Understanding SAMA CSF Expectations in 2026
The Saudi Central Bank's Cyber Security Framework (SAMA CSF) remains the primary regulatory standard for financial institutions in the Kingdom. Unlike prescriptive checklists, SAMA CSF operates on a maturity-based model aligned with international standards including NIST CSF 2.0 and ISO/IEC 27001:2022. This means compliance is not about ticking boxes—it is about demonstrating that your organisation has implemented, tested, and continuously improved security controls proportionate to your risk profile.
SAMA expects financial institutions to adopt a risk-based approach, meaning control intensity should match the sensitivity of data handled and the criticality of services delivered. A payment processor faces different baseline expectations than a smaller regional lender, yet both must evidence their control decisions and their effectiveness.
Core Pillars of Evidence-Based Compliance
SAMA CSF compliance rests on four interconnected pillars:
- Governance and Risk Management: Board and senior management must demonstrate active oversight of cybersecurity strategy. This requires documented risk assessments, a formal cybersecurity policy approved by the board, and clear accountability for security outcomes. Evidence includes board minutes, risk registers updated at least annually, and incident response plans tested in the past 12 months.
- Technical and Operational Controls: Institutions must implement controls across asset management, access control, cryptography, and incident response. Evidence takes the form of system configurations, access control matrices, encryption key management records, and logs from security tools (firewalls, intrusion detection, endpoint protection).
- Third-Party and Supply Chain Security: Vendors and service providers handling financial data must be assessed and monitored. Evidence includes vendor risk assessments, contractual security clauses, audit reports from third parties, and ongoing monitoring dashboards.
- Incident Response and Resilience: Organisations must detect, respond to, and recover from security incidents. Evidence includes documented incident logs, post-incident reviews, business continuity test results, and disaster recovery drills conducted at least annually.
Alignment with NCA ECC and PDPL
SAMA CSF does not operate in isolation. The National Cybersecurity Authority's Essential Cybersecurity Controls (NCA ECC) provide a baseline of mandatory technical measures applicable across critical infrastructure and essential services. Financial institutions must satisfy both frameworks simultaneously.
Additionally, the Saudi Personal Data Protection Law (PDPL) and its implementing regulations require evidence of data protection by design, consent management, breach notification procedures, and data subject rights handling. Your cybersecurity evidence must explicitly address how you protect personal data in transit and at rest, and how you detect and report breaches within the regulatory timeframe.
Practical Steps to Build and Maintain Evidence
Documentation: Maintain a centralised repository of security policies, procedures, and change logs. Ensure all control implementations are documented with business justification, implementation date, and responsible owner.
Logging and Monitoring: Deploy security information and event management (SIEM) tools or equivalent log aggregation to capture authentication, authorisation, data access, and configuration changes. Retention must meet SAMA and PDPL requirements—typically a minimum of 12 months.
Testing and Validation: Conduct annual vulnerability assessments and penetration testing by qualified third parties. Document findings, remediation actions, and verification of fixes. This evidence demonstrates that controls are not just in place but effective.
Training and Awareness: Maintain records of security awareness training, phishing simulation results, and role-specific training for system administrators and data handlers. SAMA expects a security-conscious culture, not just technical controls.
Third-Party Audits: Engage external auditors to validate your control environment against SAMA CSF, NCA ECC, and ISO/IEC 27001:2022. Annual audits or assessments provide independent evidence of compliance maturity.
The Path Forward
SAMA CSF compliance in 2026 demands a shift from compliance theatre to genuine risk management. Security leaders must build an evidence trail that tells the story of their organisation's commitment to protecting financial stability and customer data. This requires investment in tools, training, and governance—but it also reduces operational risk and builds stakeholder confidence.
Start by mapping your current controls against SAMA CSF domains, identify gaps, and prioritise remediation based on risk. Then, systematically document what you have done, why you did it, and how you know it works. That evidence is your proof of compliance.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment