Get Demo
↑

PCI DSS Compliance in the UAE and Saudi Arabia: CBUAE, SAMA, and QSA Paths

PCI DSS in UAE and Saudi Arabia - CBUAE card-scheme PCI obligations, SAMA.

Published: September 2026 Compliance · PCI DSS 8-12 min read

In the UAE and Saudi Arabia, PCI DSS still validates through card-brand and acquirer SAQ/ROC programs. Central-bank instruments add sector-specific duties - they do not replace Attestations of Compliance, and they do not create a PCI SSC entity certificate.

Related: Saudi merchants · GCC PCI · Pakistan · PCI vs ISO · Certification myth · Fines.

Gotcha: SAMA CSF or UAE Information Assurance alignment is not an automatic PCI AOC. Run regulator and brand tracks with a shared control library. CBUAE Article 18 binds Card Schemes, not every merchant or PSP.

UAE — CBUAE Article 18 (Card Schemes only)

Source: Central Bank of the UAE Rulebook, Article (18): Card Schemes, Circular C 15/2021 (effective 6/6/2021, in force). rulebook.centralbank.ae — Article 18.

Information Security paragraphs:

Scope caveat: These duties bind licensed Card Schemes. Merchants and PSPs still follow acquirer/brand PCI validation; scheme-level Article 18 obligations do not erase merchant or SP SAQ/ROC requirements.

Saudi Arabia — SAMA Cyber Security Framework v1.0

Document: SAMA Cyber Security Framework Version 1.0, May 2017 (Rulebook applicability entry dated 24/5/2017, in force). PDF: SAMA Rulebook store (SAMA_EN_3837_VER1).

§1.4 Applicability (bank vs non-bank split): All domains apply to the banking sector. For other financial institutions, exceptions apply - including exclusion of sub-domain 3.2.3. However, if the organization stores, processes, or transmits cardholder data or deals with SWIFT services, then the PCI standard and/or SWIFT Customer Security Controls Framework should be implemented.

§3.2.3 Compliance with (inter)national industry standards (applies to banks / where the domain is in scope): Member Organizations should comply with mandatory industry standards, with control considerations listing PCI-DSS, EMV, and SWIFT CSCF (March 2017 edition referenced in the framework).

Framework language is SAMA control-consideration style (“should comply / should be implemented”) - not “PCI SSC certification.”

Saudi Arabia — Payments Implementing Regulations, Article 35

Document: Implementing Regulations of the Payments and Payment Services Law, Article 35 (SAMA Rulebook). Licensees must adhere to relevant approved technical standards of the Payment System of which they are members (or that otherwise apply), and any other technical standards relevant for payment-transaction execution (including the Payment Card Industry – Data Security Standards as may be applicable and amended).

“As may be applicable” is not a blanket statement that every licensee is PCI Level 1. Confirm licence type, CHD flows, and acquirer/brand validation path.

Practical Dual-Market Path

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help merchants and service providers collect QSA-ready evidence across scoping, cloud, and SAQ/ROC validation paths.

Frequently Asked Questions

Is mada a separate standard from PCI?

Scheme and national rules can stack on PCI. Confirm current mada/acquirer documentation for your channel; do not assume a SAMA CSF mapping alone satisfies brand validation.

Does the CBUAE 72-hour notice replace brand notification?

No. Meet both regulator (where Article 18 applies to you as a Card Scheme) and brand/acquirer compromise timelines.

Are all SAMA Member Organizations required to be PCI Level 1?

No. Banks have 3.2.3 in scope; other FIs follow the §1.4 exception unless they handle CHD (or SWIFT). Payment licensees follow Article 35 as applicable, plus brand/acquirer rules.

Saudi merchants · GCC PCI · Pakistan · PCI vs ISO · Certification myth · Fines

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!