Cybersecurity

SAMA Cybersecurity Framework: A Complete Guide for Saudi Financial Institutions

Learn about the SAMA Cybersecurity Framework, its key controls, compliance requirements, and how Saudi financial institutions can strengthen cyber resilience and regulatory compliance.

By Blue Edge Team | Aug 17, 2026

SAMA Cybersecurity Framework helping Saudi financial institutions strengthen governance, risk management, cyber resilience, and regulatory compliance

SAMA Cybersecurity Framework: A Complete Guide for Saudi Financial Institutions

Quick answer: The SAMA Cybersecurity Framework is a mandatory regulatory standard issued by the Saudi Arabian Monetary Authority that requires financial institutions operating in Saudi Arabia to implement structured cybersecurity controls across governance, risk management, operations, and third-party management. Compliance is assessed through annual self-assessments and regulatory audits.

Saudi Arabia's financial sector is one of the most digitally active in the Middle East—and one of the most targeted. As banks, insurance companies, and fintech firms accelerate their digital transformation, cyber threats have grown in both scale and sophistication. The Saudi Arabian Monetary Authority (SAMA) responded with a framework designed to set a clear, enforceable standard for cybersecurity across every institution it supervises.

First published in 2017 and refined over subsequent years, the SAMA Cybersecurity Framework establishes the baseline controls that financial institutions must implement to protect customer data, maintain operational continuity, and preserve trust in Saudi Arabia's financial system. For compliance officers, IT security teams, and executive leadership, understanding this framework is not optional—it is a regulatory obligation with direct business consequences.

This guide breaks down the framework's structure, key domains, compliance requirements, and how your institution can build a mature cybersecurity posture aligned with SAMA's expectations.


What Is the SAMA Cybersecurity Framework?

The SAMA Cybersecurity Framework (officially titled the "Cyber Security Framework") is a regulatory document issued by the Saudi Arabian Monetary Authority to govern how Member Organizations—including banks, insurance companies, financing companies, and payment service providers—manage cybersecurity risk.

The framework is grounded in international standards, drawing heavily from NIST, ISO/IEC 27001, and BASEL III guidelines, while tailoring requirements to the specific risk profile of Saudi financial institutions. It operates on a maturity-based model, meaning organizations are assessed not just on whether controls exist, but on how effectively and consistently those controls are implemented.

The framework applies to all entities directly licensed and supervised by SAMA. Non-compliance can result in regulatory action, reputational damage, and increased exposure to cyber incidents.


How Is the SAMA Cybersecurity Framework Structured?

The framework is organized around four core domains, each containing sub-domains and specific controls. Together, these domains cover the full lifecycle of cybersecurity risk management.

1. Cybersecurity Leadership and Governance

This domain establishes accountability at the board and executive level. SAMA requires that cybersecurity be treated as a strategic risk, not just a technical issue. Member Organizations must appoint a Chief Information Security Officer (CISO), establish a cybersecurity policy approved by senior management, and integrate cybersecurity considerations into their overall risk management strategy.

2. Cybersecurity Risk Management and Compliance

Risk management under SAMA requires a formalized, documented process for identifying, assessing, and treating cybersecurity risks. Institutions must conduct regular risk assessments, maintain a risk register, and demonstrate that identified risks are being actively managed. Compliance with applicable laws—including the Saudi Personal Data Protection Law (PDPL)—must also be embedded within this domain.

3. Cybersecurity Operations and Technology

This is the most operationally intensive domain. It covers the technical and procedural controls institutions must implement, including:

  • Asset and configuration management
  • Identity and access management
  • Threat intelligence and vulnerability management
  • Incident detection, response, and recovery
  • Security monitoring and logging

4. Third-Party Cybersecurity

Given that financial institutions rely heavily on vendors, cloud providers, and outsourced services, SAMA requires that cybersecurity obligations extend through the supply chain. Institutions must assess third-party security postures, include cybersecurity clauses in contracts, and monitor vendor compliance on an ongoing basis.


SAMA Cybersecurity Framework: Key Controls at a Glance

The table below compares key control areas across the four domains, along with their primary focus and maturity indicators:

Domain Key Control Area Primary Focus Maturity Indicator
Governance CISO appointment & board reporting Leadership accountability Documented roles and reporting structure
Governance Cybersecurity policy framework Strategic alignment Board-approved policy, annual review cycle
Risk Management Risk assessment process Threat identification Formal risk register with remediation timelines
Risk Management Regulatory compliance monitoring Legal adherence PDPL alignment, audit documentation
Operations & Technology Identity and access management Access control MFA enforced, privileged access reviewed
Operations & Technology Incident response planning Operational resilience Tested IR plan, documented response times
Operations & Technology Security monitoring (SOC) Threat detection 24/7 monitoring, defined escalation paths
Third-Party Management Vendor risk assessment Supply chain security Documented due diligence for all critical vendors
Third-Party Management Contractual security obligations Vendor accountability Cybersecurity clauses in all third-party contracts

What Are SAMA's Cybersecurity Maturity Levels?

SAMA uses a five-level maturity model to assess compliance. Each level reflects a progressively more structured and embedded approach to cybersecurity:

  • Level 1 – Initial: Controls are ad hoc, undocumented, and reactive.
  • Level 2 – Repeatable: Some controls exist but are inconsistently applied.
  • Level 3 – Defined: Controls are documented, standardized, and consistently applied across the organization.
  • Level 4 – Managed: Controls are measured, monitored, and continuously improved using performance data.
  • Level 5 – Optimizing: Cybersecurity is embedded in organizational culture, with proactive threat management and continuous innovation.

SAMA expects Member Organizations to target Level 3 at minimum across all control domains. Higher-risk institutions or those with greater digital complexity are expected to operate at Levels 4 or 5.


How Do Saudi Financial Institutions Comply with the SAMA Framework?

Compliance with the SAMA Cybersecurity Framework follows a structured annual cycle:

  • Self-Assessment: Institutions conduct an internal maturity assessment against all framework controls, typically using SAMA's published assessment template.
  • Gap Analysis: Identified gaps are documented and prioritized based on risk severity.
  • Remediation Planning: A formal remediation roadmap is developed with assigned owners and target completion dates.
  • External Audit: SAMA may require an independent third-party audit to validate self-assessment findings.
  • Regulatory Submission: Results are submitted to SAMA through the designated reporting channel.

Institutions that consistently score below expected maturity levels may face supervisory intervention, including mandatory remediation timelines and increased regulatory scrutiny.


Building a Compliant Cybersecurity Program: Where to Focus First

For institutions in the early stages of compliance, prioritizing the following areas will deliver the greatest impact:

  • Establish governance first. Without a defined CISO role and board-level accountability, other controls lack direction and ownership.
  • Formalize your risk management process. A documented risk register with clear remediation ownership demonstrates regulatory intent.
  • Invest in security monitoring. SAMA places significant weight on detection and response capabilities. A Security Operations Center (SOC)—whether in-house or managed—is increasingly expected.
  • Audit your third parties. Many institutions underestimate vendor risk. Conducting structured assessments of critical suppliers is both a SAMA requirement and a practical risk reduction measure.

Strengthening Saudi Financial Institutions Through Structured Cybersecurity

The SAMA Cybersecurity Framework provides a clear, structured path for Saudi financial institutions to build resilient, trustworthy, and compliant cybersecurity programs. The framework's maturity model ensures that compliance is not a one-time exercise—it demands continuous improvement and genuine organizational commitment.

As cyber threats targeting the financial sector continue to evolve, institutions that invest in strong governance, robust operations, and third-party oversight will be best positioned to protect their customers, their assets, and their regulatory standing.

If your institution is working toward SAMA compliance and requires expert guidance on cybersecurity architecture, risk assessments, or managed security services, contact our team today to discuss how we can support your compliance journey.

Frequently Asked Questions

  • Who does the SAMA Cybersecurity Framework apply to?

    The SAMA Cybersecurity Framework applies to all Member Organizations supervised by the Saudi Arabian Monetary Authority. This includes licensed banks, insurance companies, financing companies, and payment service providers operating in Saudi Arabia.

  • What is the minimum maturity level required under the SAMA framework?

    SAMA expects Member Organizations to achieve at least Level 3 (Defined) maturity across all control domains. This means cybersecurity controls must be formally documented, standardized, and consistently applied organization-wide.

  • How often do institutions need to assess their SAMA cybersecurity compliance?

    SAMA requires institutions to conduct a self-assessment annually. The results must be documented and may be subject to independent third-party audits as directed by SAMA.

  • What happens if a financial institution fails to comply with the SAMA framework?

    Non-compliance can result in regulatory intervention, including mandatory remediation requirements, increased audit scrutiny, and potential supervisory action. Persistent non-compliance may also carry reputational and legal consequences under Saudi financial regulations.

  • How does the SAMA Cybersecurity Framework relate to ISO/IEC 27001?

    The SAMA framework aligns closely with ISO/IEC 27001 principles and shares many of the same control categories. However, SAMA's framework is specific to the Saudi financial sector and includes additional requirements relevant to local regulatory obligations, such as alignment with the Saudi Personal Data Protection Law (PDPL). Holding an ISO 27001 certification supports SAMA compliance but does not replace it.