Press TechRound interviews Secure.com CEO on the future of AI security
Read

Beyond SAMA: A Quick Map of CMA, IA, and SIMAH Cybersecurity Expectations for Regulated Startups

A quick map of CMA, UAE IA, and SIMAH cybersecurity expectations beyond SAMA, so regulated startups know what applies to them and when.

Key Takeaways

  • The CMA Cybersecurity Guidelines are non-certifiable but mandatory for financial institutions operating in Saudi capital markets, covering governance, risk management, operational controls, and third-party cybersecurity across 4 domains and 26 subdomains.
  • The UAE Information Assurance (IA) Standard, originally issued by NESA and now under the UAE Cybersecurity Council and Signals Intelligence Agency (SIA), is a 188-control framework that matters to any startup connected to UAE critical infrastructure or regulated sectors, not only UAE-headquartered firms.
  • SIMAH is not a regulator with its own published control framework. Its cybersecurity expectations arrive through SAMA-approved membership agreements and the Credit Information Law, which require confidentiality, identity verification, and data protection controls from every member institution.
  • A startup that only maps to SAMA can still be out of alignment with CMA, IA, or SIMAH obligations if it touches capital markets, UAE infrastructure, or credit data.
  • The operational challenge is rarely understanding each framework on its own. It is proving the same evidence, on time, across all of them without burning out a small security team.

Most fintech and regulated startups in Saudi Arabia build their entire security program around one acronym: SAMA. That instinct is not wrong. But SAMA is not the only body a growing startup will answer to. Depending on what you build, who funds you, where you operate, and who you exchange data with, the Capital Market Authority (CMA), the UAE’s Information Assurance (IA) framework, and the Saudi Credit Bureau (SIMAH) can all show up on your compliance roadmap, often at the same time.

This piece is a quick map, not a full implementation guide. It is meant to help founders, CISOs, and compliance leads at regulated startups recognize which of these apply to them, what each one actually expects, and how the overlap changes the way security work gets planned and evidenced.

Why Looking Beyond SAMA Matters

SAMA’s Cyber Security Framework gets most of the attention because it covers banks, insurers, and finance companies, which is where a large share of regulated startups sit. But regulatory exposure in the Gulf rarely stops at one framework. A payments startup raising capital may trigger CMA obligations. A company expanding operations or infrastructure into the UAE may trigger IA obligations. Any lender or finance company that pulls or contributes credit data touches SIMAH’s data-sharing rules. None of these show up on day one, and none of them replace SAMA. They stack on top of it.

Regulatory Landscape

One Regulator Is Rarely the Only One

SAMA is where most regulated startups start. But depending on what you build and who you connect to, three more frameworks can land on the same roadmap — often at once.

SAMAStarting point
Most fintech and regulated startups in Saudi Arabia build their program around this framework first.
CMA

Capital markets

Triggered by raising capital or offering products under Capital Market Authority oversight.

UAE IA

Cross-border infrastructure

Triggered by operations, customers, or partnerships connected to UAE critical infrastructure.

SIMAH

Credit data exchange

Triggered the moment a lender or finance company pulls or contributes credit data.

None of these replace SAMA — they stack on top of it, usually without warning on day one.

CMA Cybersecurity Guidelines At a Glance

The Capital Market Authority’s Cybersecurity Guidelines apply to entities operating in Saudi Arabia’s capital markets under CMA oversight.

CMA Cybersecurity Guidelines, At a Glance

Capital Market Authority
4Main domains
26Subdomains
0Certificates issued
100%Mandatory alignment

The four domains

01
Governance
02
Risk management
03
Operational controls
04
Third-party cybersecurity

What it actually means for you

Who it applies to
All financial institutions operating within Saudi Arabia under CMA oversight.
Certifiable
No — the guidelines are non-certifiable, but compliance is still mandatory to avoid penalties.
What “done” looks like
Continuous audit readiness, not a certificate to hang on the wall.
  • Who it applies to: All financial institutions operating within Saudi Arabia under CMA oversight are required to comply.
  • Certifiable or not: The guidelines are non-certifiable requirements, but compliance is still mandatory, and organizations are expected to align with them to avoid penalties and regulatory consequences.
  • Structure: The guidelines are organized into 4 main domains and 26 subdomains, covering governance, risk management, operational controls, and third-party cybersecurity.
  • What “done” looks like: Once an organization has implemented all the requirements, it remains ready for CMA audits rather than earning a certificate.

For a startup, the practical read is this: if you are regulated by the CMA because of what you offer in the capital markets, the guidelines are not optional just because there is no certificate to hang on the wall.

UAE Information Assurance (IA)

UAE Cybersecurity Council / SIA (formerly NESA)

UAE Information Assurance (IA), At a Glance

One of the more technically demanding frameworks in the region — and it can reach a Saudi-headquartered startup through a single UAE connection.

188security controls across four strategic domains
60 management-level controls
128 technical security controls

Who it applies to

Organizations running critical national infrastructure across all UAE emirates — and private-sector operators classified within those sectors too.

Why it reaches beyond the UAE

A Saudi-based startup isn’t automatically in scope — but infrastructure, customers, or partnerships tied to UAE regulated sectors can pull it in regardless of HQ.

Sectors in scope

Energy Utilities Telecommunications Transport Financial infrastructure Healthcare Government systems

Enforcement has teeth. Shortcomings in risk assessment, personal data protection, or incident response can carry penalties reaching into the millions of dollars.

The UAE Information Assurance Standard started life under the National Electronic Security Authority (NESA) and is now administered under the UAE Cybersecurity Council, with the Signals Intelligence Agency (SIA) carrying forward NESA’s operational role.

  • Who it applies to: Organisations operating critical national infrastructure across all UAE emirates, spanning energy, utilities, telecommunications, transport, financial infrastructure, healthcare, and government systems are expected to comply, and private sector organizations in these sectors can be classified as critical infrastructure operators too.
  • Scale of the framework: The IA framework is organised around 188 security controls split across four strategic domains, with 60 management-level controls and 128 technical security controls, making it one of the more technically demanding frameworks in the region.
  • Why it matters beyond the UAE: A Saudi-based startup is not automatically in scope. But if your infrastructure, customers, or partnerships connect you to UAE financial infrastructure or another regulated UAE sector, IA expectations can follow that connection even if your headquarters sits in Riyadh.
  • Enforcement has teeth: Failing to comply can lead to serious consequences, including financial penalties that can reach into the millions of dollars for shortcomings in risk assessment, personal data protection, or incident response.

SIMAH And The Data Sharing Obligations Behind It

SIMAH, the Saudi Credit Bureau, is not a cybersecurity regulator in the way CMA or SAMA are. It does not publish its own public control catalogue for member institutions to certify against. Its cybersecurity expectations arrive through the agreements and law that govern how credit data moves.

  • What governs the relationship: SIMAH is obliged to sign membership agreements approved by the Saudi Central Bank with any party that wants to obtain credit information, and those agreements set out the rights and obligations of both parties.
  • Confidentiality is explicit: SIMAH is committed to maintaining confidentiality over the credit information and data in its possession and to sharing it exclusively with members, other bureaus, and related parties in accordance with the law and its regulations.
  • Verification before disclosure: Before issuing a credit report, SIMAH verifies the identity of the applicant and the purpose of the request, and obtains the member’s undertaking that the information will not be misused.
  • Security controls are required, not optional: SIMAH establishes data and information security protection controls over the information it holds, and member institutions are expected to mirror that standard on their own side of the connection.
  • Who this touches: Any regulated lender, finance company, or fintech that connects to SIMAH to pull or contribute credit data inherits these confidentiality and security obligations as a condition of membership, not as a separate certification exercise.
Saudi Credit Bureau

SIMAH: Obligations Without a Certificate

SIMAH isn’t a cybersecurity regulator in the way CMA or SAMA are. Its expectations arrive through the agreements and law that govern how credit data moves.

How SIMAH’s obligations actually reach a member

1

Membership agreement

SAMA-approved agreement sets out rights and obligations for both parties.

2

Confidentiality

Credit data shared only with members, other bureaus, and related parties per law.

3

Identity verification

Applicant identity and request purpose verified before any report is issued.

4

Mirrored security

Members are expected to mirror SIMAH’s own data protection controls.

Who this touches: any lender, finance company, or fintech connecting to SIMAH to pull or contribute credit data — as a condition of membership, not a separate certification exercise.

The quick comparison

How CMA, UAE IA, and SIMAH stack up against each other.

DifferentiatorCMA GuidelinesUAE IASIMAH
Issuing bodyCapital Market AuthorityUAE Cybersecurity Council / SIASaudi Credit Bureau, under SAMA
CertifiableNoFramework-based control assessmentNo — via membership agreements
Who it targetsCapital markets institutions in Saudi ArabiaCritical infrastructure & regulated UAE sectorsAny institution exchanging credit data
Core shape4 domains, 26 subdomains188 controls, management + technicalConfidentiality, verification, data security terms

CMA Cybersecurity Guidelines

Issuing bodyCapital Market Authority
CertifiableNo
Who it targetsCapital markets institutions in Saudi Arabia
Core shape4 domains, 26 subdomains

UAE Information Assurance

Issuing bodyUAE Cybersecurity Council / SIA
CertifiableFramework-based control assessment
Who it targetsCritical infrastructure & regulated UAE sectors
Core shape188 controls, management + technical

SIMAH

Issuing bodySaudi Credit Bureau, under SAMA
CertifiableNo — via membership agreements
Who it targetsAny institution exchanging credit data
Core shapeConfidentiality, verification, data security terms

What The Overlap Means For Regulated Startups

Understanding each framework on its own is the easy part. The hard part is what happens when a startup sits inside two or three of them at once.

  • The same evidence, such as access logs, vendor assessments, and incident records, often needs to be reformatted and resubmitted for different regulators on different timelines.
  • Small security and compliance teams end up doing manual triage and evidence chasing across frameworks instead of hardening actual defenses.
  • Gaps tend to surface at the worst time, during a funding round, a new banking partnership, or an audit, rather than during a calm quarter when they could have been caught early.
  • Governance language like scope, permission, approval, and audit trail needs to hold up consistently across every framework a startup answers to, not just the one it started with.
Where Secure.com Fits In

One Regulator Roadmap, One Team to Prove It

Understanding each framework on its own is the easy part. Proving the same evidence, on time, across all of them without burning out a small team is the actual challenge.

Governed Defense. Powered by Offense.

No More Grunt Work. No More Burnout. AI teammates attack your defenses, harden what they find, and hand your team back hundreds of hours a month.

Your team sets the rules AI teammates do the work Attack · Harden · Prove · Repeat
GRC AI Teammate
  • Owns controls, compliance posture, evidence collection, audit readiness, and trust reporting
  • Carries the most weight when CMA, IA, SIMAH, and SAMA obligations all apply at once
  • Keeps evidence current and ready inside the scope, permissions, and approvals your team has set
  • Replaces manually stitching together evidence for four different reviewers
Built On Security OS
  • Attacks, hardens, and proves defensive outcomes above the stack you already own
  • Shared foundation: context, orchestration, governed execution, audit trail, feedback loop
  • Your team sets the rules and approves consequential action
  • A single teammate is complete on day one — no need for the full roster
GRC AI Teammate A single teammate is built to be complete on day one.

Related reads

More on getting audit-ready without burning out the team.

FAQs

Does a startup regulated by SAMA also need to worry about CMA?
Only if the startup’s activities fall under CMA oversight, typically anything touching Saudi capital markets. SAMA and CMA are separate regulators with separate expectations, so being aligned with one does not automatically satisfy the other.
Is the UAE Information Assurance Standard relevant to a Saudi-based startup?
It can be. IA obligations attach to organizations connected to UAE critical infrastructure or regulated sectors, not strictly to where a company is headquartered. A Saudi startup expanding infrastructure or partnerships into the UAE should check whether that connection puts it in scope.
Is SIMAH a regulator that startups need to get certified against?
No. SIMAH does not run its own certification program. Its cybersecurity expectations come through SAMA-approved membership agreements and the Credit Information Law, which require confidentiality, identity verification, and data protection controls from every member.
Are the CMA Cybersecurity Guidelines certifiable?
No. They are non-certifiable, but compliance is mandatory, and organizations are expected to implement the full set of requirements to stay ready for CMA audits.
How does Secure.com help a startup manage several overlapping frameworks at once?
The GRC AI Teammate keeps controls, evidence, and audit readiness current inside the scope and approvals a team sets, so the same underlying work does not have to be manually rebuilt every time a new framework, like CMA, IA, or SIMAH, enters the picture.

Conclusion

SAMA is the framework most regulated startups meet first, but it is rarely the last one they encounter. CMA, UAE IA, and SIMAH each bring their own scope, structure, and evidence expectations, and a startup that grows fast enough to matter will likely touch more than one of them. Knowing which framework applies, and why, is the first step. Being able to prove compliance across all of them without drowning the team in grunt work is the next one.