Saudi Arabia's financial sector operates under one of the region's most demanding cybersecurity regulatory environments. The Saudi Arabian Monetary Authority's Cybersecurity Framework (SAMA CSF) sets out specific security
Saudi Arabia's financial sector operates under one of the region's most demanding cybersecurity regulatory environments. The Saudi Arabian Monetary Authority's Cybersecurity Framework (SAMA CSF) sets out specific security requirements for every organisation it regulates from major commercial banks to insurance companies, fintech firms, and currency exchange houses. Understanding what it requires, and where most institutions fall short, is the starting point for a credible compliance programme.
What Is the SAMA Cybersecurity Framework?
TheSAMA Cybersecurity Framework is a mandatory regulatory standard published by the Saudi Central Bank (SAMA) for all organisations under its regulatory authority. It provides a structured set of cybersecurity controls organised around five functions: Govern, Identify, Protect, Detect, and Respond & Recover.
The framework draws on international standards including NIST CSF, ISO 27001, and PCI-DSS but includes Saudi-specific regulatory requirements that make direct comparison with those standards imperfect. Compliance with ISO 27001 provides a strong foundation but does not automatically satisfy all SAMA CSF requirements.
Who Must Comply?
All entities regulated by SAMA are in scope, including:
• Commercial and investment banks
• Insurance and reinsurance companies
• Finance companies
• Payment service providers and fintechs
• Currency exchange houses
• Mortgage companies
Foreign bank branches operating in Saudi Arabia must comply with the SAMA CSF for their Saudi operations."
The Five SAMA CSF Functions Govern
Establish the cybersecurity leadership structures, policies, and governance mechanisms that make security a board-level priority. This includes appointing a qualified CISO, maintaining an approved cybersecurity strategy, and ensuring board oversight of cyber risk. Many institutions treat this as a documentation exercise.
SAMA auditors
look for evidence of active board engagement not just signed policies.Identify Understand and document your organisation's assets, risks, and vulnerabilities. Asset inventories, risk registers, and third-party risk assessments are the core requirements. The quality of your risk identification directly determines the relevance of every other control you implement.
Protect
Implement the controls that prevent security incidents: identity and access management, data encryption, application security, network security, and employee security awareness training. This is where most technical investment sits — and where configuration gaps most commonly create regulatory exposure.
Detect
Establish monitoring and detection capabilities: SIEM deployment, security log management, vulnerability scanning, and user behaviour monitoring. Many Saudi financial institutions have deployed SIEM tools but lack the tuning and operational capability to turn alert volume into actionable detection.
Respond & Recover
Incident response planning, business continuity, and disaster recovery. SAMA requires documented, tested plans not theoretical documents. The gap between what is written and what would actually happen during a real incident is the most consequential compliance weakness most institutions carry.
What SAMA Auditors Actually Look For
Based on published guidance and commonly reported audit findings, SAMA auditors assess:
• Evidence of board-level cybersecurity oversight (not just CISO reports)
• Active, current asset inventories not spreadsheets that were last updated eighteen months ago
• Third-party risk assessments for critical vendors
• Documented and tested incident response exercises
• Staff training completion records and awareness programme metrics
• SIEM operational effectiveness, not just deployment
Common SAMA CSF Compliance Gaps
• CISO role filled by someone without dedicated security expertise
• Risk assessments conducted once and not reviewed
• Third-party vendors not subject to consistent security due diligence
• Security awareness training annual-only, with no ongoing reinforcement
• Incident response plans that have never been tested with realistic scenarios
• SIEM deployed but generating unreviewed alerts"
SAMA CSF vs NCA ECC: Understanding the Relationship
Financial institutions must address both the SAMA CSF and the NCA Essential Cybersecurity Controls. The frameworks overlap significantly both share governance, access control, monitoring, and incident response requirements. A well-structured compliance programme can address both frameworks in an integrated way, reducing duplication of effort. However, the SAMA CSF includes sector-specific financial controls that the NCA ECC does not fully replicate.
📊 Sharp Innovatech supports Saudi financial institutions with SAMA CSF gap assessments, remediation planning, and audit preparation. Contact our GRC team to discuss your compliance position.
Practical Next Steps
If your institution has not conducted a formal SAMA CSF gap assessment in the last twelve months, that is the appropriate starting point. The assessment establishes an objective baseline, identifies the highest-priority remediation actions, and produces the documentation structure needed for regulatory review.
Organisations that treat SAMA compliance as a genuinely operational security programme rather than an audit-passing exercise typically find that it produces real security improvements alongside regulatory compliance. That is the intended outcome.
FAQs
Q1: What is the SAMA Cybersecurity Framework?
A: The SAMA Cybersecurity Framework (CSF) is a mandatory security standard issued by Saudi Arabia's Central Bank for all SAMA-regulated organisations. It covers five functions Govern, Identify, Protect, Detect, and Respond & Recover and sets specific cybersecurity requirements for Saudi financial institutions.
Q2: Is ISO 27001 sufficient for SAMA CSF compliance?
A: No. ISO 27001 provides a strong foundation and reduces the gap significantly, but SAMA CSF includes Saudi-specific regulatory requirements that go beyond the international standard. A separate SAMA CSF gap assessment is necessary even for ISO 27001-certified organisations.
Q3: How often does SAMA audit cybersecurity compliance?
A: SAMA conducts regular supervisory reviews of regulated institutions. The frequency depends on the institution's size, risk profile, and prior compliance history. Organisations should maintain a continuous compliance posture rather than preparing only for scheduled audits.
Q4: What are the consequences of SAMA CSF non-compliance?
A: Consequences can include regulatory notices, required remediation programmes, enhanced supervisory attention, and — in serious cases — impacts on operating licences. SAMA has strengthened enforcement of cybersecurity requirements in recent years.
Q5: Can SAMA CSF and NCA ECC compliance be addressed together?
A: Yes, and it is more efficient to do so. The two frameworks share significant control overlap. An integrated compliance programme can address both simultaneously, reducing duplication and producing better-structured security documentation.




