Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SAMA cloud computing requirements explained

SAMA Cloud Computing Requirements: The Complete 3.4.3 Guide (2026)

The SAMA cloud computing requirements are set out in one subdomain of the Saudi Central Bank’s Cyber Security Framework — 3.4.3 Cloud Computing, in Domain 4, Third Party Cyber Security — and they are more specific than most of the Framework: a Member Organization must obtain SAMA’s approval before using cloud services or signing with the provider, must in principle use only cloud services located in Saudi Arabia and obtain explicit SAMA approval for anything outside the Kingdom, and must have a contract that secures no secondary use of its data, logical segregation, business continuity, the right to review, audit and examine the provider, and return and irreversible deletion of data on exit.

The subdomain applies to hybrid and public cloud; SAMA states it does not apply to private, internal cloud. Because cloud adoption is also outsourcing, subdomain 3.4.2 and the Rules on Outsourcing apply alongside it, and where the institution is also an NCA-regulated entity the NCA Cloud Cybersecurity Controls apply on top. This guide sets out every control consideration in 3.4.3, the approval and data-location rules and how they are applied in practice, the contract clauses the Framework requires, the relationship with outsourcing and NCA requirements, and a sequence for taking a cloud service from proposal to SAMA approval.

SAMA cloud computing requirements: CSF subdomain 3.4.3
Hybrid and public cloud only · policy defined, approved, implemented, monitored, measured · adoption: risk assessment + due diligence → SAMA approval before use or contract → contract with cyber security requirements · data in Saudi Arabia unless SAMA explicitly approves · no secondary use · segregation · continuity · review, audit and examination rights · exit: termination, return, irreversible deletion.

Where the SAMA cloud computing requirements sit

Subdomain 3.4.3 states the principle: the Member Organization should define, implement and monitor the required cyber security controls within its cloud computing policy and process for hybrid and public cloud services, and periodically measure and evaluate their effectiveness — with the note that the requirement is not applicable to private cloud services. The objective is that all functions and staff know the organisation’s direction and position on hybrid and public cloud, the process to apply for such services, the risk appetite for them and the specific cyber security requirements. Our guide to the SAMA CSF domains covers the domain structure; SAMA compliance covers the maturity model the subdomain is scored on.

The SAMA cloud computing requirements in full: subdomain 3.4.3

Consideration Requirement What it means in practice
1 Cyber security controls within the cloud computing policy for hybrid and public cloud defined, approved, implemented and communicated A board- or committee-approved cloud policy, not a section of the outsourcing policy
2 Compliance with the cloud computing policy monitored A register of cloud services with their approval status; periodic checks that no service is in use outside the process
3 Controls periodically measured and evaluated for effectiveness KPIs and KRIs on cloud services — the maturity-level-4 test
4a — adoption process A cyber security risk assessment and due diligence on the provider and its services; SAMA approval obtained prior to using cloud services or signing the contract; a contract including the cyber security requirements in place before use Three gates, in order: assess, get SAMA’s approval, sign — then use
4b — data location In principle only cloud services located in Saudi Arabia; explicit SAMA approval required for services outside the Kingdom Region selection is a regulatory decision; a non-KSA region needs its own approval
4c — data use limitations The provider must not use the Member Organization’s data for secondary purposes A contractual prohibition covering analytics, model training and service improvement
4d — security The provider implements and monitors the cyber security controls determined in the risk assessment to protect confidentiality, integrity and availability The risk assessment’s control set becomes the contract’s security schedule
4e — data segregation The organisation’s data is logically segregated, and the provider can identify and distinguish it at all times Tenant isolation evidenced, not assumed
4f — business continuity Business continuity requirements met in accordance with the organisation’s business continuity policy The cloud service inherits the RTO, RPO and MAO of the activities it supports
4g — audit, review and monitoring The organisation has the right to perform a cyber security review, a cyber security audit and a cyber security examination at the provider Three distinct rights, each written into the contract
4h — exit Termination rights; return of data on termination; irreversible deletion of data on termination An exit plan with a tested data-return format and a deletion certificate

The two rules that change the project

SAMA approval before use or contract

Consideration 4a.2 places SAMA’s approval before both use and signature, which means the submission has to be built from the risk assessment and due diligence already completed and the draft contract already negotiated to the Framework’s clauses. Subdomain 3.4.2 adds that material outsourcing requires SAMA’s approval and that the cyber security function must be involved; the Rules on Outsourcing set the materiality test and the no-objection process. A cloud service is therefore submitted once, on a file that satisfies both subdomains. Our guide to SAMA outsourcing covers the materiality test and the submission.

Data in Saudi Arabia

Consideration 4b sets the default — services located in the Kingdom — and the exception — explicit SAMA approval for services outside it. The practical consequences: the provider’s KSA region is the baseline architecture; any component that processes or stores the organisation’s data elsewhere — support access, backups, disaster recovery replicas, SaaS control planes, analytics — is either kept in-region or named in the approval request; and the Personal Data Protection Law’s cross-border transfer rules apply in parallel for personal data. Our guide to the Saudi standard contractual clauses covers that layer.

The contract clauses the SAMA cloud computing requirements demand

Clause Source What it must secure
Security schedule 4a.3, 4d The controls from the risk assessment, with the provider’s obligation to implement and monitor them
Data location 4b Named regions for processing, storage, backup, DR and support access; no change without the organisation’s consent and, where outside KSA, SAMA’s approval
Purpose limitation 4c No secondary use of the organisation’s data
Segregation 4e Logical segregation and the provider’s ability to identify the organisation’s data at all times
Continuity 4f Availability and recovery commitments meeting the organisation’s business continuity policy; the provider’s participation in tests
Review, audit and examination rights 4g Three rights for the organisation — and, through 3.4.1 and the outsourcing rules, for SAMA
Termination and exit 4h Termination rights; data returned in a usable format; irreversible deletion with evidence
Sub-contracting 3.4.1, outsourcing rules Consent and notification before the provider extends the chain

SAMA cloud computing requirements, outsourcing and the NCA

Regime When it applies What it adds
SAMA CSF 3.4.3 Any hybrid or public cloud service used by a Member Organization The policy, the SAMA approval, data location and the eight contract areas above
SAMA CSF 3.4.2 and the Rules on Outsourcing Where the cloud service is an outsourcing arrangement — almost always Materiality assessment, prior no-objection for material arrangements, cyber security function involvement, contract, monitoring and exit
SAMA CSF 3.4.1 Every provider Contract and vendor management: due diligence, cyber security requirements in contracts, periodic review
NCA Cloud Cybersecurity Controls (CCC) Where the organisation is also within NCA scope — for example through critical national infrastructure — as a cloud tenant or provider The NCA’s own control set for cloud tenants and CSPs
PDPL Personal data in the cloud Cross-border transfer conditions and controller obligations

Our guide to the NCA cybersecurity controls covers where the CCC sits among the NCA’s sets.

From proposal to SAMA approval

  1. Classify the service. Hybrid or public (3.4.3 applies) or private (it does not); material or non-material outsourcing under the Rules; personal data involved or not.
  2. Run the cyber security risk assessment. Data classification, the control set the provider must implement, the residual risk, and the business continuity requirements inherited from the BIA.
  3. Do the due diligence. The provider’s certifications and assurance reports, its KSA region and data flows, its sub-processors, its exit capability.
  4. Negotiate the contract to the eight areas. Security schedule, location, purpose limitation, segregation, continuity, the three audit rights, exit, sub-contracting.
  5. Submit to SAMA. Risk assessment, due diligence, the draft contract, the data-location statement and, if any component is outside the Kingdom, the explicit request — before signature and before use.
  6. Register, monitor, measure. Enter the service in the cloud register with its approval; monitor compliance with the policy; measure the controls’ effectiveness for the maturity assessment.

Frequently asked questions

What are the SAMA cloud computing requirements?
Subdomain 3.4.3 of the SAMA Cyber Security Framework: a cloud computing policy for hybrid and public cloud that is defined, approved, implemented, monitored and measured, and that requires a risk assessment and due diligence, SAMA’s approval before use or contract, data located in Saudi Arabia unless SAMA explicitly approves otherwise, no secondary use, segregation, business continuity, review, audit and examination rights, and return and irreversible deletion on exit.

Does SAMA have to approve every cloud service?
Consideration 4a.2 requires SAMA’s approval prior to using cloud services or signing the contract with the provider, for hybrid and public cloud; private cloud is outside the subdomain. Material outsourcing separately requires SAMA’s approval under 3.4.2 and the Rules on Outsourcing.

Can a Saudi bank use a cloud region outside the Kingdom?
Only with explicit SAMA approval. Consideration 4b states that in principle only cloud services located in Saudi Arabia should be used, and that use outside the Kingdom requires the Member Organization to obtain explicit approval from SAMA.

Does 3.4.3 apply to private cloud?
No. The subdomain states that the requirement is not applicable to private cloud services — internal cloud. Private cloud is governed by the rest of the Framework’s operations and technology controls.

Do the NCA cloud controls also apply?
Where the institution is within the NCA’s scope — for example as an operator of critical national infrastructure — the NCA Cloud Cybersecurity Controls apply in addition to SAMA’s requirements, as tenant or provider.

Where this leaves you

Treat the SAMA cloud computing requirements as three gates and eight clauses: assess and do due diligence, obtain SAMA’s approval before signing or using, and sign a contract that secures location in the Kingdom, purpose limitation, segregation, continuity, the three audit rights and a real exit — then register, monitor and measure the service, because 3.4.3 is scored on the same maturity model as everything else and the approval letter is only the beginning of the evidence.

References

More on SAMA

The cloud computing policy, the cloud service risk assessment and due diligence templates, the SAMA approval submission checklist, the contract clause schedule and the cloud services register are in the SAMA Compliance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.