Understanding SAMA CSF Current Expectations

The SAMA Cyber Security Framework continues to define mandatory security posture for all financial institutions regulated by the Saudi Arabian Monetary Authority. Unlike prescriptive checklists, the framework operates on a maturity model across five core pillars: Governance, Risk Management, Resilience, Detection and Response, and Compliance and Assurance. Financial institutions must demonstrate not only that controls exist, but that they operate at measurable maturity levels aligned with institutional risk appetite and regulatory expectation.

In 2026, SAMA's supervisory approach increasingly emphasizes evidence-based compliance. Institutions are expected to maintain comprehensive control documentation that maps directly to framework requirements, demonstrates control effectiveness through testing outcomes, and shows continuous improvement cycles. This shift reflects global regulatory trends and integration with the National Cybersecurity Authority (NCA) Enhanced Cyber Controls (ECC) framework, which now operates in parallel for critical infrastructure operators.

The Five Pillars and Evidence Requirements

Governance and Accountability

SAMA expects documented governance structures that assign clear cybersecurity accountability at board and executive levels. Evidence should include board-approved cybersecurity strategies, defined roles and responsibilities, documented decision-making frameworks, and evidence of regular board-level reporting on cyber risk. Financial institutions must demonstrate that cybersecurity is embedded in enterprise risk management, not siloed within IT.

Risk Management

Institutions must conduct annual risk assessments aligned with the framework's risk taxonomy. Evidence includes documented asset inventories, threat modeling tied to financial sector attack patterns, vulnerability assessments with remediation tracking, and third-party risk registers. Integration with the Saudi Personal Data Protection Law (PDPL) is now mandatory—data classification, data flow mapping, and privacy impact assessments must be linked to cyber risk registers.

Resilience and Business Continuity

Control evidence includes disaster recovery plans tested at defined intervals, backup verification logs, incident response playbooks exercised through tabletop and live simulations, and recovery time objective (RTO) and recovery point objective (RPO) metrics aligned to critical business functions. SAMA expects documented evidence of annual testing with outcomes reviewed and remediated.

Detection and Response

Security monitoring must be evidenced through Security Operations Center (SOC) logs, alert tuning documentation, incident response timelines, and metrics demonstrating mean time to detect (MTTD) and mean time to respond (MTTR). Institutions should maintain forensic-ready logging across critical systems and demonstrate integration with NCA incident reporting obligations where applicable.

Compliance and Assurance

Evidence includes internal audit findings, external penetration test reports, vulnerability scan results, and remediation tracking. SAMA expects institutions to conduct annual self-assessments against the framework maturity model and to engage independent auditors to validate control effectiveness. Documentation of corrective actions and their closure is mandatory.

Practical Evidence Collection Strategy

Security leaders should establish a control evidence repository organized by framework pillar. Each control should link to policy, procedure, system configuration, testing results, and remediation records. Automated evidence collection through configuration management databases (CMDBs), log aggregation platforms, and vulnerability management tools reduces manual effort and improves audit readiness.

Integration with ISO/IEC 27001:2022 and ISO/IEC 42001 (AI governance) strengthens the evidence base. Many financial institutions use these international standards as operational scaffolding while mapping controls back to SAMA CSF pillars for regulatory reporting.

Key Compliance Actions for 2026

  • Conduct a gap analysis against the current SAMA CSF maturity model and document remediation roadmaps
  • Establish a control testing calendar aligned to SAMA supervisory expectations
  • Integrate PDPL compliance evidence into cyber risk registers
  • Implement continuous monitoring and automated evidence collection
  • Engage independent auditors to validate control maturity and identify improvement opportunities
  • Document board-level cybersecurity reporting and strategic decision-making

SAMA's regulatory focus remains on demonstrating that cybersecurity controls are not theoretical but operationally effective and continuously improved. Evidence-based compliance is no longer optional—it is the baseline expectation for financial institutions operating in the Kingdom.