Framework · Financial sector · Saudi Arabia
SAMA CSF compliance means meeting the Cyber Security Framework of the Saudi Central Bank for banks, insurers and finance companies it regulates. The framework sets controls in four domains and measures them on a 0 to 5 maturity scale, with level 3, structured and formalised, as the expected minimum.
Financial institutions regulated by the Saudi Central Bank.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
SAMA CSF requires board-led cyber security governance, a managed risk and compliance process, operational and technical controls, and third-party security, each operating at maturity level 3 or higher.
Committee, strategy, policy, CISO, awareness.
In QULDEX: Governance evidence mappedRisk, compliance, reviews and audits.
In QULDEX: Risk register and auditsAssets, access, apps, crypto, monitoring, incidents.
In QULDEX: Controls mapped to ISO 27001Contracts, outsourcing, cloud.
In QULDEX: Vendor registerLevel 3 minimum per area.
In QULDEX: Maturity rating per areaThese 22 control areas carry most of the work, grouped by domain. Select any area to see what it asks for, typical evidence and the matching ISO 27001 or NCA ECC reference.
Showing up to 6 per group. Search, filter, or open a group to see all 22.
3.1.1Cyber security governanceA cyber security committee and board oversight, with the board accountable for cyber risk.
In QULDEXCommittee charters and minutes are evidence.
3.1.2Cyber security strategyAn approved cyber security strategy aligned with business objectives.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.1.3Cyber security policyAn approved cyber security policy, communicated and reviewed periodically.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.1.4Roles and responsibilitiesDefined roles including a CISO and the cyber security function, independent from IT.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.1.5Cyber security in project managementCyber security built into project and change management.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.1.6Awareness and trainingAwareness programmes and training for staff and management.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.2.1Cyber security risk managementIdentify, analyse, respond to and monitor cyber security risks.
In QULDEXThe risk register holds assessments and treatments.
3.2.2Regulatory complianceComply with SAMA requirements and national regulation.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.2.3Compliance with international standardsAlign with relevant standards such as PCI DSS and SWIFT CSP where applicable.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.2.4Cyber security reviewPeriodic cyber security reviews and testing.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.2.5Cyber security auditsIndependent audits of the cyber security framework.
In QULDEXAudits run in the audit workspace with findings into CAPA.
3.3.3Asset managementAn inventory and classification of information assets.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.3.5Identity and access managementLeast privilege, MFA and periodic access reviews.
In QULDEXAccess reviews run as recurring tasks.
3.3.6Application securitySecurity across the application lifecycle.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.3.9CryptographyApproved cryptographic standards and key management.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.3.14Security event managementMonitoring and a security operations capability.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.3.15Incident managementDetect, respond to and report incidents, including to SAMA.
In QULDEXIncidents carry SAMA reporting timers.
3.3.17Vulnerability managementFind and fix technical vulnerabilities on time.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.4.1Contract and vendor managementCyber security requirements in contracts and vendor oversight.
In QULDEXEach vendor is assessed and linked to its services.
3.4.2OutsourcingCyber security for outsourced services, following SAMA outsourcing rules.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
3.4.3Cloud computingCyber security for cloud services, including data location requirements.
In QULDEXQULDEX tracks this area with an owner, a maturity rating and evidence, and maps it to ISO 27001 and NCA ECC.
Level 3Maturity level 3 minimumMaturitySAMA expects member organisations to reach at least level 3 ("structured and formalised") on the 0–5 maturity scale.
In QULDEXQULDEX records a maturity level per control area with evidence.
Nothing matches that search.
Section numbers follow the SAMA Cyber Security Framework v1.0. Summaries are QULDEX paraphrases; the SAMA document is the authority.
Assess your current maturity per control area, close the gaps to level 3, then keep the evidence current for SAMA reviews. Most institutions need 6 to 12 months to lift weak areas.
Rate each control area from 0 to 5 with evidence.
Committee, strategy, policy and an independent CISO.
Document, approve, communicate and apply controls consistently.
Contracts, outsourcing approvals and cloud assessments.
Audit the framework and track findings.
Durations are QULDEX planning ranges.
SAMA reviewers expect these records.
| Document | Area | Where it lives in QULDEX |
|---|---|---|
| Cyber security committee charter and minutes | 3.1.1 | Policy library |
| Cyber security strategy and policy | 3.1.2–3.1.3 | Policy library |
| CISO appointment | 3.1.4 | Policy library |
| Risk register | 3.2.1 | Risk register |
| Audit reports | 3.2.5 | Audit workspace |
| Asset inventory | 3.3.3 | Risk register |
| Access reviews | 3.3.5 | Evidence vault |
| Incident reports | 3.3.15 | CAPA automation |
| Vendor and outsourcing assessments | 3.4 | Vendor register |
| Maturity self-assessment | Maturity model | Audit workspace |
Section numbers follow SAMA CSF v1.0.
Most institutions need 6 to 12 months to bring every area to level 3. The number of weak areas and third-party arrangements drive the effort.
Bars show the upper end of each range on one scale (12 months = full width).
Check these eight things first. Nothing you enter leaves this page.
SAMA CSF is the financial-sector framework; NCA ECC sets national controls, and ISO 27001 and PCI DSS evidence overlaps with both.
| SAMA CSF | NCA ECC-2:2024 | ISO 27001:2022 | PCI DSS v4.0.1 | Shared evidence |
|---|---|---|---|---|
| 3.1.1 Governance | 1-2 | 5.1 | 12.4 | Committee minutes |
| 3.2.1 Risk | 1-5 | 6.1 | 12.3 | Risk register |
| 3.3.5 Access | 2-2 | A.5.15–A.5.18 | 7, 8 | Access reviews |
| 3.3.9 Crypto | 2-8 | A.8.24 | 3, 4 | Crypto standard |
| 3.3.14 Monitoring | 2-12 | A.8.16 | 10 | SOC reports |
| 3.3.15 Incidents | 2-13 | A.5.24–A.5.26 | 12.10 | Incident reports |
| 3.4 Third parties | 4-1 | A.5.19–A.5.22 | 12.8 | Vendor register |
Indicative mapping for planning. The full crosswalk is in the QULDEX control library.
QULDEX is SAMA CSF compliance and audit management software built from EGV Group's audit delivery, used by financial institutions, their advisors and the auditors who test them. Pick your role to see who does what.
For banks, insurers and finance companies.
For SAMA CSF consultants and internal audit.
For independent cyber security auditors.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →The cyber security framework the Saudi Central Bank issued in 2017 for the financial institutions it regulates. It sets controls in four domains and measures them on a 0–5 maturity scale.
At least level 3, "structured and formalised", meaning controls are documented, approved, communicated and consistently applied.
Cyber security leadership and governance; cyber security risk management and compliance; cyber security operations and technology; and third-party cyber security.
They can. SAMA CSF applies to SAMA-regulated institutions; NCA ECC applies to government and critical infrastructure organisations, which can include financial institutions. Most evidence overlaps.
Most institutions need 6 to 12 months, depending on how many areas start below level 3.
NCA ECC, SAMA CSF, UAE IAS and Gulf data protection laws.
blog.quldex.comA file-naming scheme auditors can follow.
blog.quldex.comHow many samples auditors look at.
blog.quldex.comHow auditors grade findings.
Reviewed by
Answer a short readiness check and get a gap summary by domain. No sales call needed to see the result.