Post-Quantum Cryptography for Banks: Saudi Guide
Post-Quantum Cryptography for Banks: Saudi Guide

Post-Quantum Cryptography for Banks: Saudi Guide
Post-quantum cryptography for banks is moving from a future-facing security topic to a practical risk-management priority across the GCC. For banks in Saudi Arabia, the UAE and Qatar, the immediate challenge is not replacing every RSA or ECC implementation overnight. It is knowing where vulnerable cryptography exists, which systems matter most, and how to migrate without disrupting payments, authentication or critical banking services.
In practical terms, GCC banks should start with cryptographic asset discovery, quantum-risk assessment and crypto agility. Saudi institutions face explicit SAMA requirements and deadlines, while the UAE has introduced national encryption requirements that address post-quantum cryptography, and Qatar has already demonstrated operational quantum-safe communications infrastructure.
What Is Post-Quantum Cryptography for Banks?
Post-quantum cryptography, or PQC, uses cryptographic algorithms designed to resist attacks from both conventional computers and future cryptographically relevant quantum computers.
For banks, that matters because public-key cryptography protects a wide range of systems: TLS connections, certificates, digital signatures, authentication, payment infrastructure, APIs, software signing and secure exchanges with third parties.
How quantum computing threatens RSA and ECC
RSA and elliptic-curve cryptography depend on mathematical problems that are difficult for today’s conventional computers to solve.
A sufficiently powerful quantum computer running Shor’s algorithm could change that security assumption. No bank needs to panic or rip out its cryptographic infrastructure immediately, but waiting until such systems become practical would leave little room for controlled migration.
Large financial environments can take years to inventory, test and update because cryptography is often buried inside applications, hardware security modules, vendor platforms and legacy systems.
Why “harvest now, decrypt later” matters
The quantum threat is not only about what an attacker might do in the future.
Sensitive encrypted information can potentially be collected today and retained until future technology makes decryption feasible. This “harvest now, decrypt later” scenario matters most for information that must remain confidential for many years, such as customer identities, corporate records, financial agreements and sensitive transaction data.
That makes data lifespan an important part of any quantum-risk assessment.
PQC vs quantum key distribution
Post-quantum cryptography and quantum key distribution are related but different approaches.
PQC uses quantum-resistant mathematical algorithms and can often be introduced through software, protocol and infrastructure changes. Quantum key distribution, or QKD, uses quantum-mechanical properties to distribute encryption keys and normally requires specialized communications infrastructure.
Qatar offers a useful regional example: Ooredoo, Hamad Bin Khalifa University and the Ministry of Defence announced the country’s first QKD-enabled quantum-safe communications link on May 31, 2026.
Why Post-Quantum Cryptography for GCC Banks Matters Now
Quantum readiness is developing differently across Saudi Arabia, the UAE and Qatar. Banks should therefore separate global technical standards from local regulatory obligations instead of assuming one framework satisfies another.
Saudi Arabia.
Saudi Arabia currently has the clearest supervisory requirements in the region.
SAMA’s in-force circular, dated August 27, 2026, requires financial institutions to complete an enterprise-level quantum-computing risk assessment by the end of Q1 2027.
It also requires accurate and comprehensive procedures for identifying and classifying cryptographic assets by the end of Q4 2026. Institutions must connect those assets to relevant data, systems and services, classify migration priorities, assess resilience and identify constraints and third-party dependencies. Quantum risk must also become part of ongoing governance and board-level risk oversight where applicable.
For banks in Riyadh, Jeddah and elsewhere in Saudi Arabia, this shifts PQC from an exploratory technology topic into a concrete operational-resilience programme.
UAE.
The UAE’s National Encryption Policy requires encryption controls for data at rest and in transit and specifically addresses key management, post-quantum cryptography, implementation and ongoing monitoring.
That does not mean every UAE bank has an identical migration path. Institutions still need to map the national policy, sector-specific obligations and internal risk frameworks to their technical environments.
The UAE also has an active post-quantum research ecosystem. Abu Dhabi’s Technology Innovation Institute conducts PQC research and has contributed to NIST’s ongoing post-quantum standardization work.
For banks operating in Dubai, Abu Dhabi, DIFC or ADGM environments, the sensible approach is to treat PQC readiness as part of broader cryptographic governance rather than as a standalone technology project.
Qatar.
Qatar’s first operational QKD-based quantum-safe communications link is an early signal of national interest in quantum-secure infrastructure.
For banks in Doha, the immediate opportunity is not necessarily to deploy QKD everywhere. It is to use this period to identify cryptographic dependencies, test quantum-resistant architectures and monitor how local supervisory expectations evolve.
Banks in Bahrain, Kuwait and Oman can take a similar preparation-first approach rather than waiting for highly prescriptive requirements.

What Cryptographic Assets Should Banks Inventory First?
A cryptographic asset inventory is the foundation of a credible post-quantum programme. If a bank cannot locate its existing cryptography, it cannot confidently migrate it.
RSA, ECC, certificates, TLS and PKI
Start by finding where RSA and ECC are used across.
TLS endpoints and certificates
Public key infrastructure
Certificate authorities
Authentication systems
Code-signing workflows
Digital signatures
Database and application encryption
Internal and external APIs
This work fits naturally alongside broader API security controls and Zero Trust architecture.
Discovery should include certificate lifetimes and data-retention periods. A certificate expiring soon creates a different migration problem from a cryptographic dependency embedded inside a core banking platform expected to remain in service for years.
HSMs, key management and core banking dependencies
Banks should also map the infrastructure responsible for generating, protecting and using cryptographic keys.
That includes HSMs, enterprise key-management platforms, payment gateways, ATM and card environments, mobile banking services, core banking applications and identity platforms.
Changing an algorithm in a specification is easy. Changing it safely across interconnected banking infrastructure is not.
Third-party fintech and cloud dependencies
Vendor risk deserves equal attention.
Banks increasingly depend on fintech providers, cloud platforms, SaaS applications, payment processors and open-banking integrations. Those suppliers may control certificates, key-management components or cryptographic libraries that the bank cannot replace independently.
Procurement teams should therefore document vendor roadmaps, supported algorithms, HSM compatibility, certificate capabilities and contractual dependencies early in the migration programme.
Which PQC Standards Should GCC Banks Follow?
NIST’s finalized post-quantum standards provide an important technical foundation for GCC institutions.
They do not, however, replace local regulatory requirements.
FIPS 203 and ML-KEM
NIST FIPS 203 specifies ML-KEM, a module-lattice-based key-encapsulation mechanism designed for establishing shared secrets over public channels.
NIST published the final standard on August 13, 2024.
For banks, ML-KEM is especially relevant when evaluating future approaches to secure key establishment and communications.
FIPS 204 and ML-DSA
FIPS 204 specifies ML-DSA, a post-quantum digital-signature algorithm.
Digital signatures are important across authentication, software signing, certificates and transaction-related trust mechanisms. Banks should evaluate ML-DSA against their actual use cases rather than treating it as a universal drop-in replacement.
FIPS 205 and SLH-DSA
FIPS 205 specifies SLH-DSA, a stateless hash-based digital-signature algorithm.
NIST finalized FIPS 203, FIPS 204 and FIPS 205 together in August 2024 as its first three finalized post-quantum cryptography standards.
Global standards still require local governance mapping
Technical standardization and regulatory compliance are not the same thing.
A Saudi bank must map PQC decisions to SAMA requirements and other applicable Saudi controls. UAE institutions need to consider the National Encryption Policy alongside sector-specific obligations. Banks elsewhere in the GCC should apply the same principle to their local regulators and internal risk frameworks.
How Should GCC Banks Migrate to Post-Quantum Cryptography?
Migration should be treated as a staged risk programme, not a mass algorithm replacement exercise.
Build the cryptographic inventory and quantum-risk register
Discover where cryptography exists and connect each asset to.
The system or service it protects
The algorithm and key type in use
Data sensitivity
Required confidentiality lifespan
Certificate and key lifecycles
Internal dependencies
Third-party dependencies
Migration complexity
The result should be a prioritized risk register rather than an unstructured spreadsheet of certificates.
Prioritize high-risk systems and build crypto agility
Crypto agility means designing systems so cryptographic algorithms, keys and protocols can be replaced without rebuilding the entire application.
For banks, priority areas typically include long-lived sensitive records, customer authentication, PKI, payment systems, external APIs, code signing and critical HSM-backed workloads.
Crypto agility is important because today’s standardized PQC algorithms may not be the last cryptographic transition financial institutions face.
Pilot hybrid and PQC-ready architectures
Avoid moving directly from inventory to production-wide replacement.
Test PQC-ready and hybrid designs in controlled environments. Measure certificate sizes, connection performance, application behavior, HSM support, network compatibility and vendor interoperability.
Rollback procedures matter too. A migration that improves cryptographic strength but introduces instability into critical banking services is not a successful security programme.
Operational teams can complement this work with guidance on cloud misconfiguration prevention and cyber incident response.
Saudi vs UAE vs Qatar: Different PQC Priorities
The technical destination may be similar, but local priorities differ.
| Market | Current emphasis | Practical banking priority |
|---|---|---|
| Saudi Arabia | Explicit SAMA quantum-risk requirements | Inventory, classification, enterprise assessment and migration planning |
| UAE | National encryption policy plus active PQC research ecosystem | Map policy requirements, strengthen crypto governance and test migration architectures |
| Qatar | Operational quantum-safe communications activity | Build inventory, test quantum-resistant approaches and monitor banking requirements |
Saudi Arabia.
For Saudi financial institutions, post-quantum cryptography for banks should begin with the milestones already defined by SAMA.
The key point is not simply to produce compliance documentation. Banks should use the exercise to create an accurate map of cryptographic dependencies that can support an actual migration programme.
UAE.
Dubai and Abu Dhabi institutions can connect PQC work to wider encryption governance, cloud modernization and digital-finance programmers.
Vendor readiness will be particularly important in complex environments spanning on-premises infrastructure, cloud platforms, fintech integrations and regional financial ecosystems.
Qatar.
Doha institutions have an opportunity to build readiness before bank-specific quantum requirements become more prescriptive.
That means identifying long-lived confidentiality risks now, understanding vendor dependencies and testing where quantum-resistant cryptography can be introduced safely.

Best Practices for Building a Quantum-Safe GCC Bank
Make crypto agility part of enterprise architecture
Do not treat post-quantum migration as a one-time upgrade.
New systems should make cryptographic components replaceable wherever practical. That reduces future migration costs and prevents individual algorithms from becoming deeply embedded across applications.
Add PQC readiness to vendor procurement
Banks should ask technology suppliers clear questions.
Which NIST-standardized PQC algorithms do you support?
Do you support hybrid deployments?
Are your HSMs and key-management platforms PQC-ready?
What certificate and PKI changes are required?
What is your migration roadmap?
Which dependencies could block implementation?
A Dubai bank modernizing its infrastructure can also connect PQC planning with GCC cloud disaster-recovery guidance and broader resilience planning.
Bring security, risk, compliance and application teams together
PQC cannot sit only with the cryptography team.
CISOs, security architects, enterprise architects, application owners, compliance teams, procurement specialists and risk leaders all have roles to play.
This is especially important in GCC banks where Arabic and English customer channels may rely on shared identity platforms, certificates, APIs and back-end infrastructure.
Teams planning broader modernization can also review serverless computing for GCC organizations and AI infrastructure planning for GCC enterprises.

Final Words
Post-quantum cryptography for banks does not require every RSA or ECC system to be replaced immediately. It requires banks to understand their exposure before time pressure turns a manageable technology transition into an operational crisis.
For GCC institutions, the practical sequence is:
Discover → Assess → Prioritize → Build crypto agility → Pilot → Migrate.
Saudi banks already have explicit SAMA milestones to work toward. UAE banks have a national encryption policy that includes post-quantum cryptography, while Qatar’s quantum-safe communications activity shows that the wider regional ecosystem is moving forward.
The strongest starting point is visibility: know which cryptography you depend on, how long the protected data must remain secure, which vendors can support migration and which systems will be hardest to change.
Mak It Solutions can help GCC organizations turn quantum-readiness questions into a practical technical roadmap. Explore Mak It Solutions services or contact the team to discuss a cryptographic asset assessment, architecture review or Saudi, UAE or Qatar-focused strategy.
This article provides general cybersecurity and technology information. Regulatory requirements should be confirmed against the latest official guidance applicable to your institution.
FAQs
Q : Are Saudi banks required to assess quantum-computing risk?
A : Yes. SAMA’s August 27, 2026 circular requires covered financial institutions to conduct an enterprise-level quantum-computing risk assessment by the end of Q1 2027. It also requires comprehensive procedures for identifying and classifying cryptographic assets by the end of Q4 2026.
Q : Does the UAE National Encryption Policy address post-quantum cryptography?
A : Yes. The UAE government’s published description says the National Encryption Policy includes requirements covering key management, post-quantum cryptography, implementation and ongoing monitoring. Banks should still map those requirements to the other regulations and internal controls that apply to their specific environment.
Q : Which NIST post-quantum standards are most relevant to GCC banks?
A : The first three finalized NIST PQC standards are FIPS 203, FIPS 204 and FIPS 205. They specify ML-KEM for key establishment, ML-DSA for digital signatures and SLH-DSA for digital signatures respectively.
Q : Can banks migrate to PQC without replacing their entire PKI?
A : Potentially. A staged migration can combine crypto agility, certificate changes, hybrid approaches and gradual infrastructure upgrades. Banks still need to test certificate authorities, HSMs, TLS endpoints, applications and third-party interoperability before production rollout.
Q : What is the difference between crypto agility and post-quantum migration?
A : Crypto agility is the architectural ability to change cryptographic algorithms, keys or protocols without major system redesign. Post-quantum migration is the specific transition away from quantum-vulnerable public-key cryptography toward quantum-resistant alternatives. Building crypto agility makes both the current PQC transition and future cryptographic changes easier to manage.


