Templates
SAMA Quantum Computing Readiness Pack
The circular applies to banks, credit information companies, finance companies, payment service companies, and support entities for financing activity licensed by the Saudi Central Bank. It imposes no filing obligation. Compliance is demonstrated through the evidence an institution holds and through the minutes of its committees, which means the exposure arrives at examination rather than at a submission date.
That shapes what this pack contains. Every document produces evidence. Every procedure states the artifact that closes it and the acceptance test that proves it. The working model calculates rather than collects, so a change to a weight or an assumption recalculates the whole priority picture instead of requiring the analysis to be redone.
The pack was written against the official circular text, not against press reporting of it. The four measures are reproduced as worded, including the points most often lost in summary: the risk category list is expressly non-exhaustive and names human capital within it, Measure 3 carries no date of its own but follows the outputs of Measure 2, and the standing governance item applies where applicable with escalation to the Board or its equivalent.
Method is distinguished from obligation throughout. Where a document specifies an exposure test, a weighting model or a target algorithm, it says so and marks it as professional practice, tunable to the institution's own risk posture. Nothing is presented as a regulatory requirement that the circular does not impose.
What is inside
Twelve documents
Quantum Computing Risk and Cryptographic Resilience Policy — board-level policy with a statement-by-statement embedding table showing which form, checklist or pipeline each clause is wired into
Cryptographic Asset Inventory and Classification Procedure — nine-step procedure with a full implementation runbook, six discovery techniques sequenced with what each one misses, and cycle acceptance criteria
Quantum Risk Assessment Methodology and Report — twelve-week delivery plan, workshop facilitation protocol, a worked scoring example and the scoring errors to correct at calibration
Post-Quantum Cryptography Migration Strategy and Roadmap — target cryptographic state, seven phases with gates, and seven documented alternative solutions with their limitations
Governance Addendum and Board Reporting Pack — terms of reference amendment clauses, a six-page reporting pack template, escalation protocol and minute wording
Third-Party Quantum Readiness Assessment and Contract Clauses — a 24-question vendor attestation, a six-dimension scoring rubric and five contract clauses
Compliance Attestation and Evidence Pack — evidence index mapped to each measure, attestation, correspondence template and an 18-question examination readiness checklist
Program Delivery Roadmap and Milestone Plan — 23 milestones, critical path with float analysis, quarter-by-quarter plan, resource and budget structure, gate reviews
Board Briefing Deck — 15 slides taking a board from the circular to the four decisions it needs to make
Cryptographic Standard — approved algorithms, key lengths, protocol versions and modes, minimum requirements by data classification, and a dated deprecation calendar
Key Management Standard — four-tier key hierarchy, full lifecycle from ceremony to destruction, separation of duties, and what post-quantum specifically breaks in key handling
Program Charter — objectives with measures of achievement, decision rights, seven workstreams, assumptions and constraints, and a definition of done
Assurance Test Program — four audit engagements with numbered procedures, sample sizes, a stratified sampling method and the form of the opinion
The working model
A 15-sheet workbook with 1,545 formulas: requirement traceability, a 24-field cryptographic bill of materials, sensitivity and priority classification, data and services classification, crypto-agility assessment, third-party register, risk register, treatment plans, roadmap, exception register, governance calendar, trend history and a rolled-up dashboard.
Every dropdown value, weight, threshold and deadline lives on a single reference sheet as an editable cell. Nothing is hardcoded. Change the threat horizon assumption and every priority tier recalculates.
Worked examples are seeded throughout so the model can be checked against a known answer before real data is loaded: eight inventory records spanning core banking, correspondent messaging, payment switching, database encryption, cloud, code signing, backup and branch environments, five third-party records including one non-responsive vendor, eight data and service records, eighteen risks, twenty-two treatment actions and twenty-three milestones.
Bilingual, properly
English and Arabic are delivered as two separate packages. No file mixes languages, and no workbook sheet does either.
The Arabic edition is not a translation laid over an English layout. Page direction, headings, lists, tables, headers and footers all run right to left, and the workbook has Arabic sheet names, Arabic dropdown values and Arabic formula literals, with every calculation verified to produce identical results to the English edition.
Each package contains the documents in Word, the same documents in PDF, the workbook and the presentation, in separate folders.
Who this is for
Chief information security officers, heads of compliance, chief risk officers, internal audit functions and program managers at institutions within the circular's distribution scope. It also suits consultancies and advisory teams delivering readiness work for those institutions.
Before you use it
This is a professional template set, not a completed compliance position. Content in angle brackets must be completed by the institution. The algorithm selections, weights, thresholds and dates reflect prevailing practice and should be calibrated to your own estate and risk appetite, then approved through your own governance.
The pack does not constitute legal advice, and it does not replace reading the circular itself.
Author
Prepared by AlHasan AlGhamdi, Founder of CISO Consulting, a Saudi cybersecurity governance, risk and compliance consultancy based in Riyadh advising financial institutions across the Kingdom and the wider Gulf.
PublisherAlHasan AlGhamdi
Version1.0
ClassificationRegistered
Format · SizeZIP · 48.1 MB
Last revision2026-09
🛡 Signed link
QuantomComputingSAMA