Understanding Current SAMA CSF Expectations

The SAMA Cyber Security Framework remains the primary regulatory instrument for financial institutions operating in Saudi Arabia. Unlike aspirational frameworks, SAMA CSF is prescriptive: it defines mandatory controls across governance, risk management, technical defences, and incident response. Compliance is not optional; it is a condition of banking license renewal and regulatory standing.

The framework aligns with international standards—notably NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022—but adds Saudi-specific governance requirements, including board-level accountability, local data residency, and integration with the broader National Cybersecurity Authority (NCA) ecosystem and the Saudi Personal Data Protection Law (PDPL).

Core Pillars and Evidence Requirements

Governance and Risk Management

SAMA expects a documented cybersecurity strategy approved by the board, with clear roles, responsibilities, and escalation paths. Evidence includes:

  • Board meeting minutes showing cybersecurity agenda items and decisions
  • Formal cybersecurity policy and procedures, version-controlled and dated
  • Risk register mapping threats to controls, with risk owners and remediation timelines
  • Third-party risk assessments and vendor management agreements

Regulators audit not just the existence of policies but their enforcement. Logs showing policy violations, remediation actions, and management sign-off are critical evidence.

Technical Controls and Segmentation

SAMA mandates network segmentation, encryption of sensitive data in transit and at rest, and multi-factor authentication for privileged access. Compliance evidence includes:

  • Network diagrams showing segmentation boundaries and data flow
  • Encryption key management policies and audit logs
  • Access control matrices and privileged account reviews
  • Vulnerability scans and patch management records

Passive documentation is insufficient. Examiners conduct live testing: they request real-time demonstrations of MFA, verify encryption status on sample systems, and review patch deployment timelines against vulnerability disclosure dates.

Incident Response and Business Continuity

SAMA requires a tested incident response plan, with defined detection thresholds, escalation procedures, and communication protocols. Compliance evidence includes:

  • Incident response plan, reviewed and approved annually
  • Tabletop exercise records showing cross-functional participation
  • Incident logs with timestamps, root cause analysis, and corrective actions
  • Business continuity and disaster recovery test results

Regulators expect evidence that incidents are detected within hours, not days. Security Operations Centre (SOC) logs, SIEM dashboards, and alert thresholds must demonstrate active monitoring capability.

Integration with NCA ECC and PDPL

SAMA compliance now intersects with the National Cybersecurity Authority's Essential Cybersecurity Controls (ECC) and the Saudi PDPL with its implementing regulations. Financial institutions must evidence:

  • Data classification and protection aligned with PDPL requirements for personal data
  • Data subject rights processes (access, deletion, portability)
  • Privacy impact assessments for new systems
  • Alignment with NCA ECC baseline controls for critical infrastructure

Failing to integrate these frameworks creates compliance gaps and regulatory exposure.

Practical Steps for Audit Readiness

Inventory and map: Document all systems, data flows, and controls against SAMA CSF domains. Use a control matrix to show which policy, procedure, or log entry evidences each requirement.

Automate evidence collection: Configure SIEM, vulnerability scanners, and access management tools to generate compliance-ready reports. Manual evidence gathering is error-prone and slow.

Conduct pre-audit assessments: Engage independent auditors to test controls before regulatory examination. Address gaps proactively.

Maintain audit trails: Ensure all security events, policy changes, and remediation actions are logged with immutable timestamps and user attribution.

SAMA compliance is not a checkbox exercise. It requires a disciplined, documented approach to governance, risk management, and technical defence. Security leaders who treat compliance as an operational imperative—not a compliance burden—build the resilience and transparency that regulators expect.