شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

SAMA CSF

SAMA Cyber Security Framework (CSF)

The Cyber Security Framework (SAMA CSF) sets the cybersecurity controls and the maturity level the Saudi Central Bank expects of the financial institutions it regulates. This guide is for CISOs and compliance teams in banks, finance companies and payment firms.

Last updated: 3 October 2026

What the SAMA CSF is

The Cyber Security Framework (CSF) is the common cybersecurity baseline the Saudi Central Bank (SAMA) set for the financial institutions it regulates, which the framework calls Member Organisations. SAMA issued version 1.0 in May 2017 by circular 381000091275 dated 28/8/1438H, and the SAMA Rulebook lists it as in force.

The framework has three stated objectives: a common approach to cybersecurity across Member Organisations, an appropriate maturity level for cybersecurity controls, and proper management of cyber risk throughout the organisation. SAMA uses it to assess maturity periodically and to compare organisations with one another.

Principle-based, not a checklist

The CSF is principle-based, also described as risk-based. Each subdomain sets a principle, an objective and mandated control considerations. Where a control consideration cannot be tailored or implemented, the organisation should consider compensating controls, pursue internal risk acceptance and request a formal waiver from SAMA.

What it covers

The controls apply to the organisation's information assets: electronic and physical information, applications and databases, computers and machines such as ATMs, storage devices, and premises, equipment and networks. The framework gives direction to the organisation, its subsidiaries, staff, third parties and customers. Business continuity requirements are covered separately by SAMA.

Who it applies to

The framework text lists the Member Organisations it applies to:

  • All banks operating in Saudi Arabia.
  • All insurance and/or reinsurance companies operating in Saudi Arabia.
  • All financing companies operating in Saudi Arabia.
  • All credit bureaus operating in Saudi Arabia.
  • The financial market infrastructure.

The SAMA Rulebook now lists the framework as applying to the banking sector, the finance sector, payment systems and payment service providers, credit bureaus and the regulatory sandbox. Fintechs licensed or permitted by SAMA in these categories should therefore expect the CSF to apply to them.

Banks and other institutions

All domains apply to the banking sector. For other financial institutions the framework makes exceptions:

  • Subdomain 3.1.2: alignment with the banking sector's cybersecurity strategy is mandatory where applicable.
  • Subdomain 3.2.3 is excluded, but organisations that store, process or transmit cardholder data or deal with SWIFT services should implement PCI DSS and/or the SWIFT Customer Security Controls Framework.
  • Subdomain 3.3.12, payment systems, is excluded.
  • Subdomain 3.3.13, electronic banking services, is excluded, but organisations that provide online services to customers should implement multi-factor authentication.

Insurers

Regulating and supervising the insurance sector is now the remit of the Insurance Authority, so insurers should confirm their current cybersecurity requirements with that authority.

Structure: four main domains

The framework is built around four main domains, each divided into subdomains that focus on a single topic.

3.1 Cyber security leadership and governance (7 subdomains)

Governance, strategy, policy, roles and responsibilities, cybersecurity in project management, awareness, and training.

3.2 Cyber security risk management and compliance (5 subdomains)

Risk management, regulatory compliance, compliance with (inter)national industry standards such as PCI DSS, EMV and the SWIFT Customer Security Controls Framework, cybersecurity review, and cybersecurity audits.

3.3 Cyber security operations and technology (17 subdomains)

Human resources, physical security, asset management, cybersecurity architecture, identity and access management, application security, change management, infrastructure security, cryptography, bring your own device (BYOD), secure disposal of information assets, payment systems, electronic banking services, cybersecurity event management, incident management, threat management, and vulnerability management.

3.4 Third party cyber security (3 subdomains)

Contract and vendor management, outsourcing, and cloud computing.

Each subdomain follows the same pattern: a principle that summarises the required controls, an objective that explains their purpose, and numbered control considerations that can go up to four levels deep. Use that numbering when you document evidence, so each piece of evidence maps to the consideration it proves.

The maturity model and the level 3 minimum

SAMA measures cybersecurity maturity with a predefined model of six levels. To reach level 3, 4 or 5, an organisation must first meet all the criteria of the levels below it.

  • Level 0, non-existent: no documentation and no awareness; controls are not in place.
  • Level 1, ad hoc: controls are not or only partially defined and are performed inconsistently.
  • Level 2, repeatable but informal: execution follows a standardised but unwritten practice.
  • Level 3, structured and formalised: controls are defined, approved and implemented in a structured, formal way, and implementation can be demonstrated.
  • Level 4, managed and measurable: the effectiveness of controls is periodically measured, evaluated and improved where necessary.
  • Level 5, adaptive: controls are subject to continuous improvement and integrated with enterprise risk management.

The minimum is level 3

To achieve an appropriate maturity level, SAMA expects Member Organisations to operate at maturity level 3 or higher. At level 3, cybersecurity policies, standards and procedures are established; compliance with them is monitored, preferably with a governance, risk and compliance (GRC) tool; and key performance indicators are defined, monitored and reported. Level 4 adds key risk indicators and trend reporting to judge effectiveness.

Self-assessment and SAMA review

Implementation is subject to a periodic self-assessment, performed by the organisation on the basis of a questionnaire. SAMA then reviews and audits these self-assessments to determine the level of compliance and the maturity level.

Key obligations buyers ask about

Beyond the maturity target, certain control considerations come up in almost every SAMA CSF programme.

Governance

  • A cybersecurity committee mandated by the board, headed by an independent senior manager from a control function, with a charter and meetings at least quarterly.
  • A cybersecurity function independent of IT, with separate reporting lines, budgets and staff evaluations, reporting to the CEO or managing director or to the general manager of a control function.
  • A full-time chief information security officer (CISO) at senior management level who has Saudi nationality, is sufficiently qualified and has SAMA's no objection to the appointment.
  • A budget allocated by the board that is sufficient for the required cybersecurity activities.

Operations

  • Annual review and penetration testing of customer and internet-facing services.
  • A security event management process with a designated monitoring team (a security operations centre), resources for continuous 24x7 monitoring, centralised analysis and correlation of logs (SIEM), and independent periodic testing of the SOC's effectiveness, for example through red-teaming.

Third parties and cloud

  • A contract that includes cybersecurity requirements before cloud services are used.
  • SAMA approval before using cloud services; in principle, only cloud services located in Saudi Arabia, or explicit SAMA approval for cloud services outside it.

SAMA issues further circulars and frameworks on related topics, so read the CSF together with its current instructions in the Rulebook.

How to reach and hold level 3

Organisations that reach and hold level 3 usually work in this order:

  • Confirm scope: the domains and subdomains that apply to your type of institution, including the exceptions for non-banks, and the other SAMA instructions that sit alongside the CSF.
  • Baseline your maturity: score each applicable control consideration against the maturity model with evidence, not impressions.
  • Fix governance first: the committee, the independent function, a Saudi CISO with SAMA's no objection, and an approved policy, standards and procedures. Level 3 cannot be demonstrated without documentation.
  • Close operational gaps by risk: identity and access management, vulnerability management, event and incident management, and third-party controls.
  • Measure: key performance indicators that show implementation for level 3, then key risk indicators and trend reporting if you aim for level 4.
  • Keep evidence current: maturity is reassessed periodically, and evidence assembled once before a review goes stale.

Mistakes to avoid

  • Treating level 3 as a documentation exercise: it also requires demonstrable implementation and monitored compliance.
  • Scoring generously in the self-assessment: SAMA reviews and audits the results.
  • Using cloud services without the approvals the third-party domain requires.

Effort depends on your starting maturity, the size of your technology estate and the number of suppliers you rely on, so plan in phases.

How DataSec helps

DataSec helps financial institutions reach level 3 and hold it:

  • Compliance assessment: maturity scoring of every applicable control consideration against SAMA's model, with the gaps to your target level.
  • GRC advisory: the committee charter, cybersecurity policy, standards and procedures, risk methodology and the key performance indicators level 3 asks for.
  • Third-party risk and GRC platform: supplier and outsourcing assessments for the third-party domain, with evidence kept in one register.
  • Penetration testing: the annual testing of customer and internet-facing services.
  • Managed SOC: security event monitoring and incident handling from Riyadh.

Licence scope

DataSec holds the NCA Managed Security Operations Center (MSOC) Services Licence, Tier 2, which covers managed SOC services for any organisation other than government entities and organisations that own, operate or host critical national infrastructure. If your institution falls into either category, we support you with assessment, advisory, testing and solutions instead.

Your obligations under the Personal Data Protection Law are independent of the CSF, and one compliance assessment can cover both. If you are also within the scope of the NCA Essential Cybersecurity Controls, collect evidence once for every requirement.

How DataSec helps

Managed SOC services are provided within the scope of our Tier 2 licence, that is, to organisations other than government entities and those that own, operate or host critical national infrastructure.

  • Compliance assessment

    Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.

  • GRC advisory

    Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.

  • Third-party risk & GRC platform

    Vendor assessment and compliance management on a single platform.

  • Penetration testing

    Application, network and infrastructure testing with recognised methodologies and an actionable report.

  • Managed SOC

    24/7 monitoring, analysis and response under an NCA licence.

Frequently asked questions

Is SAMA CSF mandatory for fintechs and insurers?

The SAMA Rulebook lists the framework as applying to the banking sector, the finance sector, payment systems and payment service providers, credit bureaus and the regulatory sandbox, so a fintech licensed or permitted by SAMA in these categories should expect it to apply. The 2017 framework text also lists insurance and reinsurance companies, but the insurance sector is now regulated by the Insurance Authority, so insurers should confirm their current requirements with it.

What are the SAMA CSF maturity levels?

Six levels from 0 to 5: non-existent, ad hoc, repeatable but informal, structured and formalised, managed and measurable, and adaptive. To reach level 3 or above, an organisation must first meet all the criteria of the levels below it.

What maturity level does SAMA expect?

Level 3, structured and formalised, as a minimum. At that level controls are defined, approved and implemented in a structured way that can be demonstrated, compliance with policies, standards and procedures is monitored, and key performance indicators are defined and reported.

Which version of the SAMA CSF is current?

Version 1.0, issued by SAMA circular 381000091275 dated 28/8/1438H (24 May 2017), which the SAMA Rulebook lists as in force. SAMA reviews the framework periodically, so check the current text in the Rulebook before an assessment.

How is SAMA CSF compliance assessed?

The organisation carries out a periodic self-assessment based on a questionnaire. SAMA then reviews and audits these self-assessments to determine the level of compliance with the framework and the maturity level, so keep evidence behind every rating.

Can we get a waiver from a control?

The framework is principle-based. If a control consideration cannot be tailored or implemented, the organisation should consider compensating controls, pursue internal risk acceptance and request a formal waiver from SAMA through the process set out in the framework.

Does the CISO have to be Saudi?

Yes. The governance subdomain expects a full-time CISO at senior management level who has Saudi nationality, is sufficiently qualified and whose appointment has SAMA's no objection.

Does SAMA CSF compliance cover the PDPL?

No. The Personal Data Protection Law is a separate law supervised by SDAIA, with its own obligations such as breach notification and data subject rights. Evidence can be collected once, but assess compliance against each requirement separately.

Official sources

This guide is general information, not legal advice, and regulators update their requirements; always refer to the version currently published by the regulator.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.