Understanding SAMA's Current Cyber Security Framework

The Saudi Central Bank (SAMA) Cyber Security Framework establishes a baseline of mandatory security controls for all financial institutions, payment service providers, and critical infrastructure operators under its jurisdiction. Unlike voluntary frameworks, SAMA CSF compliance is a regulatory requirement enforced through regular supervisory reviews and examinations.

The framework aligns with international standards—particularly ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0—while addressing the specific risk environment and operational context of the Saudi financial system. Entities must demonstrate not only that controls exist, but that they are effective, documented, and continuously monitored.

Core Pillars and Compliance Evidence

1. Governance and Risk Management

SAMA expects a documented cyber risk governance structure with clear accountability. Evidence includes:

  • Board-approved cyber security strategy and annual risk assessments aligned with business objectives
  • Defined roles for Chief Information Security Officer (CISO) or equivalent, with direct board reporting lines
  • Documented risk appetite statement specific to cyber threats
  • Third-party risk assessments for critical vendors and service providers

Auditors will request board meeting minutes, governance charters, and evidence that cyber risk is reviewed at least quarterly at senior management level.

2. Technical Controls and Asset Management

SAMA mandates baseline technical hygiene: access control, encryption, network segmentation, and endpoint hardening. Compliance evidence must include:

  • Inventory of all IT assets (hardware, software, cloud services) with classification by criticality
  • Encryption standards applied to data at rest and in transit, with key management procedures documented
  • Multi-factor authentication (MFA) enforced for all privileged accounts and remote access
  • Vulnerability management program with defined scan frequency, remediation timelines, and closure evidence
  • Configuration baselines and change management logs showing approval and testing

Maintain centralized logs of all control changes and evidence of periodic penetration testing or red-team exercises conducted by qualified third parties.

3. Incident Response and Business Continuity

SAMA requires a tested incident response plan and business continuity strategy. Auditors will examine:

  • Documented incident response procedures with clear escalation paths and communication protocols
  • Evidence of annual tabletop exercises or simulations involving senior management
  • Recovery time objectives (RTO) and recovery point objectives (RPO) for critical systems, approved by the board
  • Backup and disaster recovery testing results, with documented recovery success rates
  • Incident logs showing detection, response, and closure for a representative sample of events

4. Compliance with NCA ECC and PDPL

The National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) and the Saudi Personal Data Protection Law (PDPL) overlap with SAMA CSF. Entities must demonstrate:

  • Data classification and handling procedures compliant with PDPL requirements
  • Privacy impact assessments for new systems or data processing activities
  • Breach notification procedures aligned with PDPL timelines (72 hours to NCA; without undue delay to affected individuals)
  • Alignment of access controls and data retention policies with both SAMA and PDPL expectations

Audit Readiness: Practical Steps

Documentation First: Compile a centralized control register mapping each SAMA requirement to your implemented control, responsible party, and evidence location.

Automate Evidence Collection: Use Security Information and Event Management (SIEM) systems, vulnerability scanners, and privileged access management (PAM) tools to generate audit trails automatically. Manual spreadsheets are insufficient.

Regular Self-Assessment: Conduct internal assessments at least semi-annually using the same criteria SAMA examiners will apply. Identify and remediate gaps before supervisory reviews.

Engage Third Parties Wisely: Retain qualified external auditors to validate your control environment. SAMA respects independent assessments and will factor them into supervisory judgments.

Key Takeaway

SAMA compliance is not a checkbox exercise. The framework demands a mature, documented, and continuously improving security posture. Security leaders must ensure that every control is not only in place but also auditable—with clear evidence of design, implementation, testing, and effectiveness. Organizations that treat compliance as an opportunity to strengthen their security posture will find themselves better positioned to resist emerging threats and maintain stakeholder trust.