SAMA Cybersecurity Framework
Achieve and maintain SAMA CSF compliance: maturity assessment, control implementation, and continuous monitoring.
Understanding SAMA CSF
The Saudi Central Bank's Cybersecurity Framework (SAMA CSF) establishes mandatory cybersecurity requirements for all financial institutions operating in Saudi Arabia. It defines 4 core domains with maturity-based assessment, requiring institutions to demonstrate not just that controls exist but that they are effective, measured, and continuously improved.
For financial institutions also subject to NCA ECC requirements, we deliver a unified compliance programme that maps overlapping controls, eliminating duplicate effort and reducing total compliance cost.
4 SAMA CSF domains
Cybersecurity Leadership & Governance
Cybersecurity policy & strategy, roles & responsibilities, awareness, compliance & audit.
Cybersecurity Risk Management & Compliance
Risk assessment methodology, treatment plans, regulatory mapping, third-party risk assessment.
Cybersecurity Operations & Technology
Identity & access management, network & endpoint security, application security, SIEM monitoring.
Third-Party Cybersecurity
Vendor risk management, outsourcing controls, cloud service governance, SLA monitoring.
SAMA maturity model
SAMA evaluates compliance on a 5-level scale. Most institutions target Level 3–4.
Level 1, Initial
Ad-hoc processes, no formal cybersecurity programme.
Level 2, Managed
Policies exist but inconsistently applied. Some controls in place.
Level 3, Defined
Standardised processes and controls. Organisation-wide security programme.
Level 4, Quantitatively Managed
Metrics-driven. Controls measured and continuously improved.
Level 5, Optimising
Proactive threat hunting, automated response, industry-leading maturity.
SAMA CSF + NCA ECC: unified compliance
Financial institutions must comply with both SAMA CSF and NCA ECC. Rather than treating them as separate projects, our unified framework maps overlapping controls (typically 40–60%) to a single set of policies, processes, and evidence.
- Reduces compliance effort by up to 40%
- Eliminates duplicate documentation
- Provides a single control framework for ongoing monitoring
- Simplifies board and audit reporting
Assess your SAMA readiness
Run a free SAMA self-assessment or speak to our compliance experts.
SAMA CSF Compliance FAQ
Find answers to common questions about our services