Framework · Financial sector · Saudi Arabia

SAMA CSF compliance: domains, maturity levels and evidence

SAMA CSF compliance means meeting the Cyber Security Framework of the Saudi Central Bank for banks, insurers and finance companies it regulates. The framework sets controls in four domains and measures them on a 0 to 5 maturity scale, with level 3, structured and formalised, as the expected minimum.

Key takeaways

What you need to know about SAMA CSF

Maturity, not checkboxesEach area is rated on a 0–5 scale; level 3 is the floor.
Board-ownedA cyber security committee and the board own cyber risk.
Independent CISOThe cyber security function is separate from IT.
Third parties countOutsourcing and cloud have their own domain.
Works with NCANCA ECC can apply on top for critical infrastructure.

Who must comply with SAMA CSF?

Financial institutions regulated by the Saudi Central Bank.

BanksAll banks operating in Saudi Arabia.
Insurers and reinsurersInsurance and reinsurance companies.
Finance companiesConsumer and corporate finance companies.
Payment and fintech firmsWhere SAMA regulation applies.
Their suppliersThrough contract and outsourcing requirements.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the framework requires

What does SAMA CSF require?

SAMA CSF requires board-led cyber security governance, a managed risk and compliance process, operational and technical controls, and third-party security, each operating at maturity level 3 or higher.

3.1 Lead

Leadership and governance

Committee, strategy, policy, CISO, awareness.

In QULDEX: Governance evidence mapped
3.2 Assure

Risk management and compliance

Risk, compliance, reviews and audits.

In QULDEX: Risk register and audits
3.3 Operate

Operations and technology

Assets, access, apps, crypto, monitoring, incidents.

In QULDEX: Controls mapped to ISO 27001
3.4 Third parties

Third-party security

Contracts, outsourcing, cloud.

In QULDEX: Vendor register
0–5 Mature

Maturity model

Level 3 minimum per area.

In QULDEX: Maturity rating per area
Control area explorer

Which SAMA CSF control areas matter most?

These 22 control areas carry most of the work, grouped by domain. Select any area to see what it asks for, typical evidence and the matching ISO 27001 or NCA ECC reference.

2017framework issued
4domains
0–5maturity scale
3minimum level

Showing up to 6 per group. Search, filter, or open a group to see all 22.

Leadership and governance 6

  1. 3.1.1Cyber security governance

    A cyber security committee and board oversight, with the board accountable for cyber risk.

    In QULDEXCommittee charters and minutes are evidence.

    Typical evidence
    Committee charter, minutes
    Maps to
    NCA ECC 1-2

  2. 3.1.2Cyber security strategy

    An approved cyber security strategy aligned with business objectives.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Approved strategy
    Maps to
    NCA ECC 1-1

  3. 3.1.3Cyber security policy

    An approved cyber security policy, communicated and reviewed periodically.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Approved policy
    Maps to
    ISO 27001 A.5.1

  4. 3.1.4Roles and responsibilities

    Defined roles including a CISO and the cyber security function, independent from IT.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Organisation chart
    Maps to
    ISO 27001 5.3

  5. 3.1.5Cyber security in project management

    Cyber security built into project and change management.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Project reviews

  6. 3.1.6Awareness and training

    Awareness programmes and training for staff and management.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Training records
    Maps to
    ISO 27001 A.6.3

Risk management and compliance 5

  1. 3.2.1Cyber security risk management

    Identify, analyse, respond to and monitor cyber security risks.

    In QULDEXThe risk register holds assessments and treatments.

    Typical evidence
    Risk register
    Maps to
    ISO 27001 6.1

  2. 3.2.2Regulatory compliance

    Comply with SAMA requirements and national regulation.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Compliance register

  3. 3.2.3Compliance with international standards

    Align with relevant standards such as PCI DSS and SWIFT CSP where applicable.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Certificates and reports
    Maps to
    PCI DSS

  4. 3.2.4Cyber security review

    Periodic cyber security reviews and testing.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Review reports

  5. 3.2.5Cyber security audits

    Independent audits of the cyber security framework.

    In QULDEXAudits run in the audit workspace with findings into CAPA.

    Typical evidence
    Audit reports
    Maps to
    ISO 27001 9.2

Operations and technology 7

  1. 3.3.3Asset management

    An inventory and classification of information assets.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Asset inventory
    Maps to
    ISO 27001 A.5.9

  2. 3.3.5Identity and access management

    Least privilege, MFA and periodic access reviews.

    In QULDEXAccess reviews run as recurring tasks.

    Typical evidence
    Access reviews
    Maps to
    ISO 27001 A.5.15–A.5.18

  3. 3.3.6Application security

    Security across the application lifecycle.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Secure SDLC evidence
    Maps to
    ISO 27001 A.8.25–A.8.29

  4. 3.3.9Cryptography

    Approved cryptographic standards and key management.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Crypto standard
    Maps to
    ISO 27001 A.8.24

  5. 3.3.14Security event management

    Monitoring and a security operations capability.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    SOC reports
    Maps to
    ISO 27001 A.8.16

  6. 3.3.15Incident management

    Detect, respond to and report incidents, including to SAMA.

    In QULDEXIncidents carry SAMA reporting timers.

    Typical evidence
    Incident reports
    Maps to
    ISO 27001 A.5.24–A.5.26

  7. 3.3.17Vulnerability management

    Find and fix technical vulnerabilities on time.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Scan reports
    Maps to
    ISO 27001 A.8.8

Third-party security 3

  1. 3.4.1Contract and vendor management

    Cyber security requirements in contracts and vendor oversight.

    In QULDEXEach vendor is assessed and linked to its services.

    Typical evidence
    Vendor assessments
    Maps to
    ISO 27001 A.5.19–A.5.22

  2. 3.4.2Outsourcing

    Cyber security for outsourced services, following SAMA outsourcing rules.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Outsourcing register

  3. 3.4.3Cloud computing

    Cyber security for cloud services, including data location requirements.

    In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.

    Typical evidence
    Cloud assessments
    Maps to
    NCA CCC

Maturity model 1

  1. Level 3Maturity level 3 minimumMaturity

    SAMA expects member organisations to reach at least level 3 ("structured and formalised") on the 0–5 maturity scale.

    In QULDEXQULDEX records a maturity level per control area with evidence.

    Typical evidence
    Maturity self-assessment

Section numbers follow the SAMA Cyber Security Framework v1.0. Summaries are QULDEX paraphrases; the SAMA document is the authority.

Compliance path

How do you reach SAMA CSF maturity level 3?

Assess your current maturity per control area, close the gaps to level 3, then keep the evidence current for SAMA reviews. Most institutions need 6 to 12 months to lift weak areas.

  1. Self-assess maturity

    Rate each control area from 0 to 5 with evidence.

  2. Fix governance first

    Committee, strategy, policy and an independent CISO.

    1–2 monthsRisk register →
  3. Lift weak areas to level 3

    Document, approve, communicate and apply controls consistently.

  4. Third parties and cloud

    Contracts, outsourcing approvals and cloud assessments.

  5. Independent audit

    Audit the framework and track findings.

  6. Keep it current

    YearlyMaturity self-assessment
    PeriodicIndependent audit
    Every incidentReport to SAMA

Durations are QULDEX planning ranges.

Records to keep

Which documents does SAMA CSF need?

SAMA reviewers expect these records.

DocumentAreaWhere it lives in QULDEX
Cyber security committee charter and minutes3.1.1Policy library
Cyber security strategy and policy3.1.2–3.1.3Policy library
CISO appointment3.1.4Policy library
Risk register3.2.1Risk register
Audit reports3.2.5Audit workspace
Asset inventory3.3.3Risk register
Access reviews3.3.5Evidence vault
Incident reports3.3.15CAPA automation
Vendor and outsourcing assessments3.4Vendor register
Maturity self-assessmentMaturity modelAudit workspace

Section numbers follow SAMA CSF v1.0.

Time and cost

How long does SAMA CSF take and what drives the effort?

Most institutions need 6 to 12 months to bring every area to level 3. The number of weak areas and third-party arrangements drive the effort.

Where the time goes

Self-assessment3–6 wk
Governance1–2 mo
Lifting areas3–8 mo
Third parties1–3 mo
Audit1–2 mo

Bars show the upper end of each range on one scale (12 months = full width).

What changes the effort

  • Starting maturity: areas at level 1 take longest
  • Outsourcing: each arrangement needs review
  • Cloud use: adds data location checks
  • Existing ISO 27001: covers much of domain 3
  • NCA scope: ECC may apply too
Readiness check · 2 minutes

How ready are you for SAMA CSF?

Check these eight things first. Nothing you enter leaves this page.

3.1.1Does a cyber security committee report to the board?
3.1.4Is there an independent CISO and cyber security function?
3.2.1Is cyber risk assessed and treated?
3.3.5Are access rights reviewed and MFA in place?
3.3.14Do you monitor security events?
3.3.15Can you report incidents to SAMA on time?
3.4.2Are outsourcing arrangements approved and assessed?
Level 3Have you rated every area against the maturity scale?
Crosswalk

How SAMA CSF maps to NCA ECC, ISO 27001 and PCI DSS

SAMA CSF is the financial-sector framework; NCA ECC sets national controls, and ISO 27001 and PCI DSS evidence overlaps with both.

SAMA crosswalk

SAMA CSFNCA ECC-2:2024ISO 27001:2022PCI DSS v4.0.1Shared evidence
3.1.1 Governance1-25.112.4Committee minutes
3.2.1 Risk1-56.112.3Risk register
3.3.5 Access2-2A.5.15–A.5.187, 8Access reviews
3.3.9 Crypto2-8A.8.243, 4Crypto standard
3.3.14 Monitoring2-12A.8.1610SOC reports
3.3.15 Incidents2-13A.5.24–A.5.2612.10Incident reports
3.4 Third parties4-1A.5.19–A.5.2212.8Vendor register

Indicative mapping for planning. The full crosswalk is in the QULDEX control library.

Where QULDEX fits

How QULDEX runs SAMA CSF from maturity rating to audit

QULDEX is SAMA CSF compliance and audit management software built from EGV Group's audit delivery, used by financial institutions, their advisors and the auditors who test them. Pick your role to see who does what.

For banks, insurers and finance companies.

  1. AssessRate maturityMaturity per area with evidence
  2. GovernSet the committeeCharters and minutes recorded
  3. OperateLift areas to level 3Controls mapped to evidence
  4. VendorsAssess third partiesVendor and outsourcing register
  5. IncidentsReport to SAMAIncident timers
  6. AuditHost the auditControlled evidence sharing
Without one systemWith QULDEX
Maturity rated in a spreadsheetMaturity per area with evidence
Board told once a yearCommittee minutes and reports on record
Outsourcing approvals scatteredOne outsourcing register
SAMA and NCA evidence kept twiceOne control set mapped to both
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

SAMA CSF questions people ask

What is the SAMA Cyber Security Framework?

The cyber security framework the Saudi Central Bank issued in 2017 for the financial institutions it regulates. It sets controls in four domains and measures them on a 0–5 maturity scale.

What maturity level does SAMA expect?

At least level 3, "structured and formalised", meaning controls are documented, approved, communicated and consistently applied.

What are the four SAMA CSF domains?

Cyber security leadership and governance; cyber security risk management and compliance; cyber security operations and technology; and third-party cyber security.

Do NCA ECC and SAMA CSF both apply?

They can. SAMA CSF applies to SAMA-regulated institutions; NCA ECC applies to government and critical infrastructure organisations, which can include financial institutions. Most evidence overlaps.

How long does it take to reach level 3?

Most institutions need 6 to 12 months, depending on how many areas start below level 3.

Sources

References

  1. Saudi Central Bank (SAMA), Cyber Security Framework v1.0, May 2017. sama.gov.sa
  2. SAMA Rules on Outsourcing. sama.gov.sa
  3. National Cybersecurity Authority, ECC-2:2024. nca.gov.sa
  4. ISO/IEC 27001:2022. iso.org

Reviewed by

Swati Chaturvedi

Framework reviewer · QULDEX

Reviewed this page against the SAMA Cyber Security Framework: domains, maturity model and evidence.

Page history
  • : Page first built: control area explorer, maturity model and readiness check

Find the areas below SAMA level 3

Answer a short readiness check and get a gap summary by domain. No sales call needed to see the result.

Schedule
Book a Demo