SAMA Framework: From Policy to Proof

The Saudi Central Bank's Cyber Security Framework (SAMA CSF) has evolved into a mature, evidence-driven standard that moves beyond theoretical compliance. Financial institutions and critical infrastructure operators now face explicit expectations to demonstrate that security controls are not merely documented but actively implemented, monitored, and effective. The framework's five pillars—governance, risk management, security operations, resilience, and compliance—form the backbone of SAMA's assessment methodology, and regulators increasingly demand tangible proof of maturity across each domain.

Unlike frameworks that rely on self-attestation, SAMA's current approach requires institutions to maintain a continuous audit trail of control execution. This shift reflects alignment with the National Cybersecurity Authority's Cybersecurity Essentials (ECC) and international standards such as ISO/IEC 27001:2022, which emphasize measurable outcomes over checkbox compliance.

Five Pillars: What Evidence Looks Like

Governance

SAMA expects documented board-level cyber risk oversight, including board minutes, risk committee charters, and evidence of regular cyber briefings. Institutions must show that cybersecurity is a standing agenda item with clear escalation paths. Evidence includes appointment records for Chief Information Security Officers, documented authority matrices, and audit trails of governance decisions.

Risk Management

Annual risk assessments must be formally conducted, documented, and reviewed by independent parties. SAMA auditors seek evidence of threat modelling, asset inventories, vulnerability scans, and risk heat maps updated quarterly. Risk registers must link to mitigation plans with assigned owners and completion dates. Third-party risk assessments should be current and cover supply chain, cloud, and outsourced security functions.

Security Operations

This pillar demands the most granular evidence: Security Operations Centre (SOC) logs, incident response playbooks with execution records, patch management schedules with compliance metrics, and access control reviews. SAMA expects real-time or near-real-time monitoring dashboards, with evidence of alert tuning, false-positive reduction, and mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR) metrics tracked over time.

Resilience

Business continuity and disaster recovery plans must include test results, tabletop exercise minutes, and recovery time objective (RTO) and recovery point objective (RPO) validation. Evidence includes backup integrity verification logs, failover test reports, and documented lessons learned from drills conducted at least annually.

Compliance

Institutions must evidence adherence to the Saudi Personal Data Protection Law (PDPL), PCI DSS 4.0 (where applicable), and sector-specific regulations. This includes data classification matrices, consent records, third-party audit reports, and evidence of remediation for any identified gaps.

Building an Audit-Ready Evidence Repository

Effective compliance requires a centralized, searchable evidence management system. Security teams should maintain:

  • Control matrices mapping SAMA requirements to implemented controls
  • Automated evidence collection from tools (SIEM, vulnerability scanners, identity and access management platforms)
  • Timestamped documentation of control execution and effectiveness testing
  • Third-party assessment reports (penetration tests, security audits, SOC 2 Type II certifications)
  • Incident logs and post-incident reviews with demonstrable improvements
  • Training records and security awareness metrics

SAMA and the National Cybersecurity Authority increasingly conduct unannounced or targeted assessments. Institutions that maintain real-time, auditable evidence repositories can respond quickly and credibly to information requests, reducing friction during regulatory engagements.

Practical Next Steps

Security leaders should conduct a control-by-control gap assessment against the current SAMA CSF, identify missing evidence, and establish automated collection processes. Engage audit and compliance teams early to align on evidence standards. Consider engaging independent assessors to validate maturity levels before regulatory review. Finally, embed evidence collection into operational workflows rather than treating it as a retrospective compliance exercise.

The regulatory environment in Saudi Arabia now rewards institutions that treat cybersecurity evidence as a strategic asset, not a burden. Those who do will navigate audits with confidence and demonstrate genuine resilience to the National Cybersecurity Authority and the market.