priority assets are known only from declarations, nobody has tested the inventory’s accuracy.
- Coverage against a denominator set in advance. Coverage is measured against an estate enumerated before discovery ran, from the asset register SAMA has required since 2017 and the service map. The institution states the denominator with every coverage figure, as in “94 percent of the 2,140 TLS endpoints enumerated from the load-balancer and service registries.”
- A signed register of accepted gaps. In the register, the institution lists the scope inside the denominator that discovery has not reached, with a reason and a closure date for each gap, and signs it.
With those measures, SAMA could treat December 31 as a measured baseline. A bank that reports 70 percent coverage of its critical systems, with evidence grades, tells its supervisor more than a bank that reports complete coverage from interviews, and its committees can track that percentage from one periodic review to the next.
The G7 Cyber Expert Group already suggests in its roadmap that financial institutions establish quantifiable metrics to track progress. In 2025 the UK’s NCSC launched a pilot that assures consultancies for post-quantum discovery and migration planning after an assessment of each applicant, and its 2025 annual review reported the first eight firms onboarded. SAMA could set evidence expectations for discovery work directly and could also recognize assured providers. With stated evidence expectations, an examiner could tell an interview-only report from an inventory.
The next date is March 31, 2027, when the enterprise risk assessments and action plans are due. SAMA will show in its first examinations under the circular which reading of item Second it applies. A bank does not have to wait for that answer to build its evidence. One that reports measured coverage on December 31, with its gaps named and the register signed, still won’t know whether SAMA accepts an incomplete inventory, but its risk committee will spend the coming years monitoring the bank’s cryptography instead of a questionnaire.