Understanding SAMA's Cyber Security Framework

The Saudi Central Bank (SAMA) Cyber Security Framework establishes mandatory requirements for all financial institutions operating in the Kingdom. Unlike voluntary industry guidance, SAMA's expectations carry regulatory force and are subject to supervisory examination. The framework aligns with international standards—including NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022—while reflecting the specific risk environment and business models of Saudi financial services.

SAMA's framework rests on five core pillars: governance and risk management, asset and access management, threat and vulnerability management, incident management, and business continuity. Each pillar contains specific control objectives that institutions must implement and evidence.

Key Evidence Requirements by Control Domain

Governance and Risk Management

SAMA expects documented cyber risk governance at board and executive committee level. Evidence includes:

  • Board-approved cyber security policies and strategy
  • Defined roles, responsibilities, and reporting lines (including a named CISO or equivalent)
  • Annual cyber risk assessments aligned with business strategy
  • Board minutes demonstrating cyber risk oversight and decision-making
  • Documented risk appetite and tolerance thresholds

Financial institutions must maintain a current asset inventory linked to risk classification. This inventory should map critical systems, data flows, and dependencies to business functions. SAMA examiners will request evidence that the inventory is maintained, reviewed, and used to prioritize controls.

Access and Identity Management

SAMA mandates strong authentication, privileged access controls, and user provisioning governance. Required evidence includes:

  • Multi-factor authentication implementation for all remote and privileged access
  • Documented privileged access management (PAM) procedures and audit logs
  • User access reviews conducted at least quarterly, with sign-off from business owners
  • Segregation of duties matrices and compensating controls where segregation is not feasible
  • Termination procedures with evidence of timely access revocation

Threat and Vulnerability Management

Institutions must demonstrate active threat monitoring and vulnerability remediation. Key evidence items:

  • Vulnerability scanning results and remediation tracking (with documented timelines)
  • Penetration testing reports (internal and external) conducted at least annually
  • Security patch management procedures and compliance metrics
  • Threat intelligence integration into security operations
  • Configuration baselines and compliance monitoring reports

SAMA expects evidence that vulnerability findings are tracked to closure and that remediation timelines reflect risk severity. Institutions must also demonstrate that security controls are tested and validated before deployment to production.

Incident Management and Response

SAMA requires a documented incident response plan, regular testing, and evidence of execution capability. Required documentation:

  • Incident response plan approved by senior management
  • Tabletop exercises or simulations conducted at least annually
  • Incident log showing detection, investigation, and resolution timelines
  • Root cause analysis reports for significant incidents
  • Evidence of communication with SAMA and other regulators (where required)
  • Lessons-learned documentation and control improvements implemented

Institutions must also maintain a security event log with sufficient detail to reconstruct incidents. This includes system logs, network traffic, and application logs retained in accordance with SAMA's data retention expectations.

Business Continuity and Resilience

SAMA expects documented disaster recovery and business continuity plans with regular testing. Evidence includes:

  • Business continuity and disaster recovery plans covering critical systems
  • Recovery time objectives (RTO) and recovery point objectives (RPO) aligned with business criticality
  • Annual testing results with documented timelines and findings
  • Backup and restoration procedures with validation logs

Practical Compliance Approach

Security leaders should establish a compliance evidence repository—a centralized system documenting control implementation, testing, and monitoring. This repository should map each control to SAMA requirements, NIST CSF 2.0 functions, and ISO/IEC 27001:2022 clauses, simplifying both internal audit and regulatory examination.

Regular self-assessment against the SAMA framework, conducted quarterly or semi-annually, helps identify gaps before supervisory examination. Engaging internal audit and compliance teams in control validation strengthens the quality of evidence and demonstrates governance rigor.

SAMA examinations are data-driven. Institutions that can quickly produce control documentation, testing results, and audit trails demonstrate maturity and reduce examination friction. Conversely, missing or poorly maintained evidence signals control weakness and invites deeper scrutiny.

Integration with Broader Regulatory Obligations

The SAMA Cyber Security Framework does not exist in isolation. Institutions must also align with the Saudi Personal Data Protection Law (PDPL), which mandates data protection impact assessments and breach notification procedures. Evidence of PDPL compliance—including data inventory, processing agreements, and breach response logs—should be integrated into the broader cyber security evidence portfolio.

For institutions operating across the GCC, alignment with the National Cybersecurity Authority (NCA) Essential Cyber Criteria (ECC) and equivalent frameworks in the UAE, Kuwait, and Bahrain ensures consistent control implementation across borders.

Conclusion

SAMA's Cyber Security Framework is not a checklist to complete; it is a governance and control framework that must be evidenced through documented policies, tested procedures, and maintained audit trails. Financial institutions that treat evidence collection as an integral part of control operation—not an afterthought—will demonstrate compliance credibly and position themselves to respond to emerging threats with agility and transparency.