HomeFrameworksNational Cyber & Cloud SchemesSAMA CSF

Framework  National Cyber & Cloud Schemes

SAMA CSF

The SAMA Cyber Security Framework is the mandatory cybersecurity standard for institutions supervised by the Saudi Central Bank (still widely referred to as SAMA, the Saudi Arabian Monetary Authority). Version 1.0 was issued in May 2017 and applies to banks, insurance and reinsurance companies, financing companies, credit bureaus, and financial market infrastructure.

It is principle-based and organized into four domains (cyber security leadership and governance, risk management and compliance, operations and technology, and third-party cyber security) with 32 subdomains, each stating a principle, an objective, and control considerations.

Every member organization is measured on a six-level maturity model (0 non-existent to 5 adaptive) and must operate at level 3 (structured and formalized, with documented, approved, and implemented controls) or higher across the framework.

Compliance is assessed through a self-assessment questionnaire that SAMA reviews and audits, supplemented by SAMA on-site reviews and by independent assessments the regulator may require.

In writing, a member organization needs a board-approved cyber security strategy, policy, and governance charter with a dedicated cyber security function and committee, a risk management methodology and register, a compliance register mapping SAMA and other requirements, documented controls for each subdomain (identity and access, infrastructure, applications, cryptography, secure development, monitoring, incident management, business continuity), third-party contracts and assessments, awareness records, and the annual maturity self-assessment with evidence.

SAMA has issued additional frameworks (business continuity, IT governance) and the NCA's ECC also applies to the sector.

AI-compiled
Share
Sponsored
SAMA
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with SAMA CSF
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

All organizations regulated by the Saudi Central Bank: banks, insurance and reinsurance companies, financing companies, credit bureaus, and financial market infrastructure, plus, through contracts, their outsourcing providers and fintech partners. Compliance is a licensing condition.

What the assessor asks to see

Cyber security strategy, policy, and governance charter; committee minutes; roles and responsibilities; risk management methodology and risk register; compliance register; asset inventory and classification; identity and access management records; infrastructure and application security controls; cryptography standards; secure development lifecycle evidence; security monitoring and event management; vulnerability and penetration testing reports; incident management records and SAMA notifications; business continuity and disaster recovery tests; third-party due diligence and contracts; awareness and training records; internal audit reports; the completed maturity self-assessment with supporting evidence.

Maturity model

Six levels: 0 non-existent, 1 ad hoc, 2 repeatable but informal, 3 structured and formalized, 4 managed and measurable, 5 adaptive. Member organizations must reach level 3 or higher, and each higher level requires all criteria of the preceding levels to be met.

Assessors

Who assesses SAMA CSF

Self-assessment by the member organization reviewed and audited by SAMA supervisors; SAMA may direct independent assessments by external firms. No private certification exists. SAMA is the regulator.

No firm has claimed a SAMA CSF assessor listing yet. Claim yours →

Consultants

Who helps with SAMA CSF

Saudi and regional cybersecurity consultancies and the local arms of global audit and advisory firms offer SAMA CSF maturity assessments, gap remediation, and evidence preparation; GRC tools ship the control set. Engagements run six to eighteen months to reach level 3 across all subdomains.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a SAMA CSF consultant listing yet. Claim yours →

Software

Tools for SAMA CSF

Tools that name this framework in their own material.

Related reading

  1. Cybersecurity compliance handbook for the Kingdom of Saudi ArabiaMaps how the SAMA framework sits alongside the NCA controls for a bank that answers to both regulators.PwC Middle East

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for SAMA CSF

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with SAMA CSF

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.