Understanding the SAMA Cyber Security Framework

The Saudi Central Bank (SAMA) Cyber Security Framework represents the regulatory baseline for all financial institutions operating in the Kingdom. Unlike advisory guidance, the framework is mandatory and forms the foundation of SAMA's supervisory expectations. Institutions must implement controls across governance, risk management, asset management, access control, cryptography, incident response, and business continuity.

The framework aligns with international standards—particularly ISO/IEC 27001:2022 and NIST CSF 2.0—while reflecting Saudi Arabia's specific regulatory environment and the broader NCA Cybersecurity Controls (ECC) requirements that apply across critical sectors. This alignment means organizations can often satisfy both SAMA and sector-specific mandates through a single, well-designed control environment.

Core Pillars and Audit Expectations

SAMA's supervisory teams assess compliance across five key dimensions:

  • Governance and Organization: Board-level cyber oversight, defined roles, and a documented information security strategy aligned with business objectives.
  • Risk Management: Formal risk assessments, risk appetite statements, and documented treatment decisions for identified threats.
  • Technical Controls: Network segmentation, encryption, access logging, vulnerability management, and endpoint detection and response (EDR).
  • Incident Response and Resilience: Tested incident response plans, business continuity procedures, and regular tabletop exercises.
  • Third-Party and Supply Chain Security: Vendor risk assessments, contractual security clauses, and ongoing monitoring of critical service providers.

Building Audit-Ready Evidence

Compliance is not a one-time checkbox. SAMA examiners expect documented, verifiable evidence that controls operate continuously. Security leaders should maintain:

  • Policy and Procedure Documentation: Current, version-controlled policies covering access management, change control, incident handling, and vendor management. Each policy should reference applicable SAMA requirements and ISO/IEC 27001:2022 controls.
  • Risk Assessment Records: Annual or event-driven risk assessments with clear methodology, asset inventories, threat identification, and documented risk decisions signed by management.
  • Control Testing and Monitoring Logs: Evidence of regular access reviews, vulnerability scans, penetration test reports, firewall rule audits, and security event logs retained for the required period.
  • Training and Awareness Records: Attendance logs, completion certificates, and phishing simulation results demonstrating that staff understand their security responsibilities.
  • Incident Records: Documented incidents, root cause analyses, remediation actions, and evidence of closure, even for low-severity events.
  • Third-Party Assessments: Vendor security questionnaires, SOC 2 reports, penetration test summaries, and evidence of ongoing monitoring and contract compliance.

Alignment with Saudi PDPL and NCA ECC

The Saudi Personal Data Protection Law (PDPL) and its implementing regulations require organizations to protect personal data with appropriate technical and organizational measures. SAMA's framework reinforces these obligations for financial institutions handling customer data. Similarly, the NCA's Cybersecurity Controls (ECC) provide a sector-agnostic baseline; financial institutions must meet both SAMA's specific expectations and any NCA requirements applicable to their critical infrastructure role.

A unified governance model—where the Chief Information Security Officer (CISO) reports findings to an audit committee and the board—demonstrates that cyber risk is treated as a business risk, not an IT problem. This structure is essential for SAMA auditors and supports compliance with broader corporate governance standards.

Practical Next Steps

Organizations should conduct a gap assessment against the SAMA framework, prioritize remediation of control gaps, and establish a continuous monitoring program. Appoint a cyber governance lead, establish metrics to track control effectiveness, and schedule regular board reporting. Engage external auditors or consultants familiar with SAMA expectations to validate readiness before a formal examination.

Compliance with SAMA's Cyber Security Framework is not optional—it is a regulatory imperative. By building a structured, documented control environment and maintaining audit-ready evidence, financial institutions protect themselves against sanctions, reputational damage, and operational disruption.