SAMA does not ask whether a control exists. It asks what level it runs at. Level 3 is the baseline the Cyber Security Framework expects, and the distance between a control that works and a control you can measure is where most member organisations sit.

This assessment walks all 32 sub-domains across the four SAMA domains, so you can see where the programme stands before you translate it into a maturity rating. It is free, it saves as you go, and you can stop and come back to it.

What this is

A structured pass over all 32 sub-domains of the SAMA Cyber Security Framework, so you can see where the programme stands before you translate it into the maturity levels SAMA supervises you on. We have the background elsewhere — the framework and its maturity levels, all four domains and 32 sub-domains, how it sits against the NCA ECC, the outsourcing rules and the cloud requirements. Come here when you want a score.

What it covers

DomainSub-domains assessed
Scope and maturity — member status, conditional sub-domains, target level5
3.1 Cyber Security Leadership and Governance7
3.2 Cyber Security Risk Management and Compliance5
3.3 Cyber Security Operations and Technology17
3.4 Third Party Cyber Security3
Assessment and reporting4

Scoring here, and SAMA’s maturity levels

SAMA assesses you on a six-level maturity scale from 0 to 5, and expects level 3 — defined, approved and consistently applied — as the baseline, with levels 4 and 5 for measured and continuously improving. That rating is a judgement made per sub-domain against SAMA’s own criteria.

This assessment does not attempt to assign those levels for you. It uses a five-step implementation scale to find what is missing and what cannot be evidenced, which is the raw material for a maturity rating rather than a substitute for one. The practical use is the distance between “implemented” and “implemented and evidenced”: that gap maps closely onto the gap between level 3 and level 4, and it is where most member organisations stall.

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records someone could sample
Not applicableA justified exclusion, removed from the score

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every sub-domain with your status and notes, the score broken down by domain, a prioritised gap list, and the documents from the SAMA Compliance Toolkit that close each gap — as a PDF and a working Excel file.

How long does it take?

About 25 minutes. Operations and Technology is 17 of the 32 sub-domains, so it carries most of the time.

What to do with your score

Below 40% — start with 3.1, Leadership and Governance. SAMA’s maturity model rewards documented, approved and owned processes, and without those the technical sub-domains cannot reach level 3 however well they run.

40–70% — look at the spread rather than the average. SAMA assesses per sub-domain, so one sub-domain at level 1 is a finding even if the mean is comfortable.

Above 70% — move to measurement. Level 4 needs metrics and periodic review of effectiveness, not just a working control, and that is usually a reporting build rather than a security build.

Frequently asked questions

Is this assessment really free?

Yes. All 41 questions, the domain breakdown and your overall score cost nothing. The $39 report is optional.

Does this produce the maturity rating I submit to SAMA?

No. It produces the evidence picture behind one. The maturity level per sub-domain is a judgement you make against SAMA’s criteria, and this gives you the material to make it defensibly.

Who does the framework apply to?

Member organisations regulated by SAMA — banks, insurers, financing and credit companies, and the financial market infrastructures. Some sub-domains are conditional on what you do, and the scope section covers those.

Do I also need the NCA ECC?

Often, yes. They are different regulators with different tests — SAMA scores maturity, the NCA tests compliance. The comparison guide explains how to run one control set for both, and there is a separate NCA ECC assessment.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.