Understanding SAMA's Current Cyber Security Framework

The Saudi Central Bank (SAMA) Cyber Security Framework remains the foundational regulatory requirement for all financial institutions, payment service providers, and digital banking operators in Saudi Arabia. Unlike prescriptive checklists, the framework demands that organizations demonstrate a risk-based, layered approach to protecting critical financial infrastructure and customer data.

The framework aligns with international standards—particularly ISO/IEC 27001:2022 and NIST CSF 2.0—while reflecting Saudi Arabia's regulatory priorities under the National Cybersecurity Authority (NCA) and the Saudi Personal Data Protection Law (PDPL). Financial institutions must evidence not just technical controls, but governance maturity, board-level oversight, and continuous risk assessment.

Core Pillars You Must Evidence

1. Governance and Risk Management

SAMA expects a documented cybersecurity strategy approved by the board or equivalent authority. Security leaders must provide:

  • Board meeting minutes confirming cyber risk oversight at least quarterly
  • A formal risk register mapping threats to business impact and mitigation owners
  • A cybersecurity policy framework covering incident response, access control, and third-party risk
  • Evidence of annual risk assessments aligned to SAMA's asset criticality tiers

The framework requires explicit accountability: designate a Chief Information Security Officer (CISO) or equivalent role with direct reporting to senior management, not buried in IT operations.

2. Incident Response and Business Continuity

SAMA mandates a tested incident response plan with defined escalation, communication, and recovery procedures. Evidence should include:

  • Documented incident response procedures with roles, contact lists, and decision trees
  • Records of tabletop exercises or simulations conducted within the past 12 months
  • A recovery time objective (RTO) and recovery point objective (RPO) for all critical systems
  • Backup and disaster recovery test results, with evidence of successful restoration
  • Notification protocols compliant with PDPL breach disclosure timelines (typically 30 days)

SAMA also requires evidence that incident response capabilities are tested with external parties (e.g., payment networks, regulators) where applicable.

3. Technical and Operational Controls

The framework mandates layered technical defenses. Provide evidence of:

  • Network segmentation isolating critical financial systems from general corporate networks
  • Multi-factor authentication for all privileged accounts and remote access
  • Encryption in transit (TLS 1.2 minimum) and at rest for sensitive data
  • Vulnerability management: regular scans, patch timelines, and remediation tracking
  • Security monitoring via a Security Operations Center (SOC) or managed security service provider (MSSP), with 24/7 alerting for critical events
  • Endpoint Detection and Response (EDR) or equivalent on all user and server devices

Auditors will request logs, configuration baselines, and patch deployment records. Ensure your tools generate audit trails that survive at least 90 days of retention.

4. Third-Party and Supply Chain Risk

SAMA recognizes that outsourced services (cloud, payment processors, vendors) introduce risk. Document:

  • A vendor assessment checklist covering security certifications (ISO 27001, SOC 2 Type II)
  • Contractual clauses mandating security standards, audit rights, and breach notification
  • Annual reviews of critical third-party controls and compliance status
  • Evidence of security incident reporting from vendors within agreed timelines

5. Awareness and Training

SAMA expects a security-aware workforce. Provide:

  • Mandatory annual security training records for all staff, with completion rates above 90%
  • Phishing simulation results and remedial training for high-risk groups
  • Role-specific training for system administrators, developers, and customer-facing staff

How to Organize Your Evidence

Create a SAMA compliance evidence repository organized by framework pillar. Use a simple matrix mapping each requirement to:

  • Policy reference
  • Responsible owner
  • Last review date
  • Evidence artifact (e.g., "SOC monitoring dashboard snapshot, Q3 2026")
  • Audit trail or log reference

Keep evidence current: refresh risk assessments annually, update policies when threats or business model changes, and maintain a rolling 12-month archive of incident response drills and vulnerability reports.

Closing Thought

SAMA's framework is not a one-time compliance checkbox. It is a living governance model that requires continuous demonstration of risk awareness, technical rigor, and board accountability. Financial institutions that treat cybersecurity as a strategic business function—not a cost center—will evidence compliance naturally and build resilience against the evolving threat landscape.