Ready for a SAMA CSF Gap Assessment?
Get a maturity baseline against all four SAMA CSF domains and a remediation roadmap your board and regulator will recognize.
The Saudi Central Bank (SAMA) Cyber Security Framework is mandatory for banks, insurance companies, finance companies and financial market infrastructure providers licensed in the Kingdom. Cyberox supports SAMA-regulated entities through gap assessment, remediation and annual self-assessment cycles.
Last reviewed: September 2026. Verify current requirements against the official regulator before acting — sources linked below.
SAMA CSF applies to all entities licensed and supervised by the Saudi Central Bank — commercial and Islamic banks, insurance and reinsurance companies, finance companies, and financial market infrastructure (FMI) providers operating in Saudi Arabia.
The framework covers cybersecurity leadership and governance, cybersecurity risk management and compliance, cybersecurity operations and technology, and third-party cybersecurity — assessed against defined maturity levels rather than a simple pass/fail checklist.
SAMA-supervised entities are expected to self-assess their cybersecurity maturity against the framework on a recurring basis and report results through SAMA's supervisory channels. Maintaining continuous, audit-ready evidence is central to staying compliant, not a once-a-year scramble.
A dedicated framework domain addresses third-party cybersecurity — increasingly relevant as banks and insurers rely on cloud providers, fintech partners and outsourced technology vendors. Third-party risk assessment is often the fastest-growing gap area we find.
SAMA CSF, ISO/IEC 27001, and the NCA's Essential Cybersecurity Controls share overlapping governance and risk-management structures. Financial institutions typically benefit from a single integrated program rather than three parallel compliance tracks.
SAMA periodically updates its supervisory frameworks and guidance. Confirm current framework version, maturity-level definitions and reporting requirements directly with SAMA or your compliance/legal counsel before finalizing any program — this page is a starting reference, not the authoritative source.
We help SAMA-regulated banks, insurers and finance companies benchmark current maturity, close priority gaps, and build a sustainable self-assessment process.
The National Cybersecurity Authority's baseline framework — relevant to SAMA-regulated entities as critical infrastructure.
Learn moreFull cybersecurity and compliance consulting overview for Saudi organizations.
Learn moreIndustry-specific coverage of regulatory obligations for banks and financial institutions across our served markets.
Learn moreGet a maturity baseline against all four SAMA CSF domains and a remediation roadmap your board and regulator will recognize.