Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SAMA CSF domains explained

SAMA CSF Domains: All 4 and Their 32 Subdomains Explained (2026)

The SAMA CSF domains are the four parts of the Saudi Central Bank’s Cyber Security Framework — issued under Circular 381000091275 of 24 May 2017 and recorded In-Force in the SAMA Rulebook — and every one of the Framework’s 32 subdomains, with its principle, objective and numbered control considerations, sits inside one of them. Domain 1, Cyber Security Leadership and Governance, has seven subdomains; Domain 2, Cyber Security Risk Management and Compliance, has five; Domain 3, Cyber Security Operations and Technology, has seventeen; and Domain 4, Third Party Cyber Security, has three.

The structure matters more than it does in most frameworks because SAMA assesses maturity — on the 0-to-5 model in section 2.4 — subdomain by subdomain, and the self-assessment questionnaire, the SAMA review and the remediation plan are all organised by it. This guide lists every subdomain in each of the four SAMA CSF domains as the Framework names them, explains what each domain is for and where the sector exceptions fall, and describes how to run a maturity programme domain by domain.

The four SAMA CSF domains and their 32 subdomains
1 Leadership and Governance (3.1.1–3.1.7) · 2 Risk Management and Compliance (3.2.1–3.2.5) · 3 Operations and Technology (3.3.1–3.3.17) · 4 Third Party Cyber Security (3.4.1–3.4.3) · each subdomain: principle, objective, control considerations · maturity 0–5 per subdomain.

How the SAMA CSF domains are built

Section 2.1 of the Framework describes the structure: four domains, each with subdomains focused on a specific topic; per subdomain a principle that summarises the required controls, an objective that says what they are meant to achieve, and control considerations — the mandated controls, uniquely numbered up to four levels deep. The Framework is principle-based (2.2): it prescribes what has to be achieved and leaves the how to the Member Organization. Section 2.3 makes implementation subject to periodic self-assessment on a questionnaire, reviewed and audited by SAMA to determine compliance and the maturity level. Our guide to SAMA compliance covers the six maturity levels; this guide covers the domains the levels are measured against.

The SAMA CSF domains, 1: Cyber Security Leadership and Governance

Subdomain Title What the principle requires
3.1.1 Cyber Security Governance A board-endorsed governance structure: a cyber security committee mandated by the board, headed by an independent senior manager from a control function and meeting at least quarterly, and a cyber security function independent of IT with separate reporting lines, budget and staff
3.1.2 Cyber Security Strategy A strategy defined, approved and aligned with the organisation’s strategic objectives — and, for the banking sector, aligned with the sector strategy
3.1.3 Cyber Security Policy A policy defined, approved, communicated and supported by standards and procedures
3.1.4 Cyber Security Roles and Responsibilities Roles defined and allocated across the board, senior management, the cyber security function, IT and business owners
3.1.5 Cyber Security in Project Management Cyber security requirements addressed in project management methodology and in every project
3.1.6 Cyber Security Awareness An awareness programme for staff, third parties and customers
3.1.7 Cyber Security Training Training for staff in cyber security roles and for staff generally, in line with their responsibilities

Domain 1 is where maturity levels 4 and 5 are won or lost: the committee, the strategy and the KPIs and KRIs that the higher levels require live here.

The SAMA CSF domains, 2: Cyber Security Risk Management and Compliance

Subdomain Title What the principle requires
3.2.1 Cyber Security Risk Management A risk management process to identify, analyse, respond to and monitor cyber security risks, integrated with enterprise risk management
3.2.2 Regulatory Compliance A process to identify, communicate and comply with relevant regulatory requirements
3.2.3 Compliance with (Inter)national Industry Standards Compliance with mandatory standards: PCI DSS, the EMV technical standard, and the SWIFT Customer Security Controls Framework
3.2.4 Cyber Security Review Periodic cyber security reviews of the organisation’s information assets
3.2.5 Cyber Security Audits Thorough, independent and regular audits to generally accepted auditing standards and the Framework, per the audit manual and plan

Subdomain 3.2.3 is excluded for non-banking institutions unless the organisation stores, processes or transmits cardholder data or uses SWIFT — in which case PCI DSS and the SWIFT CSCF apply through it. The SWIFT reference is to the March 2017 CSCF; the current CSCF is a later version and the obligation follows the current one.

The SAMA CSF domains, 3: Cyber Security Operations and Technology

Subdomain Title What the principle requires
3.3.1 Human Resources Cyber security requirements in the employment life cycle: screening, agreements, termination
3.3.2 Physical Security Physical protection of information assets and facilities
3.3.3 Asset Management An accurate and up-to-date inventory of information assets with owners and classification
3.3.4 Cyber Security Architecture A security architecture defined and maintained, with standards for the design of systems
3.3.5 Identity and Access Management User access controlled on need-to-have and need-to-know; privileged and remote access managed; periodic review
3.3.6 Application Security Security requirements in application development and acquisition; secure coding; testing
3.3.7 Change Management Changes to information assets controlled through a change process with security requirements
3.3.8 Infrastructure Security Security of networks, systems and devices: hardening, segmentation, malware protection, remote access
3.3.9 Cryptography Cryptographic solutions and key management standards
3.3.10 Bring Your Own Device (BYOD) A standard, staff agreements and awareness where personal devices are used for business
3.3.11 Secure Disposal of Information Assets Secure disposal and destruction of information and media
3.3.12 Payment Systems A cyber security standard for payment systems, referring to the SARIE Information Security Policy and the mada Rules and Standards Technical Book
3.3.13 Electronic Banking Services A cyber security standard for electronic banking services protecting customer information and transactions
3.3.14 Cyber Security Event Management A security event management process with a monitoring standard and a designated team — a Security Operations Center — with trained staff
3.3.15 Cyber Security Incident Management An incident management process aligned with enterprise incident management, with a designated team, trained staff and forensic capacity for major incidents
3.3.16 Threat Management A threat intelligence process — extended by the 2022 Cyber Threat Intelligence Principles
3.3.17 Vulnerability Management A vulnerability management process covering all information assets, risk-based scan frequency, classification, mitigation timelines per class and patch management

Domain 3 carries more than half the subdomains and most of the evidence burden. Subdomains 3.3.12 and 3.3.13 are excluded for non-banking institutions with conditions; the rest apply to every Member Organization. Our guide to the SAMA Cyber Threat Intelligence Principles covers the document that extends 3.3.16.

The SAMA CSF domains, 4: Third Party Cyber Security

Subdomain Title What the principle requires
3.4.1 Contract and Vendor Management Cyber security requirements in the contract and vendor management process, with due diligence and periodic review
3.4.2 Outsourcing Cyber security requirements in outsourcing: risk assessment, SAMA approval where required, contractual controls, monitoring
3.4.3 Cloud Computing A cloud computing policy for hybrid and public cloud: SAMA approval before use, data in Saudi Arabia unless SAMA explicitly approves otherwise, no secondary use, segregation, audit rights, exit

Domain 4 is the shortest and the most often found immature, because it depends on contracts signed before the Framework existed. Our guides to SAMA outsourcing and SAMA cloud computing requirements cover 3.4.2 and 3.4.3.

Running a maturity programme by SAMA CSF domain

  1. Confirm applicability first. All four domains for banks; the 3.1.2, 3.2.3, 3.3.12 and 3.3.13 exceptions for other institutions, read from section 1.4 of the Framework rather than from a consultant’s summary.
  2. Assess every subdomain on the 0–5 model. The questionnaire is per subdomain; so is SAMA’s review. A domain average hides the subdomain at level 1 that will be the finding.
  3. Build Domain 1 to level 3 before anything else. Governance, strategy, policy, roles: the other domains’ controls need a policy to be “defined, approved and implemented” against, which is the level 3 test.
  4. Treat Domain 3 as seventeen mini-programmes. Each subdomain needs its standard, its compliance monitoring and its effectiveness measurement — the three sentences that recur in almost every principle and that map to levels 3, 3 and 4.
  5. Use Domain 2 to prove it. The risk management process, the reviews and the audits in 3.2 are the evidence that the other domains operate — and are what SAMA’s own audit samples.
  6. Close Domain 4 through the contract cycle. Each renewal is the point at which 3.4.1–3.4.3 requirements enter the contract; a register of third parties with the clauses present or missing is the remediation plan.

Our guide to SAMA CSF vs NCA ECC covers running the SAMA domains alongside the NCA’s controls where both apply.

Frequently asked questions

What are the four SAMA CSF domains?
Cyber Security Leadership and Governance (subdomains 3.1.1–3.1.7), Cyber Security Risk Management and Compliance (3.2.1–3.2.5), Cyber Security Operations and Technology (3.3.1–3.3.17) and Third Party Cyber Security (3.4.1–3.4.3) — 32 subdomains, each with a principle, an objective and numbered control considerations.

Do all four domains apply to every Member Organization?
All domains apply to the banking sector. For other institutions, section 1.4 makes alignment with the banking-sector strategy in 3.1.2 mandatory only when applicable, excludes 3.2.3 unless cardholder data or SWIFT is involved, and excludes 3.3.12 and 3.3.13 with conditions.

How is maturity assessed against the domains?
By periodic self-assessment on a questionnaire, per subdomain, on the six-level model (0 non-existent to 5 adaptive); SAMA reviews and audits the self-assessment to determine compliance and the maturity level. Levels are cumulative.

Which domain has the most subdomains?
Domain 3, Cyber Security Operations and Technology, with seventeen — from human resources and physical security through identity and access, applications, infrastructure, cryptography, payment and e-banking systems, to event, incident, threat and vulnerability management.

Where do the SAMA cloud requirements sit?
In Domain 4, subdomain 3.4.3 Cloud Computing, which requires a cloud policy for hybrid and public cloud with SAMA approval before use, data located in Saudi Arabia unless SAMA explicitly approves otherwise, and contractual rights on use, segregation, audit and exit.

Where this leaves you

Work the SAMA CSF domains in the order the Framework’s logic implies: confirm applicability from section 1.4, assess all 32 subdomains on the six-level model, build the governance domain to level 3 first, run the seventeen operations subdomains as standards with monitoring and measurement, use the risk and compliance domain as the proof, and close third-party gaps through the contract cycle — because SAMA reads the self-assessment subdomain by subdomain, and so should you.

References

More on SAMA

The subdomain-by-subdomain self-assessment workbook, the maturity roadmap, and the policies and standards for all four domains are in the SAMA Compliance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.