Ask a bank’s CISO how many cryptographic certificates are live across their environment right now, and you’ll usually get a pause before the answer. Not because they don’t know the business. Because almost nobody actually knows until they go looking.
That’s the conversation I have most weeks, with CISOs and heads of cybersecurity across Saudi Arabia and the wider Gulf.
Why quantum readiness is becoming a present-day priority
A quick introduction for anyone reading this from outside the region: SAMA, the Saudi Central Bank, is the regulator responsible for the safety and soundness of Saudi Arabia’s banks, insurers, and finance companies. It’s comparable to a central bank anywhere else that also acts as the financial sector’s supervisor. Like regulators in a number of other markets, SAMA has turned its attention to a specific, forward-looking risk: the point at which today’s encryption can no longer protect data once quantum computers are powerful enough to break it. SAMA has set expectations for the institutions it regulates to understand their exposure to that risk and build a plan to address it.
For a long time, that was a someday conversation everywhere, not just in Saudi Arabia. Quantum computers will eventually break today’s encryption, so organizations should eventually have a plan. It’s not a uniquely regional shift, either: in the US, the White House has pointed to cryptographic inventory as the first and most critical step for federal agencies preparing for the quantum transition, and Singapore’s Monetary Authority has issued similar advisories to its own financial sector. SAMA’s expectations moved that into the present tense for the banks and financial institutions it regulates here.
The institutions I talk to are no longer debating whether to start. They’re debating how to start without disrupting everything else running on the same infrastructure.
Three expectations: inventory, risk assessment, and governance
Reduced to its essentials, SAMA is asking regulated institutions for three things, each building on the last. First, a complete cryptographic inventory, discovering and classifying what’s actually out there. Second, a risk assessment that prioritizes what to fix first, built on top of that inventory. Third, ongoing governance: proof that the picture stays current and that remediation gets tracked, not just promised. SAMA’s August 27, 2026 circular sets specific expectations: institutions must ensure accurate and comprehensive identification and classification of cryptographic assets by the end of Q4 2026, conduct an enterprise-level quantum-risk assessment by the end of Q1 2027, develop remediation plans, and make quantum risk a standing governance item.
In practice, each of those three asks runs into the same three problems.
The first is scale. Most teams assume their cryptographic inventory is a manageable list, until discovery actually starts and certificates, keys, and algorithms turn up in places nobody remembered: legacy systems, third-party platforms, code repositories, cloud services added years after the original architecture review. This isn’t unique to any one bank. It’s the normal condition of a large, complex financial institution, and it’s exactly why a one-time spreadsheet exercise doesn’t hold up. The starting point is getting a straight, continuously updated answer to “what do we actually have.”
The second is ownership. Finding an asset isn’t the same as knowing who’s responsible for it, what it protects, or what breaks if it changes. Risk teams need that context to prioritize sensibly. Without it, every finding looks equally urgent, which in practice means nothing gets fixed first. This is the piece that tends to separate tools that just scan from tools that actually help prioritise.
The third is proof. Boards and regulators are both asking the same underlying question in different words: show me the evidence. A list isn’t evidence. A continuously updated inventory, tied to risk and tracked remediation, is. That continuity probably matters most: keeping the picture current long after the first audit is done.
Building a standing function, not a one-time project
This pattern isn’t new, even if quantum is. We saw something similar when GDPR forced organisations to map where personal data actually lived, often for the first time, and when SOX-era controls forced finance teams to document exactly which systems touched financial reporting. In both cases, the hard part was never really the technology. It was discovering what already existed and agreeing who owned it. Cryptography is following the same arc, just a few years behind.
Some of the world’s largest banks are already treating it that way. HSBC has gone as far as co-authoring a public paper on cryptographic inventory with Keyfactor and one of its technology partners, with named leads running dedicated cryptographic-agility and quantum-technology programmes inside the bank. That’s not a project assigned to whoever’s available. That’s a standing function with its own mandate, its own specialists, and its own publishing record. I’d expect more GCC institutions to make a similar move over the next year, whether or not SAMA’s timeline is the trigger.
Choosing where to start
Those three problems—scale, ownership, and proof—are where Keyfactor’s AgileSec can help. It maintains a continuously updated cryptographic inventory, ties findings back to owners and business systems automatically, and connects that picture to risk and tracked remediation. Most of the AgileSec conversations I have start with that practical question: “what do we actually have?” From there, the work is to decide what needs attention first and keep the evidence current long after the first audit is done.
If your team is still at the stage of asking what a complete inventory would even look like for your organization, that’s a normal place to be. I’d rather have that conversation now, while there’s still room to plan, than later, when the only option left is to react.
What I find most interesting, watching this unfold across the Gulf, is how differently institutions are sequencing it. Some start with the technical discovery and work backwards to ownership. Others assign ownership first and let that decide what gets discovered first. I don’t think there’s one right order. But I do think the institutions that pick one and commit to it will be in a very different position twelve months from now than the ones still debating where to start.
Moheit Walia is Keyfactor’s Regional Sales Director for the GCC, with 15 years of experience in the cybersecurity industry. He works closely with banks, financial institutions and industry leaders across the region, having consultative conversations around cryptographic risk, resilience and quantum readiness, while helping organisations understand and prepare for the evolving security landscape.