Riyadh | +966‑557400202 | hello@nazztec.com
Compliance & Regulation

SAMA Cyber Security Framework: What Regulated Entities Must Evidence

The four domains, the six-level maturity model and why “level 3” is about formalisation, not technology — with a practical view of the evidence reviewers expect.

15 September 20268 min readNAZZTEC Editorial Team
SAMA Cyber Security Framework: What Regulated Entities Must Evidence — cover illustration

Key takeaways

  • The SAMA CSF applies to organisations regulated by the Saudi Central Bank.
  • It is organised into four domains and assessed on a maturity scale from 0 to 5.
  • Member organisations are expected to reach at least maturity level 3.
  • Level 3 means structured, formalised, approved and implemented — and provable.

Who the framework applies to

The SAMA Cyber Security Framework was issued by the Saudi Central Bank (SAMA) to strengthen cyber resilience across the financial sector. It applies to SAMA-regulated member organisations, including banks, insurance and reinsurance companies, finance companies, credit bureaus and financial market infrastructure.

The framework is principle-based. It sets out what must be achieved and how maturity will be judged, and leaves organisations to decide how to implement controls appropriate to their size and risk.

The four domains

  • Cyber Security Leadership and Governance — strategy, the cybersecurity function, committee, policy, roles, and cybersecurity within project management and human resources.
  • Cyber Security Risk Management and Compliance — risk management processes, regulatory compliance, compliance with international standards, and cybersecurity review and audit.
  • Cyber Security Operations and Technology — asset management, architecture, identity and access, application, change and infrastructure security, cryptography, BYOD, secure disposal, payment systems, e-banking, event management, incident management, threat management and vulnerability management.
  • Third Party Cyber Security — contract and vendor management, outsourcing and cloud computing.

The maturity model

LevelNameWhat it means in practice
0Non-existentNo documented or implemented control
1Ad-hocSome activity exists, but it is informal and inconsistent
2Repeatable but informalActivity is repeated, but not formally documented or approved
3Structured and formalisedDocumented, approved and implemented consistently
4Managed and measurablePerformance is measured, reviewed and improved
5AdaptiveContinuously improved and adapted to a changing threat landscape

Member organisations are expected to achieve at least level 3 across the framework. Higher levels are appropriate where risk, size or criticality demand it.

What “level 3” really requires

Level 3 is often misunderstood as a technology target. It is a formalisation target. For each control area, reviewers look for four things:

  • A documented policy, standard or procedure
  • Formal approval by the appropriate authority
  • Consistent implementation across the organisation
  • Evidence that it is operating — records, logs, tickets, reports

A control that works well but is undocumented is level 2. A beautifully documented control that is not implemented is also not level 3. Both halves are required.

Building an evidence pack that stands up to review

  • Map every requirement to an owner and a set of evidence items.
  • Keep evidence current — undated screenshots and year-old reports undermine credibility.
  • Show the governance trail: committee minutes, approvals and decisions.
  • Demonstrate follow-through on audit and assessment findings.
  • Maintain a clear record of third-party risk assessments and contractual security clauses.
  • Align the pack with related SAMA requirements, such as business continuity and IT governance, to avoid duplicated effort.

Where organisations usually fall short

  • Maturity self-assessments that are optimistic compared with the evidence.
  • Strong technology controls with weak governance and documentation.
  • Cybersecurity considered late in projects rather than built in.
  • Incomplete oversight of cloud and outsourcing arrangements.
  • Metrics collected but never used to drive improvement — which blocks progress beyond level 3.

Working with overlapping obligations

SAMA-regulated organisations often also answer to the NCA, PDPL, PCI DSS and international standards. Designing one control framework mapped to all of them allows a single test to satisfy several requirements, and gives leadership one coherent view of cyber risk instead of several competing ones.

Moving beyond level 3

Level 3 is the expected minimum, not the finish line. Moving to level 4 — managed and measurable — means controls are measured, reviewed and improved on the basis of evidence. In practice that requires key performance and risk indicators for important control areas, regular reporting to the cybersecurity committee, and documented decisions taken as a result.

For larger or more critical institutions, reaching level 4 in areas such as identity and access management, vulnerability management, event monitoring and third-party security gives leadership a measurable view of risk and demonstrates to SAMA that the programme is actively managed rather than periodically documented.

A practical cycle for sustaining maturity

  • Perform an evidence-based maturity self-assessment at least annually.
  • Agree target maturity levels by domain with the cybersecurity committee.
  • Track remediation actions with owners and dates, and report progress quarterly.
  • Update policies and procedures when business, technology or regulation changes.
  • Commission independent review periodically to validate self-assessment results.

Frequently asked questions

What maturity level does SAMA expect?
Member organisations are expected to reach at least maturity level 3 — structured and formalised — across the framework.
How is maturity assessed?
Through self-assessment and independent review, based on documented evidence that controls are defined, approved, implemented and operating.
Does the SAMA CSF replace the NCA ECC?
No. They are separate requirements from different authorities. Many financial institutions must address both, which is why a single mapped control framework is valuable.
Keep reading

More insights

PDPL Compliance Checklist for Saudi Organisations — cover illustration
Compliance & Regulation

PDPL Compliance Checklist for Saudi Organisations

The Personal Data Protection Law has been fully enforceable since September 2024. A practical checklist of what controllers must have in place — and evidence.

8 September 20269 min read

Talk to the team behind this briefing

Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.

We respond to every enquiry within one business day.