Asurvo
Regional framework

Run SAMA CSF with
confidence.

The SAMA Cyber Security Framework enables financial institutions regulated by the Saudi Central Bank (SAMA) to identify and address cyber security risks. Institutions are assessed against a 0–5 maturity model and must operate at maturity level 3 or higher.

Who it's for

Banks, insurers, and financial institutions regulated by SAMA.

Scope

Maturity-based control domains

Category
Regional

How Asurvo helps

What you get for SAMA CSF.

0–5 cyber security maturity model
Maturity level 3+ target tracking
Domain and subdomain control mapping
Built for SAMA-regulated entities

Saudi financial sector

Reaching and sustaining maturity Level 3 under the SAMA framework

The SAMA Cyber Security Framework was issued in 2017 by the Saudi Arabian Monetary Authority, now the Saudi Central Bank (it kept the SAMA acronym). Version 1.0 applies to organizations SAMA regulates, including banks, insurance and reinsurance companies, finance companies, and credit bureaus. Its purpose is to give the sector a common way to identify and address cyber risk, and to let SAMA measure each institution's cyber security maturity consistently.

Principles, not a checklist

The framework is principle-based. Each subdomain states a principle, an objective, and control considerations that describe what a mature institution should have in place. That means there is interpretation involved: two institutions can meet the same control consideration differently, but both need documentation and evidence showing the consideration is defined, approved, implemented, and monitored.

The four domains

Domain, Representative subdomains comparison
1. Cyber Security Leadership and GovernanceGovernance, strategy, policy, roles and responsibilities, cyber security in project management, awareness and training
2. Cyber Security Risk Management and ComplianceRisk management, regulatory compliance, alignment with international standards, cyber security review and audit
3. Cyber Security Operations and TechnologyHuman resources, physical security, asset management, architecture, identity and access management, application and infrastructure security, change management, cryptography, event, incident, threat and vulnerability management
4. Third-Party Cyber SecurityContract and vendor management, outsourcing, cloud computing

Domain 3 contains the largest number of subdomains and usually the most remediation work. Domain 1 is where many institutions are surprised: SAMA expects a board-approved strategy, a cyber security committee, and a function with independence from IT operations.

The maturity model

Level, Name, What it looks like comparison
0Non-existentNo documented or implemented controls for the consideration
1Ad-hocSome controls exist but are inconsistent and undocumented
2Repeatable but informalControls are applied repeatedly but not formally defined or approved
3Structured and formalizedControls are documented, approved, implemented, and their operation can be evidenced
4Managed and measurableEffectiveness is measured and periodically evaluated, with improvement actions
5AdaptiveControls are continuously improved based on metrics, threat changes, and lessons learned

A path from self-assessment to Level 3

  1. Baseline every subdomain. Score current maturity per control consideration with evidence references, not interviews alone.
  2. Fix governance first. Board-approved strategy, committee charter, defined roles, and a policy framework unlock Level 3 across many subdomains at once.
  3. Formalize procedures for operational areas like access management, change management, vulnerability management, and incident response.
  4. Generate operating evidence: review records, tickets, logs, and test results that show procedures actually run.
  5. Extend to third parties: contract clauses, outsourcing and cloud assessments, and ongoing supplier monitoring.
  6. Independently review, through internal audit or an external reviewer, and track findings to closure before reporting to SAMA.

Evidence that supports a Level 3 score

  • Board-approved cyber security strategy and policy set, with version history and approval records
  • Cyber security committee charter and minutes showing decisions and follow-up
  • Cyber risk methodology and a maintained risk register with treatment owners
  • Asset inventory tied to data classification
  • Access reviews, privileged access records, and joiner-mover-leaver evidence
  • Vulnerability scans, penetration test reports, and remediation tracking
  • Incident response plan with exercise results and incident records
  • Third-party contracts with cyber security clauses and completed vendor assessments
  • Awareness program content and completion records

Where institutions lose maturity points

  • Policies drafted but never approved at the level the framework expects, which caps the subdomain below Level 3.
  • Evidence that shows a control running once rather than consistently over the review period.
  • Treating cloud and outsourcing arrangements as procurement matters without cyber security assessment.
  • Self-assessment scores that reviewers cannot trace back to evidence.
  • Aiming only for Level 3 on paper, then slipping back when staff change because nothing is measured.

Institutions in Saudi Arabia often also track other national requirements, such as the National Cybersecurity Authority's Essential Cybersecurity Controls where applicable, and many align with ISO 27001 and PCI DSS for card operations. Asurvo tracks SAMA CSF maturity per domain and subdomain against the Level 3 target, cross-maps it to ISO 27001 and other frameworks, and keeps policy approvals, the risk register, and vendor assessments connected to the controls they evidence. More on the sector at fintech.

FAQ

Frequently asked questions

Who must comply with the SAMA Cyber Security Framework?

It applies to financial institutions regulated by the Saudi Central Bank, including banks, insurance and reinsurance companies, finance companies, and credit bureaus. Service providers to those institutions are not directly regulated by it, but they commonly receive its requirements through contracts, outsourcing rules, and vendor assessments carried out by the regulated institution.

What maturity level does SAMA require?

SAMA expects member organizations to reach at least maturity Level 3, structured and formalized, on its 0 to 5 scale. At Level 3, controls are documented, approved, implemented, and supported by evidence. Levels 4 and 5 add measurement of effectiveness and continuous improvement, which institutions may target for higher-risk areas.

Is SAMA still called the Saudi Arabian Monetary Authority?

No. The institution was renamed the Saudi Central Bank, but it retained the SAMA acronym, so the framework is still widely known as the SAMA Cyber Security Framework. Version 1.0 of the framework was issued in 2017 when the organization was still called the Saudi Arabian Monetary Authority.

How does the SAMA framework relate to ISO 27001?

The framework asks institutions to consider alignment with international standards, and many of its subdomains overlap with ISO 27001 topics such as governance, risk management, access control, and supplier security. ISO 27001 evidence is reusable, but SAMA's maturity scoring and specific control considerations, including sector topics like payment systems, require their own assessment.

What is the hardest part of reaching Level 3?

Usually formalization and consistency. Many institutions already perform controls informally, which scores Level 2. Reaching Level 3 requires approved documentation, clear ownership, and evidence that controls operate consistently over time. Governance items such as a board-approved strategy and an active committee often need to be established before operational subdomains can score at Level 3.

Ready to run SAMA CSF on Asurvo?

Book a walkthrough and see the framework live.