Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SAMA CSF maturity levels guide cover

SAMA CSF Maturity Levels: What Level 3 Means in 2026

SAMA CSF maturity levels are the scale that the Saudi Central Bank’s Cyber Security Framework uses to judge how well a member organization runs each cybersecurity control. The framework does not only ask whether a control exists. It asks whether the control is defined, approved, implemented, monitored and, at higher levels, measured and continuously improved. Knowing what each level means, and what evidence supports it, decides how your self-assessment and any regulator review will go.

SAMA’s own rulebook was not accessible to our research tools, so the descriptions here come from secondary summaries of the framework. Read the current framework text on SAMA’s rulebook site before you rely on any detail below. For structure, see our guides to the SAMA CSF domains and to SAMA compliance.

Free gap assessment

Where does your programme sit against the SAMA CSF?

Walk all 32 sub-domains across the four domains, free, and see the evidence picture behind your maturity rating.

Run the free SAMA CSF self-assessment →  or  View premium report sample

The SAMA CSF maturity levels

Secondary summaries describe six levels, numbered 0 to 5. A vendor guide to the framework quotes the top three and the required target as follows.

LevelName as summarisedWhat it means
0Non-existentNo control or process (commonly described)
1Ad hocInformal, inconsistent practice (commonly described)
2Repeatable but informalDone in a similar way but not formally documented (commonly described)
3Structured and formalisedControls defined, approved and implemented, with compliance monitored
4Managed and measurableEffectiveness measured periodically with indicators
5AdaptiveContinuous improvement, integrated with enterprise risk management

Names for levels 0 to 2 are not confirmed in the sources used here, so treat them as a common description and check the framework. The descriptions for levels 3 to 5 come from a vendor summary of the framework.

Why level 3 is the practical target among SAMA CSF maturity levels

The same summary says member organizations must operate at maturity level 3 or higher. That makes level 3 the baseline. In practice, you must show that each applicable control has a defined and approved standard, that it is implemented across the organization and that someone monitors compliance. A policy alone is not enough, and a control that operates informally without documentation does not qualify.

Confirm whether SAMA sets different expectations for particular controls or types of member organization, and whether any targets are higher for critical functions. Ask your relationship contact at the regulator if the text is unclear.

What level 3 looks like in practice

  • Defined. A written policy or standard covers the control, with scope and responsibilities.
  • Approved. The document has formal approval by the right authority, and a version history.
  • Implemented. The control operates across the in-scope environment, with records that prove it.
  • Monitored. Compliance is checked, for example through reviews, testing or audit, and gaps are tracked to closure.

For example, for access reviews, level 3 means a documented procedure, management approval, reviews done on schedule across all in-scope systems, evidence saved and exceptions followed up.

Moving from level 3 to level 4

Level 4 adds measurement. The summary says it demands periodic measurement and evaluation of control effectiveness using key risk indicators and key performance indicators. That means choosing meaningful measures for each control, collecting them regularly, setting thresholds and acting when they are breached. For access reviews, a measure might be the percentage of reviews completed on time and the number of inappropriate accesses found and removed.

Avoid measures that only count activity. Effectiveness measures tell you whether the control is reducing risk, not simply whether people did the task. Report them to management, and use trends to improve controls.

Level 5: adaptive

Level 5 describes continuous improvement integrated with enterprise risk management. Controls adapt to new threats and lessons from incidents, and improvements feed into risk decisions. Few organizations aim for level 5 across all controls. Concentrate on the areas where the risk justifies the effort, such as critical services or the controls that protect customer funds and data.

Common evidence examples by level

For level 3, typical evidence includes the approved policy, the procedure, an inventory or register showing coverage, and dated records of the control operating, such as access review sign-offs or patch reports. For level 4, add the indicator definitions, the reports showing values over time, threshold breaches and the actions taken. For level 5, add lessons learned reviews, improvement proposals and evidence that they changed the control or the risk assessment. Keep the evidence for at least the period the regulator or your auditor may review, and store it where authorised reviewers can find it.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

Building evidence for a maturity assessment

The vendor guide says SAMA takes a principle-based, risk-based approach that expects defensible, repeatable and current evidence that controls work as intended. Build an evidence library organised by control: policy, approval record, procedure, sample records for several periods, monitoring reports and follow-up actions. Refresh it on a schedule, so evidence is current at the time of assessment.

  1. Map controls to the framework’s domains and subdomains.
  2. Assign owners to each control.
  3. Score current maturity honestly against the level descriptions.
  4. Collect evidence that supports each score.
  5. Plan improvements for gaps, with owners and dates.
  6. Review the assessment with senior management and the board.

Related topics that assessors often probe include threat intelligence, business continuity and how the framework compares with NCA ECC, so prepare evidence there too.

Setting targets by control, not by organization

A single overall score hides useful detail. Set target maturity for each control or subdomain based on the risk it addresses. Controls that protect critical services and customer data may deserve a higher target, while controls with limited impact may stay at the baseline. Record the reasoning, and show it to senior management. When the regulator asks why one area sits at level 3 and another at level 4, a documented rationale is the answer. Using SAMA CSF maturity levels this way also helps you spend improvement budget where it matters.

Roles in a maturity assessment

Assign clear roles. Control owners score their own controls and collect evidence. The security or compliance function challenges the scores and checks that evidence supports them. Internal audit provides independent assurance over the process. Senior management approves the results and the improvement plan, and the board receives a summary. Keeping these roles separate avoids the common problem of owners marking their own work generously.

Keeping the assessment current

A maturity score is a snapshot. Update it when significant changes occur, such as new systems, outsourcing arrangements, incidents or organizational changes, and at least annually. Keep the previous scores, so that you can show progress. Use the assessment to drive your annual cybersecurity plan and budget, rather than treating it as a one-off compliance exercise. A rolling programme with quarterly evidence collection makes the annual review far less painful.

Finally, remember to align the assessment with related frameworks used in your organization, such as ISO 27001 or the SAMA IT governance framework. A common control library that maps to each framework avoids duplicated effort, and gives consistent answers when different reviewers ask about the same control.

Be honest about limits. If your evidence shows only that a control started recently, score it on what the records prove today, and plan to rescore after enough history exists. Regulators generally respond better to a candid score with a credible plan than to an optimistic score that falls apart under review. Keep a short note on each score explaining how it was reached, since this makes later reviews faster and more consistent for the SAMA CSF maturity levels you report.

A hypothetical example

A hypothetical bank scores its vulnerability management control at level 2: scans are run and patches applied, but there is no approved standard and the timing varies. The security team writes and approves a vulnerability management standard, sets remediation timeframes by severity, tracks compliance monthly and reports exceptions. After two quarters of records, it rescores the control at level 3. It then begins measuring the percentage of critical findings closed within the target time, working towards level 4. The example is invented for illustration.

Common mistakes with SAMA CSF maturity levels

  • Scoring by intent instead of evidence.
  • Treating a written policy as level 3 without proof of implementation.
  • Skipping approval records and version history.
  • Collecting evidence for a single date instead of across periods.
  • Choosing activity counts as effectiveness measures.
  • Assuming secondary summaries are enough without reading the framework.

The framework itself is published on SAMA’s rulebook. Use it as the authority, and consult your regulator if you are unsure.

Templates for SAMA CSF maturity levels

To avoid building maturity scoring sheets, evidence registers and improvement plans from scratch, the SAMA Toolkit provides documents you can adapt. Have a qualified Saudi regulatory adviser review them.

SAMA CSF maturity levels FAQ

What is the minimum maturity level?

A vendor summary of the framework says member organizations must operate at level 3 or higher. Check the current framework text.

What is the difference between level 3 and level 4?

Level 3 requires defined, approved, implemented and monitored controls. Level 4 adds periodic measurement of effectiveness using indicators.

Is a policy enough for level 3?

No. Controls must also be implemented and monitored, with evidence.

Do we need level 5 everywhere?

Generally no. Focus on the controls where higher maturity reduces significant risk.

Where can I read the official text?

On SAMA’s rulebook website, in the Cyber Security Framework section.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.