2026-08-27

Added · Updated

Enhancement of Operational Resilience to Address Quantum Computing Risks

Financial institutions in the Kingdom, including banks, credit information companies, finance companies, payment services companies, and other entities supporting financing activity licensed by the Central Bank, are required to implement measures to enhance operational resilience against quantum computing risks. By the end of the first quarter of 2027, they must conduct a quantum computing risk assessment and develop action plans to address identified risks, covering operational, legal, regulatory, strategic, and human resource aspects. By the end of the fourth quarter of 2026, institutions must ensure accurate inventorying and classification of all cryptographic assets, identifying data, systems, and services by sensitivity and priority for transition to quantum-resistant solutions, and assessing cryptographic resilience for priority assets. Furthermore, they must develop plans for cryptographic resilience and integrate quantum computing risks as a standing item for periodic monitoring by their Supervisory Committee for Information Security and Risk Committee.

Saudi Central Bank logo

Saudi Arabia

Saudi Central Bank

Click to view thumbnail

Circular Dear Sirs/Madams, Peace, mercy, and blessings of God be upon you. Subject: Raising the level of operational resilience to address quantum computing risks. Based on the powers vested in the Saudi Central Bank by virtue of the system issued by Royal Decree No. (M/36) dated 11/4/1442 AH, and as an extension of the Saudi Central Bank's supervisory and regulatory efforts aimed at enhancing operational resilience in the financial sector, and in light of the importance of raising the level of readiness to address potential risks and threats associated with quantum computing. Accordingly, financial institutions must take the following measures: First: Conduct an assessment of risks associated with quantum computing at the institutional level, in line with the institutional risk management procedures within the financial institution; and develop action plans to address the risks resulting from the assessment, provided that these plans include – without limitation – operational, legal, regulatory, and strategic risks, including human resources, by the end of the first quarter of 2027. Second: Ensure the accuracy and comprehensiveness of procedures for inventorying and classifying all cryptographic assets specific to the institution, while observing the following at a minimum, by the end of the fourth quarter of 2026: ▪ Identify and classify data, systems, and services associated with cryptographic assets by sensitivity and priority for their transition to quantum-resistant cryptographic solutions. ▪ Assess the level of cryptographic resilience for priority assets, and identify constraints, challenges, and aspects of reliance on third parties. Third: Develop plans and initiatives to achieve the necessary level of cryptographic resilience or alternative solutions for all priority assets, in line with the outcomes of item "Second" above. Fourth: Include quantum computing risks as a standing item for periodic monitoring within the work of the Supervisory Committee for Information Security and the Risk Committee emanating from the Board of Directors of the financial institution – where applicable – and report challenges and recommendations to the Board of Directors or whoever is in its authority. For your information and action, you may contact the Executive Department for Operational Resilience Supervision via email at (CFC@SAMA.GOV.SA) in case of any inquiries regarding this matter. Please accept my regards, Ahmed bin Yazid Al-Sheikh Deputy Governor for Supervision Distribution scope:

  • All banks operating in the Kingdom.
  • Credit information companies.
  • Finance companies operating in the Kingdom.
  • Payment services companies operating in the Kingdom.
  • Entities supporting financing activity licensed by the Central Bank.

More like this from SAMA

SAMA published 1 document in the last 30 days. We email you each new one the day it's published.

Share