The SAMA Cyber Security Framework (CSF) is the mandatory cybersecurity framework issued by the Saudi Central Bank (SAMA) in 2017. It sets the security baseline for every institution SAMA regulates, drawing on international standards — ISO 27001, NIST CSF, PCI-DSS — adapted to the Saudi financial sector.
Who it applies to
All SAMA-regulated entities: commercial and investment banks, insurers, financing companies, credit bureaus, payment service providers, fintechs, and financial-market infrastructure. Even unlicensed technology firms can fall in scope if they process financial data or provide infrastructure to a regulated entity.
Measured on maturity, not presence
The framework spans four domains — leadership & governance, risk management & compliance, operations & technology, and third-party cybersecurity. Each control is scored on a maturity scale, and an institution must reach at least Level 3 (Defined) across all domains to be considered compliant, evidenced through an annual self-assessment to SAMA.
A written policy scores nothing; a policy that is implemented, measured and evidenced scores Level 3.
Where institutions fail
Third-party risk is the recurring weak point — a large share of financial-sector breaches trace back to a vendor. The framework makes you accountable for supplier security, so vendor contracts, audit rights and ongoing monitoring have to be real, not paper.
Run a gap analysis against this framework.
The compliance builder walks each requirement, tracks your evidence, and produces a gap report — part of GRC Forge Pro. Join now to be first in when it launches.
Get started