Learn about the SAMA Cybersecurity Framework, its key controls, compliance requirements, and how Saudi financial institutions can strengthen cyber resilience and regulatory compliance.
By Blue Edge Team | Aug 17, 2026
Quick answer: The SAMA Cybersecurity Framework is a mandatory regulatory standard issued by the Saudi Arabian Monetary Authority that requires financial institutions operating in Saudi Arabia to implement structured cybersecurity controls across governance, risk management, operations, and third-party management. Compliance is assessed through annual self-assessments and regulatory audits.
Saudi Arabia's financial sector is one of the most digitally active in the Middle East—and one of the most targeted. As banks, insurance companies, and fintech firms accelerate their digital transformation, cyber threats have grown in both scale and sophistication. The Saudi Arabian Monetary Authority (SAMA) responded with a framework designed to set a clear, enforceable standard for cybersecurity across every institution it supervises.
First published in 2017 and refined over subsequent years, the SAMA Cybersecurity Framework establishes the baseline controls that financial institutions must implement to protect customer data, maintain operational continuity, and preserve trust in Saudi Arabia's financial system. For compliance officers, IT security teams, and executive leadership, understanding this framework is not optional—it is a regulatory obligation with direct business consequences.
This guide breaks down the framework's structure, key domains, compliance requirements, and how your institution can build a mature cybersecurity posture aligned with SAMA's expectations.
The SAMA Cybersecurity Framework (officially titled the "Cyber Security Framework") is a regulatory document issued by the Saudi Arabian Monetary Authority to govern how Member Organizations—including banks, insurance companies, financing companies, and payment service providers—manage cybersecurity risk.
The framework is grounded in international standards, drawing heavily from NIST, ISO/IEC 27001, and BASEL III guidelines, while tailoring requirements to the specific risk profile of Saudi financial institutions. It operates on a maturity-based model, meaning organizations are assessed not just on whether controls exist, but on how effectively and consistently those controls are implemented.
The framework applies to all entities directly licensed and supervised by SAMA. Non-compliance can result in regulatory action, reputational damage, and increased exposure to cyber incidents.
The framework is organized around four core domains, each containing sub-domains and specific controls. Together, these domains cover the full lifecycle of cybersecurity risk management.
This domain establishes accountability at the board and executive level. SAMA requires that cybersecurity be treated as a strategic risk, not just a technical issue. Member Organizations must appoint a Chief Information Security Officer (CISO), establish a cybersecurity policy approved by senior management, and integrate cybersecurity considerations into their overall risk management strategy.
Risk management under SAMA requires a formalized, documented process for identifying, assessing, and treating cybersecurity risks. Institutions must conduct regular risk assessments, maintain a risk register, and demonstrate that identified risks are being actively managed. Compliance with applicable laws—including the Saudi Personal Data Protection Law (PDPL)—must also be embedded within this domain.
This is the most operationally intensive domain. It covers the technical and procedural controls institutions must implement, including:
Given that financial institutions rely heavily on vendors, cloud providers, and outsourced services, SAMA requires that cybersecurity obligations extend through the supply chain. Institutions must assess third-party security postures, include cybersecurity clauses in contracts, and monitor vendor compliance on an ongoing basis.
The table below compares key control areas across the four domains, along with their primary focus and maturity indicators:
| Domain | Key Control Area | Primary Focus | Maturity Indicator |
|---|---|---|---|
| Governance | CISO appointment & board reporting | Leadership accountability | Documented roles and reporting structure |
| Governance | Cybersecurity policy framework | Strategic alignment | Board-approved policy, annual review cycle |
| Risk Management | Risk assessment process | Threat identification | Formal risk register with remediation timelines |
| Risk Management | Regulatory compliance monitoring | Legal adherence | PDPL alignment, audit documentation |
| Operations & Technology | Identity and access management | Access control | MFA enforced, privileged access reviewed |
| Operations & Technology | Incident response planning | Operational resilience | Tested IR plan, documented response times |
| Operations & Technology | Security monitoring (SOC) | Threat detection | 24/7 monitoring, defined escalation paths |
| Third-Party Management | Vendor risk assessment | Supply chain security | Documented due diligence for all critical vendors |
| Third-Party Management | Contractual security obligations | Vendor accountability | Cybersecurity clauses in all third-party contracts |
SAMA uses a five-level maturity model to assess compliance. Each level reflects a progressively more structured and embedded approach to cybersecurity:
SAMA expects Member Organizations to target Level 3 at minimum across all control domains. Higher-risk institutions or those with greater digital complexity are expected to operate at Levels 4 or 5.
Compliance with the SAMA Cybersecurity Framework follows a structured annual cycle:
Institutions that consistently score below expected maturity levels may face supervisory intervention, including mandatory remediation timelines and increased regulatory scrutiny.
For institutions in the early stages of compliance, prioritizing the following areas will deliver the greatest impact:
The SAMA Cybersecurity Framework provides a clear, structured path for Saudi financial institutions to build resilient, trustworthy, and compliant cybersecurity programs. The framework's maturity model ensures that compliance is not a one-time exercise—it demands continuous improvement and genuine organizational commitment.
As cyber threats targeting the financial sector continue to evolve, institutions that invest in strong governance, robust operations, and third-party oversight will be best positioned to protect their customers, their assets, and their regulatory standing.
If your institution is working toward SAMA compliance and requires expert guidance on cybersecurity architecture, risk assessments, or managed security services, contact our team today to discuss how we can support your compliance journey.
The SAMA Cybersecurity Framework applies to all Member Organizations supervised by the Saudi Arabian Monetary Authority. This includes licensed banks, insurance companies, financing companies, and payment service providers operating in Saudi Arabia.
SAMA expects Member Organizations to achieve at least Level 3 (Defined) maturity across all control domains. This means cybersecurity controls must be formally documented, standardized, and consistently applied organization-wide.
SAMA requires institutions to conduct a self-assessment annually. The results must be documented and may be subject to independent third-party audits as directed by SAMA.
Non-compliance can result in regulatory intervention, including mandatory remediation requirements, increased audit scrutiny, and potential supervisory action. Persistent non-compliance may also carry reputational and legal consequences under Saudi financial regulations.
The SAMA framework aligns closely with ISO/IEC 27001 principles and shares many of the same control categories. However, SAMA's framework is specific to the Saudi financial sector and includes additional requirements relevant to local regulatory obligations, such as alignment with the Saudi Personal Data Protection Law (PDPL). Holding an ISO 27001 certification supports SAMA compliance but does not replace it.