Understanding SAMA's Current Cyber Security Framework
The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework remains the cornerstone of financial sector resilience in the Kingdom. Unlike advisory guidance, SAMA's framework imposes binding obligations on all regulated financial institutions—banks, insurance companies, and payment service providers. The framework aligns with international standards including NIST CSF 2.0 principles while reflecting Saudi Arabia's regulatory environment and the oversight role of the National Cybersecurity Authority (NCA).
SAMA expects institutions to implement a risk-based approach to cybersecurity governance, with board-level accountability, documented policies, and measurable controls. The framework encompasses five core pillars: identify, protect, detect, respond, and recover. Critically, SAMA does not merely require the existence of controls—it demands evidence that controls are designed, implemented, tested, and continuously improved.
Building a Compliance Evidence Framework
Meeting SAMA expectations begins with systematic evidence collection. Security leaders should establish a centralized control register that maps each SAMA requirement to:
- Policy documentation—board-approved policies, procedures, and standards that define how each control operates
- Design evidence—architecture diagrams, system configurations, and access control matrices showing how controls are built into systems
- Implementation proof—deployment logs, configuration reviews, and system screenshots confirming controls are active
- Testing results—penetration tests, vulnerability scans, control effectiveness assessments, and audit findings
- Monitoring and metrics—dashboards, SOC reports, and KPIs demonstrating continuous control operation
- Remediation records—evidence of how identified gaps were closed and when
This evidence should be organized by control domain—governance, risk management, asset management, access control, data protection, incident response, and business continuity. Each domain should have a documented owner accountable for maintaining evidence currency.
Aligning with NCA Oversight and PDPL Requirements
The National Cybersecurity Authority (NCA) now coordinates cybersecurity enforcement across Saudi Arabia, including oversight of financial sector compliance. Institutions must ensure SAMA evidence also satisfies NCA expectations for critical infrastructure protection and incident reporting under the Saudi Personal Data Protection Law (PDPL) and its implementing regulations.
Key alignment points include:
- Incident response plans must address NCA notification timelines and PDPL breach disclosure requirements
- Data inventory and classification must comply with PDPL principles for personal data handling
- Third-party risk assessments should verify vendor compliance with both SAMA and NCA standards
- Security awareness training must cover PDPL obligations and NCA guidance on insider threats
Practical Steps for 2026 Compliance
Conduct a control maturity assessment. Map your current state against SAMA's framework. Use a maturity model (initial, developing, defined, managed, optimized) to identify gaps and prioritize remediation.
Establish a compliance calendar. Schedule annual control testing, policy reviews, and board reporting. SAMA expects evidence refreshed at least annually, with critical controls tested more frequently.
Implement a GRC platform. Use governance, risk, and compliance software to centralize evidence storage, automate testing workflows, and generate audit-ready reports. This reduces manual effort and improves consistency.
Engage internal audit and external advisors. Independent validation of control design and operating effectiveness strengthens evidence credibility. External auditors familiar with SAMA expectations provide valuable perspective.
Document the control environment. SAMA reviewers expect to see clear ownership, escalation paths, and decision-making authority. Org charts, RACI matrices, and governance charters should be current and accessible.
Looking Ahead
SAMA's framework is not static. Institutions should monitor NCA guidance and international standard updates (such as ISO/IEC 27001:2022 and emerging AI governance frameworks like ISO/IEC 42001) to stay ahead of evolving expectations. Compliance is a continuous journey, not a checkpoint. Leaders who treat evidence collection as an ongoing operational discipline—rather than an annual audit exercise—will demonstrate resilience and earn SAMA's confidence.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment