SAMA Cyber Security Framework: Core Expectations

The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework remains the primary regulatory standard for financial institutions, payment system operators, and entities classified as critical information infrastructure under Saudi Arabia's National Cybersecurity Authority (NCA) guidance. The framework aligns with NIST Cybersecurity Framework 2.0 principles and ISO/IEC 27001:2022 controls, creating a unified expectation across governance, risk management, and technical implementation.

SAMA's framework mandates six core pillars: governance and risk management, asset management, access control and identity management, security operations and monitoring, resilience and business continuity, and third-party and supply chain risk management. Each pillar carries specific control objectives that institutions must evidence through documentation, testing, and audit trails.

Governance and Risk Management Evidence

Security leaders must establish a documented cybersecurity strategy approved by the board or senior management committee. This strategy should articulate risk appetite, define roles and responsibilities, and map to the organization's business objectives. Evidence includes:

  • Board-approved cybersecurity policy and annual risk assessment reports
  • Documented risk register identifying threats specific to your operating environment
  • Incident response plan tested at least annually with documented results
  • Business continuity and disaster recovery plans with recovery time objectives (RTO) and recovery point objectives (RPO) aligned to critical business functions

SAMA expects institutions to maintain a Chief Information Security Officer (CISO) or equivalent role with direct reporting line to executive leadership. This individual must have documented authority to enforce security policies across the organization and sufficient budget allocation for control implementation.

Technical Controls and Monitoring

Asset management and access control require a complete inventory of hardware, software, and data assets classified by sensitivity. SAMA expects:

  • Multi-factor authentication (MFA) for all administrative and privileged access
  • Encryption of sensitive data in transit and at rest, using current cryptographic standards (AES-256 or equivalent)
  • Network segmentation isolating critical systems and payment infrastructure
  • Security monitoring via a Security Operations Center (SOC) or managed security service provider with 24/7 capability
  • Vulnerability scanning and penetration testing conducted at least annually by independent third parties

Evidence of these controls is demonstrated through system configuration baselines, access control matrices, encryption inventory, and SOC alert logs with documented response times. SAMA auditors will request samples of vulnerability reports, remediation tracking, and evidence that high-risk findings were resolved within defined timelines.

Supply Chain and Third-Party Risk

The framework explicitly addresses third-party risk, particularly for critical service providers (payment processors, cloud providers, data centers). Security leaders must maintain:

  • A third-party risk assessment questionnaire or audit program
  • Contractual clauses requiring security standards, audit rights, and incident notification timelines
  • Periodic reassessment of critical vendors, at minimum annually
  • Documented due diligence for new vendors before onboarding

Alignment with Saudi PDPL and NCA ECC

The Saudi Personal Data Protection Law (PDPL) and NCA Essential Cybersecurity Controls (ECC) reinforce SAMA expectations. Organizations handling personal data must demonstrate compliance with PDPL requirements for data minimization, purpose limitation, and breach notification within 72 hours. The NCA ECC provides a baseline for critical infrastructure operators; SAMA-regulated entities typically exceed this baseline.

Practical Steps for Evidence Gathering

Begin by mapping your current controls against the SAMA framework. Document gaps and prioritize remediation based on risk. Implement a governance structure that assigns ownership for each control. Use industry tools (SIEM platforms, vulnerability management systems, identity governance solutions) to generate audit trails and compliance reports automatically. Schedule regular management reviews to assess control effectiveness and update documentation. Finally, engage internal or external auditors to validate your evidence package before regulatory examinations.

Compliance with SAMA's framework is not a one-time project but an ongoing operational discipline. Security leaders who embed evidence gathering into routine operations will demonstrate maturity and reduce audit friction.