The SAMA Cyber Security Framework was issued in 2017 by the Saudi Arabian Monetary Authority, now the Saudi Central Bank (it kept the SAMA acronym). Version 1.0 applies to organizations SAMA regulates, including banks, insurance and reinsurance companies, finance companies, and credit bureaus. Its purpose is to give the sector a common way to identify and address cyber risk, and to let SAMA measure each institution's cyber security maturity consistently.
Principles, not a checklist
The framework is principle-based. Each subdomain states a principle, an objective, and control considerations that describe what a mature institution should have in place. That means there is interpretation involved: two institutions can meet the same control consideration differently, but both need documentation and evidence showing the consideration is defined, approved, implemented, and monitored.
The four domains
Domain 3 contains the largest number of subdomains and usually the most remediation work. Domain 1 is where many institutions are surprised: SAMA expects a board-approved strategy, a cyber security committee, and a function with independence from IT operations.
The maturity model
A path from self-assessment to Level 3
- Baseline every subdomain. Score current maturity per control consideration with evidence references, not interviews alone.
- Fix governance first. Board-approved strategy, committee charter, defined roles, and a policy framework unlock Level 3 across many subdomains at once.
- Formalize procedures for operational areas like access management, change management, vulnerability management, and incident response.
- Generate operating evidence: review records, tickets, logs, and test results that show procedures actually run.
- Extend to third parties: contract clauses, outsourcing and cloud assessments, and ongoing supplier monitoring.
- Independently review, through internal audit or an external reviewer, and track findings to closure before reporting to SAMA.
Evidence that supports a Level 3 score
- Board-approved cyber security strategy and policy set, with version history and approval records
- Cyber security committee charter and minutes showing decisions and follow-up
- Cyber risk methodology and a maintained risk register with treatment owners
- Asset inventory tied to data classification
- Access reviews, privileged access records, and joiner-mover-leaver evidence
- Vulnerability scans, penetration test reports, and remediation tracking
- Incident response plan with exercise results and incident records
- Third-party contracts with cyber security clauses and completed vendor assessments
- Awareness program content and completion records
Where institutions lose maturity points
- Policies drafted but never approved at the level the framework expects, which caps the subdomain below Level 3.
- Evidence that shows a control running once rather than consistently over the review period.
- Treating cloud and outsourcing arrangements as procurement matters without cyber security assessment.
- Self-assessment scores that reviewers cannot trace back to evidence.
- Aiming only for Level 3 on paper, then slipping back when staff change because nothing is measured.
Related requirements and how Asurvo helps
Institutions in Saudi Arabia often also track other national requirements, such as the National Cybersecurity Authority's Essential Cybersecurity Controls where applicable, and many align with ISO 27001 and PCI DSS for card operations. Asurvo tracks SAMA CSF maturity per domain and subdomain against the Level 3 target, cross-maps it to ISO 27001 and other frameworks, and keeps policy approvals, the risk register, and vendor assessments connected to the controls they evidence. More on the sector at fintech.