Understanding SAMA's Current Cyber Security Framework

The Saudi Central Bank (SAMA) Cyber Security Framework is not a voluntary guideline—it is a binding regulatory expectation for all financial institutions operating in the Kingdom. The framework aligns with international standards including ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0, while embedding Saudi Arabia's regulatory philosophy: governance first, controls second, evidence always.

SAMA's framework rests on four pillars: governance and risk management, technical and operational controls, incident response and business continuity, and third-party and supply-chain resilience. Each pillar contains specific requirements that institutions must not only implement but actively demonstrate to regulators and auditors.

Governance and Risk Management: The Foundation

SAMA expects a documented cybersecurity governance structure with clear accountability. This means:

  • A board-level cybersecurity committee with documented charter, meeting minutes, and decision logs
  • A Chief Information Security Officer (CISO) or equivalent role reporting to the board or audit committee
  • Annual cybersecurity risk assessments aligned with the institution's overall enterprise risk framework
  • A formal cybersecurity strategy document, reviewed and approved annually, with measurable objectives

Evidence of governance is not a PowerPoint slide. SAMA examiners look for board minutes showing cybersecurity agenda items, CISO performance metrics in compensation structures, and risk registers that quantify cyber exposure in business terms. The National Cybersecurity Authority (NCA) and SAMA conduct joint examinations; they cross-reference governance claims against actual board records and budget allocations.

Technical Controls: Detection and Prevention

The framework mandates baseline technical controls:

  • Access control: Multi-factor authentication (MFA) for all remote and privileged access; role-based access control (RBAC) with quarterly reviews
  • Encryption: Data in transit (TLS 1.2 minimum) and at rest (AES-256 or equivalent) for payment systems and customer data
  • Logging and monitoring: Centralized security information and event management (SIEM) with 90-day minimum retention; real-time alerting for critical events
  • Vulnerability management: Quarterly scans, annual penetration testing, and documented remediation timelines

Evidence means audit logs, configuration baselines, and third-party assessment reports. SAMA expects institutions to produce vulnerability scan results, patch deployment records, and MFA enrollment rosters. Self-attestation is insufficient; technical controls must be verifiable through logs, screenshots, and independent testing.

Incident Response and Business Continuity

SAMA requires a tested incident response plan with documented procedures for detection, containment, eradication, and recovery. Evidence includes:

  • Annual tabletop exercises with attendance records and post-exercise reports
  • Business continuity and disaster recovery plans with recovery time objectives (RTO) and recovery point objectives (RPO) defined for critical systems
  • Annual testing of backup and recovery procedures with documented results
  • Incident notification procedures aligned with the Saudi Personal Data Protection Law (PDPL) and NCA breach reporting requirements

Institutions must maintain an incident log covering the past three years, showing detection date, classification, impact assessment, and remediation status. SAMA and NCA examiners will ask for specific incidents and review how they were handled.

Third-Party and Supply-Chain Risk

SAMA's framework explicitly addresses vendor and outsourcing risk. Financial institutions must document:

  • Vendor risk assessments before engagement, with cybersecurity questionnaires and audit rights
  • Contracts that mandate incident notification, audit access, and compliance with SAMA and NCA requirements
  • Annual vendor cybersecurity reviews and audit reports
  • A supply-chain resilience plan identifying critical vendors and alternative arrangements

How to Evidence Compliance

Effective evidence management requires:

  • Documentation inventory: Maintain a central repository of policies, procedures, audit reports, and control test results, indexed by framework requirement
  • Regular self-assessment: Conduct quarterly compliance reviews using a SAMA CSF mapping matrix; identify gaps and track remediation
  • Independent audit: Commission annual third-party assessments against SAMA CSF and ISO/IEC 27001:2022; use findings to prioritize improvements
  • Board reporting: Present compliance status, audit findings, and remediation progress to the board quarterly
  • Examiner readiness: Prepare a compliance evidence package organized by framework pillar; brief leadership on likely examination questions

SAMA's cyber security expectations are not static. Institutions should monitor NCA guidance, SAMA circulars, and updates to the PDPL implementing regulations. Compliance is an ongoing process, not a one-time project. Those who treat it as a governance discipline—with board oversight, dedicated resources, and regular evidence collection—will navigate examinations confidently and reduce their actual cyber risk.