Key Takeaways
- The CMA Cybersecurity Guidelines are non-certifiable but mandatory for financial institutions operating in Saudi capital markets, covering governance, risk management, operational controls, and third-party cybersecurity across 4 domains and 26 subdomains.
- The UAE Information Assurance (IA) Standard, originally issued by NESA and now under the UAE Cybersecurity Council and Signals Intelligence Agency (SIA), is a 188-control framework that matters to any startup connected to UAE critical infrastructure or regulated sectors, not only UAE-headquartered firms.
- SIMAH is not a regulator with its own published control framework. Its cybersecurity expectations arrive through SAMA-approved membership agreements and the Credit Information Law, which require confidentiality, identity verification, and data protection controls from every member institution.
- A startup that only maps to SAMA can still be out of alignment with CMA, IA, or SIMAH obligations if it touches capital markets, UAE infrastructure, or credit data.
- The operational challenge is rarely understanding each framework on its own. It is proving the same evidence, on time, across all of them without burning out a small security team.
Most fintech and regulated startups in Saudi Arabia build their entire security program around one acronym: SAMA. That instinct is not wrong. But SAMA is not the only body a growing startup will answer to. Depending on what you build, who funds you, where you operate, and who you exchange data with, the Capital Market Authority (CMA), the UAE’s Information Assurance (IA) framework, and the Saudi Credit Bureau (SIMAH) can all show up on your compliance roadmap, often at the same time.
This piece is a quick map, not a full implementation guide. It is meant to help founders, CISOs, and compliance leads at regulated startups recognize which of these apply to them, what each one actually expects, and how the overlap changes the way security work gets planned and evidenced.
Why Looking Beyond SAMA Matters
SAMA’s Cyber Security Framework gets most of the attention because it covers banks, insurers, and finance companies, which is where a large share of regulated startups sit. But regulatory exposure in the Gulf rarely stops at one framework. A payments startup raising capital may trigger CMA obligations. A company expanding operations or infrastructure into the UAE may trigger IA obligations. Any lender or finance company that pulls or contributes credit data touches SIMAH’s data-sharing rules. None of these show up on day one, and none of them replace SAMA. They stack on top of it.
One Regulator Is Rarely the Only One
SAMA is where most regulated startups start. But depending on what you build and who you connect to, three more frameworks can land on the same roadmap — often at once.
Capital markets
Triggered by raising capital or offering products under Capital Market Authority oversight.
Cross-border infrastructure
Triggered by operations, customers, or partnerships connected to UAE critical infrastructure.
Credit data exchange
Triggered the moment a lender or finance company pulls or contributes credit data.
CMA Cybersecurity Guidelines At a Glance
The Capital Market Authority’s Cybersecurity Guidelines apply to entities operating in Saudi Arabia’s capital markets under CMA oversight.
CMA Cybersecurity Guidelines, At a Glance
Capital Market AuthorityThe four domains
What it actually means for you
- Who it applies to: All financial institutions operating within Saudi Arabia under CMA oversight are required to comply.
- Certifiable or not: The guidelines are non-certifiable requirements, but compliance is still mandatory, and organizations are expected to align with them to avoid penalties and regulatory consequences.
- Structure: The guidelines are organized into 4 main domains and 26 subdomains, covering governance, risk management, operational controls, and third-party cybersecurity.
- What “done” looks like: Once an organization has implemented all the requirements, it remains ready for CMA audits rather than earning a certificate.
For a startup, the practical read is this: if you are regulated by the CMA because of what you offer in the capital markets, the guidelines are not optional just because there is no certificate to hang on the wall.
UAE Information Assurance (IA)
UAE Information Assurance (IA), At a Glance
One of the more technically demanding frameworks in the region — and it can reach a Saudi-headquartered startup through a single UAE connection.
Who it applies to
Organizations running critical national infrastructure across all UAE emirates — and private-sector operators classified within those sectors too.
Why it reaches beyond the UAE
A Saudi-based startup isn’t automatically in scope — but infrastructure, customers, or partnerships tied to UAE regulated sectors can pull it in regardless of HQ.
Sectors in scope
Enforcement has teeth. Shortcomings in risk assessment, personal data protection, or incident response can carry penalties reaching into the millions of dollars.
The UAE Information Assurance Standard started life under the National Electronic Security Authority (NESA) and is now administered under the UAE Cybersecurity Council, with the Signals Intelligence Agency (SIA) carrying forward NESA’s operational role.
- Who it applies to: Organisations operating critical national infrastructure across all UAE emirates, spanning energy, utilities, telecommunications, transport, financial infrastructure, healthcare, and government systems are expected to comply, and private sector organizations in these sectors can be classified as critical infrastructure operators too.
- Scale of the framework: The IA framework is organised around 188 security controls split across four strategic domains, with 60 management-level controls and 128 technical security controls, making it one of the more technically demanding frameworks in the region.
- Why it matters beyond the UAE: A Saudi-based startup is not automatically in scope. But if your infrastructure, customers, or partnerships connect you to UAE financial infrastructure or another regulated UAE sector, IA expectations can follow that connection even if your headquarters sits in Riyadh.
- Enforcement has teeth: Failing to comply can lead to serious consequences, including financial penalties that can reach into the millions of dollars for shortcomings in risk assessment, personal data protection, or incident response.
SIMAH And The Data Sharing Obligations Behind It
SIMAH, the Saudi Credit Bureau, is not a cybersecurity regulator in the way CMA or SAMA are. It does not publish its own public control catalogue for member institutions to certify against. Its cybersecurity expectations arrive through the agreements and law that govern how credit data moves.
- What governs the relationship: SIMAH is obliged to sign membership agreements approved by the Saudi Central Bank with any party that wants to obtain credit information, and those agreements set out the rights and obligations of both parties.
- Confidentiality is explicit: SIMAH is committed to maintaining confidentiality over the credit information and data in its possession and to sharing it exclusively with members, other bureaus, and related parties in accordance with the law and its regulations.
- Verification before disclosure: Before issuing a credit report, SIMAH verifies the identity of the applicant and the purpose of the request, and obtains the member’s undertaking that the information will not be misused.
- Security controls are required, not optional: SIMAH establishes data and information security protection controls over the information it holds, and member institutions are expected to mirror that standard on their own side of the connection.
- Who this touches: Any regulated lender, finance company, or fintech that connects to SIMAH to pull or contribute credit data inherits these confidentiality and security obligations as a condition of membership, not as a separate certification exercise.
SIMAH: Obligations Without a Certificate
SIMAH isn’t a cybersecurity regulator in the way CMA or SAMA are. Its expectations arrive through the agreements and law that govern how credit data moves.
How SIMAH’s obligations actually reach a member
Membership agreement
SAMA-approved agreement sets out rights and obligations for both parties.
Confidentiality
Credit data shared only with members, other bureaus, and related parties per law.
Identity verification
Applicant identity and request purpose verified before any report is issued.
Mirrored security
Members are expected to mirror SIMAH’s own data protection controls.
The quick comparison
How CMA, UAE IA, and SIMAH stack up against each other.
| Differentiator | CMA Guidelines | UAE IA | SIMAH |
|---|---|---|---|
| Issuing body | Capital Market Authority | UAE Cybersecurity Council / SIA | Saudi Credit Bureau, under SAMA |
| Certifiable | No | Framework-based control assessment | No — via membership agreements |
| Who it targets | Capital markets institutions in Saudi Arabia | Critical infrastructure & regulated UAE sectors | Any institution exchanging credit data |
| Core shape | 4 domains, 26 subdomains | 188 controls, management + technical | Confidentiality, verification, data security terms |
CMA Cybersecurity Guidelines
UAE Information Assurance
SIMAH
What The Overlap Means For Regulated Startups
Understanding each framework on its own is the easy part. The hard part is what happens when a startup sits inside two or three of them at once.
- The same evidence, such as access logs, vendor assessments, and incident records, often needs to be reformatted and resubmitted for different regulators on different timelines.
- Small security and compliance teams end up doing manual triage and evidence chasing across frameworks instead of hardening actual defenses.
- Gaps tend to surface at the worst time, during a funding round, a new banking partnership, or an audit, rather than during a calm quarter when they could have been caught early.
- Governance language like scope, permission, approval, and audit trail needs to hold up consistently across every framework a startup answers to, not just the one it started with.
One Regulator Roadmap, One Team to Prove It
Understanding each framework on its own is the easy part. Proving the same evidence, on time, across all of them without burning out a small team is the actual challenge.
Governed Defense. Powered by Offense.
No More Grunt Work. No More Burnout. AI teammates attack your defenses, harden what they find, and hand your team back hundreds of hours a month.
- Owns controls, compliance posture, evidence collection, audit readiness, and trust reporting
- Carries the most weight when CMA, IA, SIMAH, and SAMA obligations all apply at once
- Keeps evidence current and ready inside the scope, permissions, and approvals your team has set
- Replaces manually stitching together evidence for four different reviewers
- Attacks, hardens, and proves defensive outcomes above the stack you already own
- Shared foundation: context, orchestration, governed execution, audit trail, feedback loop
- Your team sets the rules and approves consequential action
- A single teammate is complete on day one — no need for the full roster
Related reads
More on getting audit-ready without burning out the team.
What Manual Compliance Really Costs You
What a typical SOC 2 audit actually demands in evidence, and where the hours go.
Audit PrepSOC 2 Readiness Assessment Checklist
A practice run for finding control gaps before the formal audit finds them for you.
GovernanceWhat Auditors Actually Expect From Pen Testing
How to document and govern penetration tests so the evidence holds up in a compliance audit.
FAQs
Does a startup regulated by SAMA also need to worry about CMA?
Is the UAE Information Assurance Standard relevant to a Saudi-based startup?
Is SIMAH a regulator that startups need to get certified against?
Are the CMA Cybersecurity Guidelines certifiable?
How does Secure.com help a startup manage several overlapping frameworks at once?
Conclusion
SAMA is the framework most regulated startups meet first, but it is rarely the last one they encounter. CMA, UAE IA, and SIMAH each bring their own scope, structure, and evidence expectations, and a startup that grows fast enough to matter will likely touch more than one of them. Knowing which framework applies, and why, is the first step. Being able to prove compliance across all of them without drowning the team in grunt work is the next one.