Framework National Cyber & Cloud Schemes
SAMA CSF
The SAMA Cyber Security Framework is the mandatory cybersecurity standard for institutions supervised by the Saudi Central Bank (still widely referred to as SAMA, the Saudi Arabian Monetary Authority). Version 1.0 was issued in May 2017 and applies to banks, insurance and reinsurance companies, financing companies, credit bureaus, and financial market infrastructure.
It is principle-based and organized into four domains (cyber security leadership and governance, risk management and compliance, operations and technology, and third-party cyber security) with 32 subdomains, each stating a principle, an objective, and control considerations.
Every member organization is measured on a six-level maturity model (0 non-existent to 5 adaptive) and must operate at level 3 (structured and formalized, with documented, approved, and implemented controls) or higher across the framework.
Compliance is assessed through a self-assessment questionnaire that SAMA reviews and audits, supplemented by SAMA on-site reviews and by independent assessments the regulator may require.
In writing, a member organization needs a board-approved cyber security strategy, policy, and governance charter with a dedicated cyber security function and committee, a risk management methodology and register, a compliance register mapping SAMA and other requirements, documented controls for each subdomain (identity and access, infrastructure, applications, cryptography, secure development, monitoring, incident management, business continuity), third-party contracts and assessments, awareness records, and the annual maturity self-assessment with evidence.
SAMA has issued additional frameworks (business continuity, IT governance) and the NCA's ECC also applies to the sector.
help
Who has to comply
All organizations regulated by the Saudi Central Bank: banks, insurance and reinsurance companies, financing companies, credit bureaus, and financial market infrastructure, plus, through contracts, their outsourcing providers and fintech partners. Compliance is a licensing condition.
What the assessor asks to see
Cyber security strategy, policy, and governance charter; committee minutes; roles and responsibilities; risk management methodology and risk register; compliance register; asset inventory and classification; identity and access management records; infrastructure and application security controls; cryptography standards; secure development lifecycle evidence; security monitoring and event management; vulnerability and penetration testing reports; incident management records and SAMA notifications; business continuity and disaster recovery tests; third-party due diligence and contracts; awareness and training records; internal audit reports; the completed maturity self-assessment with supporting evidence.
Maturity model
Six levels: 0 non-existent, 1 ad hoc, 2 repeatable but informal, 3 structured and formalized, 4 managed and measurable, 5 adaptive. Member organizations must reach level 3 or higher, and each higher level requires all criteria of the preceding levels to be met.
Assessors
Who assesses SAMA CSF
Self-assessment by the member organization reviewed and audited by SAMA supervisors; SAMA may direct independent assessments by external firms. No private certification exists. SAMA is the regulator.
No firm has claimed a SAMA CSF assessor listing yet. Claim yours →
Consultants
Who helps with SAMA CSF
Saudi and regional cybersecurity consultancies and the local arms of global audit and advisory firms offer SAMA CSF maturity assessments, gap remediation, and evidence preparation; GRC tools ship the control set. Engagements run six to eighteen months to reach level 3 across all subdomains.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a SAMA CSF consultant listing yet. Claim yours →
Software
Tools for SAMA CSF
Tools that name this framework in their own material.
Related reading
- Cybersecurity compliance handbook for the Kingdom of Saudi ArabiaMaps how the SAMA framework sits alongside the NCA controls for a bank that answers to both regulators.PwC Middle East
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for SAMA CSF
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with SAMA CSF
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.