Understanding SAMA CSF Current Requirements

The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework establishes a comprehensive set of mandatory controls and governance expectations for all financial institutions operating in the Kingdom. Unlike aspirational frameworks, SAMA CSF is prescriptive: it defines what must be in place, not merely what should be considered. Financial institutions face regulatory enforcement if they fail to meet these baseline requirements.

The framework aligns with international standards including ISO/IEC 27001:2022 and NIST CSF 2.0, but adds Saudi-specific regulatory context and financial sector priorities. It covers governance, risk management, technical controls, incident response, and third-party management. Compliance is not optional—it is a condition of operating a banking license in Saudi Arabia.

Core Governance and Accountability Evidence

SAMA expects financial institutions to demonstrate governance through documented structures and accountability chains. Security leaders must evidence:

  • Board and executive oversight: Minutes from board-level cyber risk discussions, documented cyber strategy approval, and quarterly risk reporting to senior management.
  • Chief Information Security Officer (CISO) authority: A defined CISO role with direct reporting line to the Chief Executive Officer or Chief Risk Officer, not buried within IT operations.
  • Cyber risk committee: A formal committee charter, membership list, meeting schedule, and documented decisions on risk acceptance and remediation priorities.
  • Policies and standards: Written information security policies, data classification standards, access control procedures, and incident response plans, all dated and version-controlled.

SAMA auditors review these documents during examinations. Institutions without clear governance trails face findings and enforcement actions.

Risk Assessment and Continuous Monitoring

The framework requires annual enterprise-wide risk assessments and ongoing vulnerability management. Evidence includes:

  • Annual risk assessment reports identifying threats, vulnerabilities, and residual risk ratings.
  • Vulnerability scanning results (at least quarterly for internet-facing systems, more frequently for critical assets).
  • Penetration testing reports (annual minimum, with remediation tracking).
  • Security Control Assessments (SCAs) demonstrating that controls operate as designed.
  • Key Risk Indicators (KRIs) tracked and reported monthly or quarterly to senior management.

Passive compliance—running scans and filing reports—is insufficient. SAMA expects institutions to track remediation timelines, justify delays, and demonstrate that critical findings receive priority.

Technical Control Evidence

SAMA CSF mandates specific technical controls. Institutions must evidence:

  • Access control: Multi-factor authentication for privileged accounts, role-based access control matrices, and quarterly access reviews with documented approval.
  • Encryption: Encryption of sensitive data in transit and at rest; key management procedures with documented key rotation.
  • Network segmentation: Documented network architecture diagrams showing segmentation of critical systems, with firewall rules and access logs.
  • Security monitoring: A Security Operations Center (SOC) or managed security service provider with 24/7 monitoring, alert logs, and incident response records.
  • Endpoint protection: Antivirus and endpoint detection and response (EDR) deployment across all endpoints, with patch management records.

SAMA examiners request configuration reviews, log samples, and testing evidence. Controls that exist on paper but are not actively monitored will fail scrutiny.

Incident Response and Business Continuity

Institutions must evidence incident preparedness through:

  • A documented Incident Response Plan with defined roles, escalation procedures, and communication templates.
  • Annual tabletop exercises or simulations with attendance records and lessons-learned documentation.
  • Incident logs (even minor incidents) showing detection, investigation, containment, and closure.
  • A Business Continuity and Disaster Recovery Plan tested at least annually, with recovery time objectives (RTOs) and recovery point objectives (RPOs) defined and validated.

Third-Party and Vendor Risk

SAMA expects institutions to manage cyber risk in their supply chain. Evidence includes:

  • A vendor management policy defining security requirements for critical service providers.
  • Security assessments of key vendors (questionnaires, audits, or certifications such as ISO/IEC 27001:2022).
  • Contracts with defined security obligations, breach notification clauses, and audit rights.
  • Periodic vendor compliance reviews and incident reporting from vendors.

Building and Maintaining an Evidence Repository

Successful SAMA compliance requires a centralized evidence repository. Security leaders should maintain:

  • A compliance tracking matrix mapping SAMA CSF requirements to implemented controls and evidence artifacts.
  • Dated, version-controlled policies and procedures.
  • Scan and assessment reports with remediation tracking.
  • Training and awareness records.
  • Audit findings and closure evidence.
  • Risk register with current status and mitigation plans.

This repository streamlines both internal audits and SAMA examinations, reducing preparation time and demonstrating institutional maturity.

Alignment with Saudi Data Protection Law

SAMA CSF compliance must also align with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations. Institutions handling personal data must evidence data protection impact assessments, data subject rights procedures, and breach notification protocols—all of which feed into the broader cyber security posture.

Conclusion

SAMA CSF compliance is not a checkbox exercise; it is a continuous, evidence-based commitment to cyber security governance and risk management. Financial institutions that build robust documentation, maintain active monitoring, and demonstrate accountability to their boards will satisfy SAMA expectations and reduce regulatory risk. Those that treat compliance as a periodic audit task will face findings and corrective action orders.