All services

SAMA Cybersecurity Framework

Achieve and maintain SAMA CSF compliance: maturity assessment, control implementation, and continuous monitoring.

Understanding SAMA CSF

The Saudi Central Bank's Cybersecurity Framework (SAMA CSF) establishes mandatory cybersecurity requirements for all financial institutions operating in Saudi Arabia. It defines 4 core domains with maturity-based assessment, requiring institutions to demonstrate not just that controls exist but that they are effective, measured, and continuously improved.

For financial institutions also subject to NCA ECC requirements, we deliver a unified compliance programme that maps overlapping controls, eliminating duplicate effort and reducing total compliance cost.

4 SAMA CSF domains

Cybersecurity Leadership & Governance

Cybersecurity policy & strategy, roles & responsibilities, awareness, compliance & audit.

Cybersecurity Risk Management & Compliance

Risk assessment methodology, treatment plans, regulatory mapping, third-party risk assessment.

Cybersecurity Operations & Technology

Identity & access management, network & endpoint security, application security, SIEM monitoring.

Third-Party Cybersecurity

Vendor risk management, outsourcing controls, cloud service governance, SLA monitoring.

SAMA maturity model

SAMA evaluates compliance on a 5-level scale. Most institutions target Level 3–4.

Level 1, Initial

Ad-hoc processes, no formal cybersecurity programme.

Level 2, Managed

Policies exist but inconsistently applied. Some controls in place.

Level 3, Defined

Standardised processes and controls. Organisation-wide security programme.

Level 4, Quantitatively Managed

Metrics-driven. Controls measured and continuously improved.

Level 5, Optimising

Proactive threat hunting, automated response, industry-leading maturity.

SAMA CSF + NCA ECC: unified compliance

Financial institutions must comply with both SAMA CSF and NCA ECC. Rather than treating them as separate projects, our unified framework maps overlapping controls (typically 40–60%) to a single set of policies, processes, and evidence.

  • Reduces compliance effort by up to 40%
  • Eliminates duplicate documentation
  • Provides a single control framework for ongoing monitoring
  • Simplifies board and audit reporting

Assess your SAMA readiness

Run a free SAMA self-assessment or speak to our compliance experts.

Related services

NCA ECC Compliance

National cybersecurity controls for Saudi organisations.

Explore

ISO 27001 Certification

International ISMS certification.

Explore

Cybersecurity Audit

Comprehensive audit and penetration testing.

Explore

SAMA CSF Compliance FAQ

Find answers to common questions about our services