About this Framework
The SAMA Cyber Security Framework (CSF) is mandatory for all financial institutions under SAMA supervision — banks, insurance companies and payment service providers in Saudi Arabia. It follows a maturity-based approach across four core domains, requiring self-assessments, annual penetration testing and SAMA compliance reporting. The framework aligns with ISO 27001, NIST CSF and PCI DSS.
Key Control Domains
Cyber Security Leadership & Governance
Cyber Security Risk Management & Compliance
Cyber Security Operations & Technology
Third-Party Cybersecurity
Who Needs This?
- Banks and financial institutions regulated by SAMA
- Saudi insurance and reinsurance companies
- Payment service providers in Saudi Arabia
- Financing and leasing companies under SAMA
Compliance Benefits
- SAMA regulatory compliance (legally mandatory)
- Structured risk management for financial services
- Alignment with international cybersecurity standards
- Board-level security accountability required by law
Official Reference
Saudi Central Bank (SAMA)
https://www.sama.gov.sa
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/saudi-central-bank-cyber-security-framework-sama-csf