Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SAMA compliance and the Cyber Security Framework for Saudi financial institutions

SAMA Compliance: The Cyber Security Framework Maturity Levels

SAMA compliance is unusual among financial regulations in one specific way: you are not assessed as compliant or non-compliant. You are assessed at a maturity level, on a scale of nought to five, and the regulator audits you to determine which one you are at.

That changes how you should plan. A binary regime rewards getting controls in place. A maturity regime rewards evidence that they operate, are measured, and improve — which takes considerably longer to build.

What SAMA compliance covers, and where the rules live

The Saudi Central Bank — still universally abbreviated SAMA — publishes its requirements through the SAMA Rulebook, organised by sector: banking, finance, payment systems and payment service providers, money exchange, credit bureaus, and the regulatory sandbox, plus a set of requirements applying across multiple sectors.

Every SAMA compliance question starts here. Each item in the Rulebook carries a status. That matters more than it sounds — a framework you find in a consultant’s slide deck may have been superseded, and the Rulebook is where you check.

The SAMA Cyber Security Framework

The centrepiece for most organisations is the Cyber Security Framework, issued under Circular No. 381000091275 dated 24 May 2017, and recorded in the Rulebook as In-Force.

Its applicability is broad. It covers all banks operating in Saudi Arabia, all insurance and reinsurance companies, all financing companies, all credit bureaus, and the Financial Market Infrastructure.

The Framework is structured around four domains:

  • Cyber Security Leadership and Governance
  • Cyber Security Risk Management and Compliance
  • Cyber Security Operations and Technology
  • Third Party Cyber Security

Each domain contains subdomains, and each subdomain states a principle, an objective and a set of control considerations — the mandated controls, uniquely numbered, running up to four levels deep.

All four domains apply in full to the banking sector. Other financial institutions get defined exceptions: subdomain 3.2.3 is excluded unless the organisation stores, processes or transmits cardholder data or uses SWIFT services — in which case PCI DSS and/or the SWIFT Customer Security Controls Framework apply instead — and subdomains 3.3.12 and 3.3.13 are excluded, again with conditions.

Check your sector’s exceptions before scoping any SAMA compliance work. Organisations routinely implement banking-sector requirements they were never subject to, and occasionally skip ones they were.

The SAMA compliance maturity model is the assessment

The six SAMA compliance maturity levels in the Cyber Security Framework

SAMA reviews and audits member organisations to determine both the level of compliance with the Framework and the cyber security maturity level achieved. Six levels are defined, 0 to 5, and they are cumulative: to reach 3, 4 or 5 you must first meet every criterion of the preceding levels.

The step that consumes most programmes is 3 to 4, and the reason is visible in the definitions.

Level 3 — structured and formalized — asks for controls defined, approved and implemented; policies, standards and procedures established; compliance monitored, preferably with a GRC tool; and key performance indicators defined, monitored and reported. That is achievable through documentation and discipline.

Level 4 — managed and measurable — asks whether the controls actually work. Effectiveness periodically assessed and improved, the measurement documented, key risk indicators and trend reporting used to judge effectiveness, and results feeding identified improvements.

That is the real SAMA compliance gap. The difference is between recording that a control exists and demonstrating, with data over time, that it is effective. You cannot produce that retrospectively — it requires a year of measurement you either started or did not.

SAMA also publishes separate Maturity Level 4 Requirements material for banks, which tells you where the supervisory expectation sits for that sector.

How SAMA compliance relates to international standards

Standard How it helps
ISO 27001 The closest fit. A certified ISMS delivers much of levels 3 and 4 — defined controls, monitoring, internal audit, management review and improvement — in a form SAMA’s model recognises
NIST CSF Useful for structuring the four domains and for board-level conversation, though the control considerations remain more prescriptive
ISO 22301 SAMA maintains separate business continuity expectations; a certified BCMS answers them coherently rather than piecemeal
ISO 31000 Gives the risk management and compliance domain one method rather than a bespoke cyber risk scale

None of these substitutes for the Framework — SAMA assesses against its own control considerations. What they do is supply the management system underneath, which is precisely what levels 3 and 4 are testing.

Where to start with SAMA compliance

  1. Confirm your sector and its exceptions in the Rulebook before scoping anything.
  2. Establish your current maturity level honestly, control consideration by control consideration.
  3. Set the target level with the board, because it determines cost and timeline more than any other decision.
  4. Start measuring now if level 4 is the target. Effectiveness data cannot be back-filled.
  5. Do not skip Third Party Cyber Security. It is a full domain and the one most often under-documented.
  6. Check status in the Rulebook, not in secondary summaries — items carry an in-force status for a reason.

This guide reflects the SAMA Rulebook at 15 August 2026, on which the Cyber Security Framework of 24 May 2017 is recorded as In-Force.

The SAMA Compliance Toolkit provides 38 editable documentation templates covering the four domains, the maturity self-assessment, the policies and standards level 3 requires, and the measurement and reporting records level 4 asks for.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.