Skip to content
AuditGRC

SAMA Cyber Security Framework

Saudi Arabian Monetary Authority · Saudi Arabia · Updated July 30, 2026

The SAMA Cyber Security Framework sets cyber security requirements for organisations regulated by the Saudi Central Bank. Unlike the NCA ECC, it is principle-based: each subdomain states a principle, an objective and a set of control considerations, and compliance is expressed as a maturity level rather than an implemented/not-implemented state.

That difference matters in practice. Reaching the required maturity level 3 means controls are defined, approved, implemented and — critically — monitored on an ongoing basis, which is why most member organisations end up needing tooling rather than spreadsheets.

Structure at a glance

Main domains
4
Subdomains
32
Maturity levels
6 (0 to 5)
Required level
3 — Structured and formalized
Basis
Principle-based, not prescriptive

Structure and maturity model verified against SAMA's published Cyber Security Framework (Version 1.0).

Who is in scope

  • All banks operating in Saudi Arabia
  • All insurance and reinsurance companies operating in Saudi Arabia
  • All financing companies operating in Saudi Arabia
  • All credit bureaus operating in Saudi Arabia
  • The financial market infrastructure

How compliance is assessed

Member organisations complete a periodic self-assessment against SAMA’s questionnaire. SAMA then reviews and audits those self-assessments to determine the compliance level and maturity level, and compares maturity across member organisations.

Go deeper on SAMA CSF

Other frameworks