The SAMA Cyber Security Framework (CSF) is the mandatory cybersecurity standard for financial institutions regulated by the Saudi Central Bank. It defines the controls member organisations must implement and, critically, the maturity level they must reach - compliance is not simply pass or fail.
Who must comply with SAMA CSF?
The framework applies to organisations regulated by the Saudi Central Bank, including:
- Banks operating in the Kingdom
- Insurance and reinsurance companies
- Financing companies
- Credit bureaus
- Financial market infrastructure providers
The four main domains
- Cyber Security Leadership and Governance - strategy, governance structure, roles, risk management, regulatory compliance, awareness and training.
- Cyber Security Risk Management and Compliance - risk methodology, regulatory obligations, and compliance with the framework itself.
- Cyber Security Operations and Technology - human resources security, physical security, asset management, identity and access, application and infrastructure security, cryptography, backup, vulnerability and patch management, and incident response.
- Third Party Cyber Security - contracted services, outsourcing, and cloud computing risk.
The maturity model - the part most organisations underestimate
SAMA CSF assesses each control against a six-level maturity scale, and being assessed as "implemented" is not the goal on its own:
- Level 0 - Non-existent: no documentation, no activity.
- Level 1 - Ad-hoc: activities are unstructured and inconsistent.
- Level 2 - Repeatable but informal: practices exist but are not formalised.
- Level 3 - Structured and formalised: controls are defined, approved and implemented.
- Level 4 - Managed and measurable: effectiveness is measured and reported through KPIs.
- Level 5 - Adaptive: controls improve continuously against the evolving threat landscape.
Member organisations are generally expected to reach maturity level 3 as a minimum, with higher levels expected for critical controls. Reaching level 4 requires something many programmes lack: measurement. If you cannot show metrics and periodic reporting for a control, you will not be scored above level 3.
Measure your SAMA CSF maturity, control by control
GRC Copilot scores every SAMA CSF control against the maturity model, highlights where evidence is missing, and produces the reporting regulators expect.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
How to approach a SAMA CSF programme
- Confirm scope across all regulated entities and shared services.
- Run a maturity assessment - score each control 0 to 5 honestly, with evidence.
- Prioritise the gap between your current and target maturity, starting with critical controls.
- Formalise and approve policies to move from level 2 to level 3.
- Add metrics, KPIs and periodic reporting to move from level 3 to level 4.
- Report to the board and to SAMA as required, and reassess periodically.
SAMA CSF overlaps substantially with ISO/IEC 27001, NIST and the NCA ECC. Evidence collected for one framework can usually be reused for another - map once, report many times.
Frequently asked questions
What maturity level does SAMA require?
Level 3 (structured and formalised) is the general baseline expectation, with higher maturity expected for controls protecting critical services. Confirm current expectations against the latest SAMA circulars for your institution type.
How is SAMA CSF different from NCA ECC?
SAMA CSF is issued by the Saudi Central Bank for the financial sector and is maturity-scored. The NCA ECC is issued by the National Cybersecurity Authority as a national baseline across sectors. Many financial institutions are subject to both.
How often must we reassess?
Periodic self-assessment and reporting is expected, and SAMA may request results on its own cycle. Treat it as continuous rather than annual.
Does ISO 27001 certification satisfy SAMA CSF?
No, but it helps considerably. An ISO 27001 ISMS provides much of the governance and evidence SAMA looks for, yet SAMA CSF has its own control set and maturity scoring that must be addressed directly.
Key takeaways
- SAMA CSF is mandatory for Saudi Central Bank regulated entities.
- It is scored on a 0 to 5 maturity model, not simply implemented or not.
- Level 3 is the usual minimum; measurement is what unlocks level 4.
- Third-party and cloud risk is a full domain in its own right.