SAMA does not ask whether a control exists. It asks what level it runs at. Level 3 is the baseline the Cyber Security Framework expects, and the distance between a control that works and a control you can measure is where most member organisations sit.
This assessment walks all 32 sub-domains across the four SAMA domains, so you can see where the programme stands before you translate it into a maturity rating. It is free, it saves as you go, and you can stop and come back to it.
What this is
A structured pass over all 32 sub-domains of the SAMA Cyber Security Framework, so you can see where the programme stands before you translate it into the maturity levels SAMA supervises you on. We have the background elsewhere — the framework and its maturity levels, all four domains and 32 sub-domains, how it sits against the NCA ECC, the outsourcing rules and the cloud requirements. Come here when you want a score.
What it covers
| Domain | Sub-domains assessed |
|---|---|
| Scope and maturity — member status, conditional sub-domains, target level | 5 |
| 3.1 Cyber Security Leadership and Governance | 7 |
| 3.2 Cyber Security Risk Management and Compliance | 5 |
| 3.3 Cyber Security Operations and Technology | 17 |
| 3.4 Third Party Cyber Security | 3 |
| Assessment and reporting | 4 |
Scoring here, and SAMA’s maturity levels
SAMA assesses you on a six-level maturity scale from 0 to 5, and expects level 3 — defined, approved and consistently applied — as the baseline, with levels 4 and 5 for measured and continuously improving. That rating is a judgement made per sub-domain against SAMA’s own criteria.
This assessment does not attempt to assign those levels for you. It uses a five-step implementation scale to find what is missing and what cannot be evidenced, which is the raw material for a maturity rating rather than a substitute for one. The practical use is the distance between “implemented” and “implemented and evidenced”: that gap maps closely onto the gap between level 3 and level 4, and it is where most member organisations stall.
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every sub-domain with your status and notes, the score broken down by domain, a prioritised gap list, and the documents from the SAMA Compliance Toolkit that close each gap — as a PDF and a working Excel file.
How long does it take?
About 25 minutes. Operations and Technology is 17 of the 32 sub-domains, so it carries most of the time.
What to do with your score
Below 40% — start with 3.1, Leadership and Governance. SAMA’s maturity model rewards documented, approved and owned processes, and without those the technical sub-domains cannot reach level 3 however well they run.
40–70% — look at the spread rather than the average. SAMA assesses per sub-domain, so one sub-domain at level 1 is a finding even if the mean is comfortable.
Above 70% — move to measurement. Level 4 needs metrics and periodic review of effectiveness, not just a working control, and that is usually a reporting build rather than a security build.
Frequently asked questions
Is this assessment really free?
Yes. All 41 questions, the domain breakdown and your overall score cost nothing. The $39 report is optional.
Does this produce the maturity rating I submit to SAMA?
No. It produces the evidence picture behind one. The maturity level per sub-domain is a judgement you make against SAMA’s criteria, and this gives you the material to make it defensibly.
Who does the framework apply to?
Member organisations regulated by SAMA — banks, insurers, financing and credit companies, and the financial market infrastructures. Some sub-domains are conditional on what you do, and the scope section covers those.
Do I also need the NCA ECC?
Often, yes. They are different regulators with different tests — SAMA scores maturity, the NCA tests compliance. The comparison guide explains how to run one control set for both, and there is a separate NCA ECC assessment.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.