CMA Cybersecurity Guidelines

CMA CSG

What it is

The Capital Market Authority’s cybersecurity guidelines for financial market institutions — how they govern, manage and test their cybersecurity.

What it covers

  1. 01Governance
  2. 02Risk management, review and audit
  3. 03Operational controls
  4. 04Third-party security

How we help

  • Gap assessment against the guidelines
  • Governance and policy set
  • Risk and audit review
  • Remediation roadmap

In depth

The guidelines ask each institution to run cybersecurity as a governed program: a board-approved strategy and policies, regular risk reviews and audits, sound controls in daily operations, and security terms with every supplier and cloud provider.

We map where you stand against each area, close the gaps that matter most first, and prepare the evidence the CMA expects to see.

Related services

Other frameworks we work with

Ready to meet CMA CSG?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Trust

Built around the regulators you answer to

SAMA
Saudi Central BankCSF · BCM · CRFR
NCA
National Cybersecurity AuthorityECC-2:2024 · CSCC · CCC
SDAIA
Saudi Data & AI AuthorityPDPL
CMA
Capital Market AuthorityCSG
CST
Communications, Space & Technology CommissionCRF
14regulatory frameworks

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment