Financial institutions in Saudi Arabia now face concrete deadlines to prepare for quantum computing risks. With the Saudi Central Bank (SAMA) issuing new requirements in August 2026, financial institutions now have specific milestones to work toward, and the first one arrives before the end of this year.
What SAMA Is Requiring
The SAMA circular on Enhancement of Operational Resilience to Address Quantum Computing Risks sets out four requirements for financial institutions.
By the end of Q4 2026, institutions must ensure comprehensive identification and classification of their cryptographic assets, determine which data, systems, and services are associated with them, and assess the cryptographic resilience of priority assets, including any third-party dependencies.
By the end of Q1 2027, institutions must complete an enterprise-level quantum risk assessment covering operational, legal, regulatory, and strategic risks and develop action plans to address the risks identified.
Beyond those two deadlines, SAMA also requires institutions to develop plans to achieve the required level of cryptographic resilience, or appropriate alternative solutions, for priority assets. Quantum computing risks must also be regularly monitored by relevant committees, with challenges and recommendations reported to the Board.
Why This Matters Now
The underlying concern is well established. Sufficiently powerful quantum computers are expected to be capable of breaking widely used asymmetric cryptographic algorithms that help secure today's digital financial services. While that capability does not exist at scale today, migrating away from vulnerable cryptography takes time, and waiting until the threat is imminent is not a viable approach.
The US National Institute of Standards and Technology (NIST) finalized its first post-quantum cryptography standards in 2024, providing standardized algorithms that organizations can now use as they plan their migration. SAMA's new requirements bring that transition into concrete regulatory planning for Saudi financial institutions.
Where to Start
The first milestone, cryptographic asset identification and classification, is the practical starting point for everything that follows. Institutions that lack a clear picture of where cryptography is used across their systems, what depends on it, and how sensitive those assets are cannot make informed decisions about migration priorities.
This is also where crypto-agility becomes relevant. Systems designed to accommodate cryptographic changes, rather than having algorithms fixed at the point of implementation, are easier to migrate as cryptographic requirements evolve. For institutions reviewing their current architecture as part of this assessment, the ability to evolve cryptography without full system replacement is worth factoring into both the assessment and the forward planning it produces.
A Note on Authentication
It is worth being precise here: the SAMA circular addresses cryptographic resilience broadly across financial institution systems and does not set specific requirements for authentication methods.
That said, authentication systems in banking rely heavily on cryptography. Depending on the implementation, public-key cryptography can play an important role in mechanisms such as device authentication and transaction signing. As institutions assess their cryptographic estate, they should therefore understand where authentication infrastructure has cryptographic dependencies that may be affected by the transition.
For institutions modernizing or replacing authentication systems as part of their quantum readiness efforts, building in support for post-quantum cryptographic algorithms and crypto-agility from the start can reduce the need for a major migration later.
The Practical Implication
The Q4 2026 deadline for cryptographic asset identification is approaching. Institutions that have not begun this work need to move quickly, not because the migration itself needs to be complete by then, but because understanding what needs to change is the prerequisite for everything that follows.
Quantum readiness is fundamentally a planning and prioritization exercise before it becomes a technical one. SAMA's requirements reflect that preparation: understand the cryptographic estate and its dependencies, assess the broader risks, and use those findings to guide resilience and migration planning.
Frequently asked questions
Does the SAMA circular require financial institutions to complete their migration to post-quantum cryptography by the 2027 deadline?
No. The Q1 2027 deadline covers the completion of the enterprise-level risk assessment and the development of action plans. SAMA separately requires institutions to develop plans and initiatives to achieve the required level of cryptographic resilience, or appropriate alternative solutions, for priority assets. The circular does not set a single deadline for completing migration to post-quantum cryptography.
Are authentication systems in scope for the SAMA quantum requirements?
The circular does not specifically address authentication. It covers cryptographic assets broadly across financial institution systems. Authentication infrastructure may appear in a cryptographic asset inventory, given its reliance on public-key cryptography, but the regulation does not set specific requirements for authentication methods.
What is crypto-agility and why does it matter here?
Crypto-agility refers to the ability of a system to change its cryptographic algorithms without requiring a full redesign or replacement. It matters in the context of quantum readiness because migrating from current algorithms to post-quantum alternatives is easier when systems are built to accommodate such change. Institutions assessing their cryptographic estate as part of SAMA compliance may find that older systems with fixed cryptographic implementations could represent some of the more complex parts of the migration ahead.
.png)
.webp)
