Understanding SAMA CSF Expectations

The Saudi Central Bank (SAMA) Cyber Security Framework establishes a risk-based, control-oriented compliance regime for all financial institutions operating in the Kingdom. Unlike prescriptive checklists, the framework demands that organisations demonstrate a mature understanding of their threat landscape, risk appetite, and the specific controls deployed to mitigate material cyber risks.

SAMA's expectations are anchored in three pillars: governance and oversight, risk management and resilience, and technical and operational security. Each pillar contains multiple domains, and compliance is measured not by ticking boxes but by producing credible evidence that controls are designed, implemented, monitored, and continuously improved.

Governance and Oversight: The Foundation

SAMA requires that cybersecurity governance be embedded at board and executive management level. This means:

  • A documented cybersecurity strategy aligned with business objectives and approved by the board
  • Clear accountability: a Chief Information Security Officer (CISO) or equivalent with direct reporting to senior management
  • Regular board-level reporting on cyber risk posture, incidents, and remediation progress
  • Formal policies covering access control, data protection, incident response, and third-party risk management

Evidence requirement: Maintain board minutes confirming cyber risk discussion, signed governance policies with version control, and a current register of cyber risk metrics tracked monthly. SAMA inspectors will request these during examinations.

Risk Management and Resilience

SAMA mandates a structured approach to identifying, assessing, and managing cyber risks. This includes:

  • Annual cyber risk assessments that map critical assets, threats, and vulnerabilities
  • Business continuity and disaster recovery plans tested at least annually
  • Incident response procedures documented and rehearsed
  • Third-party risk management: due diligence on vendors, service providers, and outsourced functions

Evidence requirement: Maintain dated risk assessment reports, test results with sign-off, incident response playbooks, and a third-party risk register. Document remediation of identified gaps with timelines and owner accountability.

Technical and Operational Security

The framework aligns with international standards—particularly ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0—and expects organisations to implement controls across:

  • Identity and access management: Multi-factor authentication, role-based access control, privileged access management
  • Data protection: Encryption at rest and in transit, data classification, secure disposal
  • Network security: Firewalls, intrusion detection/prevention, network segmentation
  • Endpoint protection: Antimalware, patch management, endpoint detection and response (EDR)
  • Security monitoring: Security Operations Centre (SOC) or equivalent, log aggregation, threat intelligence

Evidence requirement: Maintain a detailed control inventory mapping each control to SAMA domains and international standards. Document configuration baselines, patch schedules, access lists, and SOC alert procedures. Provide audit logs demonstrating continuous monitoring.

Demonstrating Compliance: Practical Steps

1. Create a SAMA Compliance Roadmap
Map your current state against SAMA CSF domains. Identify gaps and prioritise remediation based on risk and regulatory weight.

2. Build a Control Evidence Repository
Centralise documentation: policies, procedures, configuration screenshots, access lists, test reports, and audit logs. Use a governance, risk, and compliance (GRC) platform to track control ownership and remediation status.

3. Engage Third-Party Assessors
Commission an independent cybersecurity assessment aligned with ISO/IEC 27001:2022 or NIST CSF 2.0. SAMA values external validation and will review third-party audit reports during examinations.

4. Align with National Standards
Ensure your controls also satisfy the National Cybersecurity Authority (NCA) Essential Cyber Controls (ECC) and compliance with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations, particularly where customer data is involved.

5. Establish Continuous Monitoring
Implement automated logging, alerting, and monthly control testing. Document evidence of control effectiveness—not just existence.

Key Takeaway

SAMA compliance is not a one-time audit; it is a continuous demonstration of cyber maturity. Security leaders must shift from a compliance mindset to a resilience mindset: build controls that protect the organisation, document them thoroughly, test them regularly, and be ready to explain them to regulators. The framework rewards organisations that treat cybersecurity as a strategic business function, not a technical checkbox.