Understanding SAMA CSF Expectations in 2026

The Saudi Central Bank (SAMA) Cyber Security Framework remains the primary regulatory baseline for financial institutions operating in the Kingdom. As of 2026, SAMA CSF expectations have evolved to align with international standards including ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0, and the National Cybersecurity Authority (NCA) Essential Cyber Controls (ECC). Financial institutions must now demonstrate not only technical controls but also governance maturity, incident response capability, and third-party risk management.

Core SAMA CSF Pillars and Evidence Requirements

SAMA CSF is built on five foundational pillars: governance and risk management, asset management, access control, data protection, and incident management. Each pillar requires documented evidence of implementation and effectiveness.

Governance and Risk Management

Organizations must establish a board-level cybersecurity committee with defined authority and reporting lines. Evidence includes:

  • Board-approved cybersecurity strategy aligned with business objectives
  • Annual risk assessments conducted by qualified third parties, with findings documented and remediation tracked
  • Cyber risk metrics reported to senior management at least quarterly
  • Written policies covering incident response, business continuity, and disaster recovery

SAMA expects these documents to be current, version-controlled, and demonstrably enforced across the organization.

Asset Management and Classification

Institutions must maintain an authoritative inventory of all critical assets—systems, data, and infrastructure—with documented classification levels. Evidence should include:

  • Centralized asset register updated at least quarterly
  • Data classification matrix aligned with regulatory and business sensitivity
  • Ownership and custodian assignments for each critical asset
  • Audit trails showing changes to asset inventory

This aligns with NCA ECC requirements and the Saudi Personal Data Protection Law (PDPL) data mapping obligations.

Access Control

SAMA expects role-based access control (RBAC) or attribute-based access control (ABAC) with principle of least privilege enforced. Demonstrable evidence includes:

  • Documented access control policies for all systems and data repositories
  • Quarterly access reviews with sign-off by system owners
  • Multi-factor authentication (MFA) enabled for all remote and privileged access
  • Segregation of duties matrices for critical financial processes
  • Logs of access provisioning and de-provisioning, with average time-to-revoke metrics

Data Protection

Encryption of data in transit and at rest, aligned with PDPL Article 7 requirements, is mandatory. Organizations must provide:

  • Encryption inventory specifying algorithms, key lengths, and key management procedures
  • Data loss prevention (DLP) policies and monitoring reports
  • Backup and recovery testing records demonstrating restoration capability
  • Secure disposal procedures with audit evidence

Incident Management

A mature incident response capability is non-negotiable. SAMA expects:

  • Documented incident response plan with defined roles, escalation procedures, and communication protocols
  • Incident log covering the past 24 months with classification, root cause, and remediation
  • Annual tabletop exercises or simulations with documented outcomes
  • Timely notification procedures compliant with PDPL breach notification rules

Practical Evidence Collection and Documentation

Organizations should establish a centralized compliance evidence repository—often called a control library or compliance portal—that maps each SAMA CSF requirement to specific policies, procedures, logs, and attestations. This should include:

  • Policy documentation: Current versions with approval dates and review schedules
  • Audit and assessment reports: Internal and external penetration tests, vulnerability assessments, and compliance audits
  • Operational logs and metrics: System access logs, patch deployment records, configuration management database (CMDB) snapshots
  • Training and awareness records: Completion certificates for mandatory security training
  • Third-party attestations: Vendor security assessments, SOC 2 reports, or ISO 27001 certificates

Integration with NCA ECC and PDPL

SAMA CSF compliance should be integrated with NCA Essential Cyber Controls and PDPL obligations. The NCA ECC provides a baseline for all critical infrastructure operators; PDPL Article 7 mandates data protection and breach notification. Organizations that evidence SAMA CSF compliance typically exceed both requirements, but explicit mapping is essential for audit readiness.

Preparing for SAMA Examinations

SAMA conducts regular on-site and off-site examinations. Institutions should maintain a documented compliance dashboard showing the status of each CSF pillar, remediation timelines for findings, and evidence availability. This accelerates examination cycles and demonstrates governance maturity to regulators.

By treating SAMA CSF compliance as an ongoing program—not a one-time checklist—financial institutions in Saudi Arabia can reduce regulatory risk, strengthen resilience, and build stakeholder confidence in their cybersecurity posture.