SAMA's Mandatory Framework: Current Scope and Expectations

The Saudi Central Bank's Cyber Security Framework (SAMA CSF) establishes binding security requirements for all licensed financial institutions, including banks, insurance firms, and fintech operators. Unlike advisory guidelines, SAMA CSF provisions carry regulatory force and are enforced through the National Cybersecurity Authority (NCA) and SAMA's own supervisory examinations.

As of 2026, the framework aligns with international standards—notably ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0—while reflecting Saudi Arabia's unique risk landscape and the priorities set by the National Cybersecurity Strategy. Financial institutions must treat SAMA CSF compliance not as a checkbox exercise but as a foundational operating requirement.

Core Pillars: What You Must Demonstrate

1. Governance and Risk Ownership

SAMA expects a documented governance structure in which the Board and senior management visibly own cybersecurity risk. This means:

  • A Board-level Audit or Risk Committee with explicit cybersecurity oversight
  • A Chief Information Security Officer (CISO) or equivalent role with direct access to the Chief Executive Officer and Board
  • Written cybersecurity strategy and annual risk appetite statements approved by the Board
  • Quarterly Board reporting on material incidents, vulnerabilities, and remediation status

Evidence: Board minutes, CISO appointment letters, charter documents, and a three-year cybersecurity roadmap signed by the CEO and Board Chair.

2. Risk Assessment and Asset Management

SAMA mandates annual enterprise-wide cybersecurity risk assessments covering all systems, data, and third-party dependencies. The assessment must identify critical assets, map data flows, and quantify residual risk.

  • Document all systems and their criticality classification
  • Maintain an up-to-date asset inventory with ownership and risk ratings
  • Perform threat modeling for payment systems, customer data repositories, and core banking platforms
  • Assess supply chain and third-party vendor risks, especially for cloud and outsourced services

Evidence: Risk registers, asset inventories with last-updated dates, third-party risk assessments, and a signed annual risk report.

3. Technical Controls and Segmentation

SAMA CSF requires implementation of controls aligned with the NCA's Essential Cybersecurity Controls (ECC). Key technical evidence includes:

  • Multi-factor authentication for all administrative and remote access
  • Network segmentation isolating critical systems (e.g., payment processing) from general office networks
  • Encryption of data in transit (TLS 1.2 or higher) and at rest for sensitive data
  • Endpoint detection and response (EDR) or equivalent monitoring on all user devices and servers
  • Web application firewalls and intrusion prevention systems protecting customer-facing platforms

Evidence: Configuration baselines, firewall rules with review dates, encryption key management documentation, and EDR deployment logs.

4. Incident Response and Business Continuity

SAMA requires a tested, documented incident response plan and business continuity procedures. You must demonstrate:

  • A written incident response playbook with defined roles, escalation paths, and communication protocols
  • Annual tabletop exercises or simulations involving senior management and the Board
  • Recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical services
  • Regular backup testing and restoration drills with documented results
  • A 72-hour incident notification process to SAMA and affected customers

Evidence: Signed incident response procedures, exercise reports with attendee lists, backup test logs, and a communication template for SAMA notification.

5. Compliance with Saudi PDPL and Data Protection

The Personal Data Protection Law (PDPL) and its implementing regulations require that financial institutions safeguard customer data. SAMA CSF incorporates PDPL expectations:

  • Data classification and retention policies aligned with PDPL requirements
  • Documented consent mechanisms for data processing
  • Data subject access and deletion procedures
  • Privacy impact assessments for new systems or services

Evidence: Data governance policies, consent logs, and a privacy register maintained by your Data Protection Officer.

Building Your Evidence Portfolio

SAMA and NCA examiners expect a coherent, time-stamped evidence trail. Maintain a central compliance repository containing:

  • Board resolutions and minutes
  • Risk assessments and remediation tracking
  • Control testing reports and audit findings
  • Incident logs and post-incident reviews
  • Training and awareness records
  • Third-party audit reports (SOC 2, ISO 27001 certifications)

Document the date of last review for every policy and control. SAMA expects annual updates, and gaps in currency invite scrutiny.

Practical Next Steps

If your institution is not yet fully aligned, prioritize: (1) Board governance and CISO empowerment, (2) a current risk assessment, (3) critical technical controls (MFA, segmentation, EDR), and (4) a tested incident response plan. Each step should be documented and communicated to the Board.

Engage an external auditor familiar with SAMA CSF and NCA ECC to benchmark your current state, then build a 12-month roadmap with clear ownership and milestones. Compliance is not a one-time project—it is a continuous discipline that protects your institution and your customers.