Saudi Arabia’s central bank, SAMA, is now demanding financial institutions move beyond planning for the quantum threat and begin immediate action, mirroring a coordinated global regulatory push led by authorities in the US and Singapore.
A surprising first hurdle for many, however, is simply knowing what cryptographic assets they currently possess; as one industry observer notes, asking a bank’s CISO for a live certificate count “usually gets a pause before the answer.” SAMA’s August 27, 2026 circular requires banks to complete a cryptographic inventory by the end of Q4 2026, a task identified by both SAMA and the White House as the most critical initial step in preparing for the quantum transition.
SAMA Mandate: Cryptographic Inventory by Q4 2026
The immediate challenge for Saudi Arabian banks facing the quantum threat isn’t algorithm development, but basic asset management; many financial institutions struggle to accurately enumerate their existing cryptographic certificates. Asking a Chief Information Security Officer how many certificates are currently live across their environment reveals a surprising lack of visibility into current cryptographic deployments. This initial hurdle precedes any discussion of quantum-resistant solutions, highlighting a fundamental gap in foundational security practices.
The White House has similarly identified cryptographic inventory as the initial, critical step for US federal agencies, and Singapore’s Monetary Authority has issued comparable guidance to its financial sector. This convergence of regulatory pressure from major global powers emphasises the urgency of the situation, and SAMA’s circular is a mandate for action, not a suggestion. The expectation from SAMA builds on three core requirements: inventory, risk assessment, and ongoing governance.
Each step relies on the previous one, creating a structured approach to quantum readiness. However, the initial inventory phase frequently reveals unexpected complexity. Teams often assume a manageable list of cryptographic assets until discovery begins, uncovering certificates, keys and algorithms residing in forgotten legacy systems, third-party platforms, and long-abandoned code repositories. This pervasive distribution is typical for large financial institutions, and explains why a one-time spreadsheet exercise proves inadequate.
The fundamental goal, according to the source, is ownership of the cryptographic inventory. This is proving another significant obstacle. Some of the world’s largest banks, like HSBC, are already establishing dedicated cryptographic-agility and quantum-technology programmes with named leads and a publishing record, signaling a shift toward a standing function rather than a temporary project.
This proactive approach demonstrates a commitment to long-term management of cryptographic assets. The expectation is that more institutions in the Gulf Cooperation Council will follow suit, regardless of whether SAMA’s timeline is the primary driver. The need for continuous monitoring and remediation is also paramount. This emphasis on sustained effort reflects the understanding that cryptographic agility is a continuous process of adaptation and improvement, not a one-time fix. The ultimate aim is to establish a dynamic system that can respond to evolving threats and maintain a secure cryptographic posture over the long term.
Quantum Risk Assessment and Remediation Timelines
Establishing a current cryptographic inventory presents an immediate challenge for Saudi Arabian banks, as many security leaders lack a clear understanding of their existing certificates. Determining the number of live certificates often prompts a significant pause, not from a lack of business knowledge, but from a genuine absence of readily available data. The regulator is actively demanding a phased approach focused on inventory, risk assessment, and ongoing governance.
Institutions are now focused on how to begin the transition, rather than debating if they should, a shift mirroring the approach taken by regulators in other global markets. The three-stage process is designed to build incrementally, with a complete cryptographic inventory serving as the foundation for subsequent risk prioritization and sustained management.
The demand for continuous inventory maintenance highlights a critical distinction between a one-time audit and a dynamic system. A simple list of cryptographic assets is insufficient; SAMA seeks evidence of a continuously updated inventory, linked to ownership and tracked remediation efforts. “What do we actually have?” is a common starting point for conversations, according to one source, emphasizing the fundamental need for accurate asset discovery.
Quantum risk must also become a standing item on the governance agenda, ensuring ongoing monitoring and adaptation. Building a standing function, rather than a one-time project, is the ultimate goal. Establishing clear accountability and linking assets to specific business systems are essential for effective management and remediation. This requires not only technical tools for discovery and classification, but also a clear understanding of business processes and data flows.
The goal is to move beyond simply identifying assets to actively managing their lifecycle and ensuring their ongoing security, White House says. A continuously updated inventory, tied to risk and tracked remediation, is the desired outcome, demonstrating a proactive approach to long-term cryptographic agility.
Source: https://www.keyfactor.com/blog/what-banks-in-saudi-arabia-are-already-doing-about-quantum-risk/




See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
