GRCCopilot
Sign In
Saudi Central Bank (SAMA)

Saudi Central Bank Cyber Security Framework (SAMA CSF)

Mandatory cybersecurity framework for all financial institutions supervised by the Saudi Central Bank

Start Assessment Create Free Account
0
Controls
0
Questions
Active
Status

About this Framework

The SAMA Cyber Security Framework (CSF) is mandatory for all financial institutions under SAMA supervision — banks, insurance companies and payment service providers in Saudi Arabia. It follows a maturity-based approach across four core domains, requiring self-assessments, annual penetration testing and SAMA compliance reporting. The framework aligns with ISO 27001, NIST CSF and PCI DSS.

Key Control Domains

Cyber Security Leadership & Governance
Cyber Security Risk Management & Compliance
Cyber Security Operations & Technology
Third-Party Cybersecurity

Who Needs This?

  • Banks and financial institutions regulated by SAMA
  • Saudi insurance and reinsurance companies
  • Payment service providers in Saudi Arabia
  • Financing and leasing companies under SAMA

Compliance Benefits

  • SAMA regulatory compliance (legally mandatory)
  • Structured risk management for financial services
  • Alignment with international cybersecurity standards
  • Board-level security accountability required by law

Official Reference

Saudi Central Bank (SAMA)
https://www.sama.gov.sa

Assessment Details

Issuer / AuthoritySaudi Central Bank (SAMA)
FrameworkSaudi Central Bank Cyber Security Framework (SAMA CSF)
Controls0
Questions0
StatusActive
Assessment Start08 May 2026

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/saudi-central-bank-cyber-security-framework-sama-csf

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.