Get Demo
↑

PCI DSS for Saudi Merchants — Aligning with SAMA & mada

This article maps PCI DSS v4.0.1, SAMA CSF, and mada rules for Saudi merchants, detailing overlapping controls, compliance roadmap, and automation.

📅 Published: June 2026 🔐 Compliance • PCI DSS ⏱️ 11–14 min read

For merchants operating in Saudi Arabia, PCI DSS compliance is not optional — it is a contractual condition of accepting card payments through the mada network and a mandatory alignment with the Saudi Central Bank’s (SAMA) cybersecurity expectations. The Payment Card Industry Data Security Standard (PCI DSS compliance) sets the global baseline for protecting cardholder data. Saudi Arabia adds two additional layers of regulatory control: SAMA’s Cybersecurity Framework (CSF) and the mada payment scheme rules. Together, these three frameworks define the compliance obligations for every Saudi merchant that processes, stores, or transmits cardholder data.

This article explains precisely how PCI DSS interacts with SAMA CSF and mada scheme requirements for Saudi merchants. You will find a direct mapping of overlapping controls, a practical compliance roadmap that satisfies all three frameworks simultaneously, and clear guidance for your annual validation cycle. Whether you are a Tier 1 payment gateway or a Tier 4 small business, understanding this tri-framework alignment is critical to maintaining your merchant agreement, avoiding fines, and protecting your customers’ payment data.

Strategic Insight: Saudi Arabia’s Vision 2030 digital economy goals and the rapid growth of fintech have elevated the importance of payment security compliance. SAMA now expects all regulated entities — including merchants — to demonstrate alignment with its CSF as part of their broader cybersecurity posture. PCI DSS v4.0.1 provides a ready-made control framework that satisfies many SAMA CSF domains. The key is knowing where the overlaps are and where gaps need separate attention.

The Regulatory Trifecta for Saudi Merchants

Three distinct regulatory and scheme-level documents govern card payment security for Saudi merchants. Understanding how they relate to each other is the first step toward a unified compliance program.

PCI DSS v4.0.1 — The Global Standard

PCI DSS is maintained by the Payment Card Industry Security Standards Council (PCI SSC). It applies to any entity that stores, processes, or transmits cardholder data. The standard contains 12 core requirements structured across six goals, from building and maintaining a secure network to regularly testing security systems. For Saudi merchants, the specific compliance level — and therefore the validation requirements — depends on annual transaction volume processed through each card brand, including mada.

SAMA CSF — The Local Regulatory Mandate

The Saudi Central Bank (SAMA) issued its Cybersecurity Framework to govern all entities under its regulatory supervision. While SAMA CSF primarily targets banks, insurance companies, and finance companies, it also applies to payment service providers and, by extension, to merchants processing payments through regulated channels. The framework is structured around five domains: Governance, Defense, Resilience, Third Party, and Awareness. PCI DSS compliance directly satisfies multiple controls within the Defense domain, covering network security, access control, encryption, and monitoring.

mada Scheme Rules — The Acceptance Layer

mada is the national payment scheme of Saudi Arabia, operated by the Saudi Payments network. All merchants accepting mada cards — which includes nearly all debit and credit cards issued in the Kingdom — must comply with mada’s operating regulations. These regulations incorporate PCI DSS by reference and add specific requirements around terminal security, transaction routing, and data localization. A failure to maintain PCI DSS compliance can result in mada deactivating your merchant ID, preventing you from accepting any mada transactions.

PCI DSS and SAMA CSF — Overlapping Controls

PCI DSS and SAMA CSF share a significant number of common security objectives. A properly implemented PCI DSS compliance program will naturally satisfy many SAMA CSF controls, reducing the overall compliance burden for merchants. The table below maps the most significant overlaps.

SAMA CSF Domain
SAMA Control Objective
PCI DSS Requirement
Overlap Rating
Defense — Network Security
DMZ architecture, firewall rules, network segmentation
Requirement 1 — Install and maintain firewall configurations
High
Defense — Access Control
Least privilege, user access reviews, multi-factor authentication
Requirement 7 — Restrict access by business need-to-know
High
Defense — Encryption
Encryption of data in transit and at rest
Requirement 4 — Encrypt cardholder data over open networks
High
Defense — Monitoring
Logging, SIEM, anomaly detection, incident response
Requirements 10 and 12 — Logging and incident response
Medium
Defense — Vulnerability Management
Patch management, vulnerability scanning, agentic penetration testing
Requirements 5 and 11 — Anti-malware and regular testing
High
Governance — Risk Management
Risk assessment methodology, risk register, risk treatment
Requirement 12 — Information security policy and risk assessment
Medium
Third Party — Vendor Management
Third-party risk assessment, service provider due diligence
Requirement 12 — Third-party service provider management
Medium

Compliance Warning: While PCI DSS covers many SAMA CSF controls within the Defense domain, it does not fully address the Governance, Resilience, and Awareness domains. Saudi merchants must implement separate controls for business continuity planning, security awareness training, board-level oversight, and cyber resilience testing to achieve full SAMA CSF alignment. Use PCI DSS as your operational security baseline, then layer on the strategic and resilience controls required by SAMA.

mada-Specific Requirements Beyond PCI DSS

In addition to PCI DSS compliance, mada imposes specific operational and technical requirements that all Saudi merchants must follow. These requirements sit on top of the PCI DSS baseline.

Terminal Security and P2PE

mada mandates the use of approved point-of-interaction (POI) terminals that comply with PCI PIN Security and PCI PTS (PIN Transaction Security) standards. Merchants using software-based POS solutions on mobile devices must ensure their solution is mada-certified and uses point-to-point encryption (P2PE) for card data. PCI DSS Requirement 4 specifically addresses encryption of cardholder data over open networks, and P2PE compliance can significantly reduce the scope of your PCI assessment.

Data Localization and Saudi Payments Routing

All mada transactions must be routed through Saudi Payments infrastructure within the Kingdom. This means transaction data, including cardholder data in transit, must remain within Saudi Arabia’s borders. While PCI DSS does not explicitly mandate geographic data residency, the combination of mada rules and Saudi Arabia’s Personal Data Protection Law (PDPL) creates a strong data localization requirement. Merchants using cloud-based payment gateways must verify that their processor maintains in-region processing capabilities.

Mandatory Notification and Incident Reporting

mada requires merchants to notify Saudi Payments immediately of any suspected or confirmed cardholder data breach. This notification timeline is typically shorter than the PCI DSS requirement and aligns with SAMA CSF’s incident response control objectives. Failure to notify can result in immediate suspension of mada acceptance privileges. Merchants must have an incident response plan that specifically addresses breach notification to both the card scheme and the regulator.

Step-by-Step Compliance Roadmap for Saudi Merchants

Building a unified compliance program that satisfies PCI DSS, SAMA CSF, and mada rules requires a structured approach. The following process outlines the key phases for a Saudi merchant.

1

Determine Your Compliance Level

Your PCI DSS compliance level is determined by your annual transaction volume across all card brands, including mada. Saudi merchants typically fall into one of four levels. Level 1 merchants — those processing over 6 million transactions annually — require an annual Report on Compliance (ROC) by a Qualified Security Assessor (QSA). Level 2 through 4 merchants may qualify for a Self-Assessment Questionnaire (SAQ), depending on their payment environment. Your mada merchant agreement will specify which level applies.

2

Define Your Cardholder Data Environment (CDE)

Scope reduction is the most effective way to simplify PCI DSS compliance. Identify every system, network segment, and personnel that touches cardholder data. Common scoping challenges for Saudi merchants include cloud-based POS systems, mobile payment applications, and customer service tools that store or transmit PAN data. By isolating your CDE with strict network segmentation, you can limit the scope of both your PCI DSS assessment and your SAMA CSF implementation. The Compliance Standards Automation platform helps merchants automate CDE mapping and scope documentation.

3

Implement PCI DSS Controls

Deploy the 12 PCI DSS requirements across your CDE, prioritizing the controls that also satisfy SAMA CSF defense objectives. Start with Requirement 1 (firewall configuration) and Requirement 7 (access control), as these create the foundation for network security. Use Requirement 4 (encryption) and Requirement 3 (data retention) to establish your data protection posture. For Saudi merchants, Requirement 12 (policy and risk management) is particularly important because it directly supports SAMA CSF governance expectations.

4

Map Controls to SAMA CSF

Create a control mapping matrix that documents how each PCI DSS requirement satisfies one or more SAMA CSF controls. This mapping becomes your shared compliance evidence library. Where PCI DSS does not fully cover a SAMA control — such as governance board reporting, awareness training, or business continuity testing — implement the additional controls separately. A unified GRC platform like CyberSilo Compliance Standards Automation can maintain this mapping dynamically across framework updates.

5

Validate and Certify

Complete your annual PCI DSS validation — either a ROC through a QSA or an SAQ depending on your level. Submit your Attestation of Compliance (AOC) to the card brands and to mada through your acquiring bank. Separately, demonstrate SAMA CSF alignment through your annual independent audit or self-assessment. Most Saudi merchants schedule these two validations within the same quarter to reduce audit fatigue and leverage shared evidence.

Comparison: PCI DSS v4.0.1 vs SAMA CSF v2

Both frameworks have recently undergone major revisions. PCI DSS v4.0.1 introduced more flexibility through defined and customized approaches while maintaining the same 12 requirements. SAMA CSF v2 updated its control catalogue to align with NIST CSF 2.0 2.0 and added new controls for AI governance and cloud security. The table below compares the structural differences that Saudi merchants need to understand.

Framework Aspect
PCI DSS v4.0.1
SAMA CSF v2
Structure
12 requirements, 6 goals
5 domains, 25 sub-domains, 187 controls
Validation Frequency
Annual ROC or SAQ
Annual independent audit or self-assessment
Approach Flexibility
Defined and customized approaches
Mandatory baseline with risk-based enhancements
Applicability
Any entity handling cardholder data
SAMA-regulated entities and payment service providers
Enforcement
Card brand fines, merchant ID suspension
SAMA regulatory action, fines, license revocation
Third-Party Focus
Service provider due diligence (Req 12)
Dedicated Third Party domain with 30+ controls

Common Compliance Challenges for Saudi Merchants

Based on our experience working with merchants across the Kingdom, several recurring challenges emerge during PCI DSS and SAMA alignment efforts.

Scope Creep from Cloud and Mobile Payments

The rapid adoption of cloud-based POS systems and mobile payment applications in Saudi Arabia has expanded the cardholder data environment for many merchants. Every cloud API integration, every mobile device that processes a payment, and every customer database that stores transaction logs expands your CDE and increases compliance complexity. Merchants must carefully architect these systems to minimize PCI scope — ideally by using tokenization or P2PE — or face a significantly larger assessment burden.

Third-Party Managed Payment Gateways

Many Saudi merchants rely on third-party payment gateway providers to process transactions. While this can reduce PCI DSS scope if the gateway is PCI DSS compliant and the merchant uses an iframe or URL redirect, it does not eliminate compliance obligations entirely. Merchants must still complete a SAQ, verify their provider’s compliance status annually, and maintain their own security policy documentation. The SAMA CSF third-party domain adds additional due diligence requirements beyond what PCI DSS demands, including contractual security clauses and on-site assessments for critical service providers.

Data Retention and PDPL Alignment

Saudi Arabia’s Personal Data Protection Law imposes strict rules on how long personal data — including cardholder data — can be retained. PCI DSS requires that stored cardholder data be limited to what is necessary for business purposes and defines maximum retention periods for specific data elements. Merchants must establish a data retention and disposal policy that satisfies both PCI DSS Requirement 3 and PDPL requirements, with clear procedures for secure deletion of expired cardholder data.

How Compliance Standards Automation Simplifies Alignment

Managing compliance across three separate frameworks manually is inefficient and error-prone. The CyberSilo Compliance Standards Automation platform is specifically designed to help Saudi merchants maintain a single source of truth for PCI DSS, SAMA CSF, and mada requirements. The platform automatically maps controls across frameworks, tracks evidence collection for each requirement, and generates consolidated reports for your QSA, SAMA auditor, and acquiring bank.

Key capabilities for Saudi merchants include:

Streamline Your PCI DSS and SAMA CSF Alignment

Managing multiple compliance frameworks doesn't have to mean duplicate work and missed controls. CyberSilo Compliance Standards Automation gives Saudi merchants a unified platform to manage PCI DSS, SAMA CSF, and mada requirements from a single dashboard — reducing assessment time, eliminating gaps, and keeping your merchant agreements active.

Frequently Asked Questions

Is PCI DSS mandatory for all merchants in Saudi Arabia?

Yes, PCI DSS compliance is mandatory for all merchants that accept card payments, including mada transactions. The requirement is enforced through your merchant agreement with your acquiring bank and through mada's operating regulations. Non-compliance can result in fines, increased transaction fees, or suspension of your ability to accept card payments.

Does PCI DSS compliance guarantee SAMA CSF compliance for Saudi merchants?

No. While PCI DSS covers a significant portion of the SAMA CSF Defense domain controls, it does not fully address the Governance, Resilience, or Awareness domains. Saudi merchants must implement additional controls for board-level security governance, business continuity planning, security awareness training, and third-party risk management to achieve full SAMA CSF alignment.

What is the difference between a ROC and an SAQ for Saudi merchants?

A Report on Compliance (ROC) is a detailed on-site assessment performed by a Qualified Security Assessor (QSA). It is required for Level 1 merchants processing over 6 million transactions annually. A Self-Assessment Questionnaire (SAQ) is a merchant-completed validation form for lower-volume merchants. The SAQ can be validated by an Internal Security Assessor (ISA) or submitted directly, depending on the acquiring bank's requirements.

Can I use a PCI DSS-compliant third-party payment gateway to reduce my scope?

Yes, using a PCI DSS-compliant third-party gateway with an iframe or URL redirect can significantly reduce your PCI DSS scope, potentially allowing you to complete a shorter SAQ. However, you remain responsible for verifying your provider's compliance annually, maintaining your own security policies, and ensuring your integration does not inadvertently expose cardholder data on your systems.

What are the data localization requirements for mada transactions?

All mada transactions must be processed and routed through Saudi Payments infrastructure within the Kingdom of Saudi Arabia. Merchants using cloud-based payment gateways must verify that their processor maintains in-region processing capabilities. This data localization requirement aligns with both mada operating rules and Saudi Arabia's Personal Data Protection Law (PDPL).

Our Conclusion & Recommendation

For Saudi merchants, PCI DSS compliance is the operational backbone of your payment security program. It satisfies the majority of mada scheme requirements and a substantial portion of SAMA CSF controls within the Defense domain. However, treating PCI DSS as a checkbox exercise rather than a foundational security program creates real risk. A breach of cardholder data not only triggers PCI DSS fines and potential merchant ID suspension but also exposes you to SAMA regulatory action and reputational damage in a rapidly digitizing economy.

The most efficient path forward for Saudi merchants is a unified compliance program that maps PCI DSS controls to SAMA CSF and mada requirements from the start. Automation is no longer optional — the complexity of managing three frameworks manually, especially as each undergoes periodic updates, creates compliance gaps that are difficult to detect until an audit or breach reveals them. CyberSilo Compliance Standards Automation provides the control mapping, evidence management, and gap analysis capabilities that enterprises in the Kingdom need to maintain continuous alignment across all three frameworks. For CISO and compliance officers managing merchant payment security, this unified approach reduces workload, improves audit outcomes, and protects your ability to serve customers in the Saudi market.

Ready to Simplify Your Merchant Compliance?

Our team works with Saudi merchants to design unified compliance programs that satisfy PCI DSS, SAMA CSF, and mada requirements. Whether you are preparing for your first ROC or looking to optimize an existing program, we can help.