SAMA CSF maturity self-assessment
Rate your maturity across all 32 subdomains of the SAMA Cyber Security Framework using SAMA's own six-level maturity model, and see where you sit against the required target of level 3. Runs in your browser — no signup, nothing transmitted anywhere.
—
Average maturity (target 3.0)
—
Subdomains below level 3
0
of 32 rated
3.1 Cyber Security Leadership and Governance
- 3.1.1 Cyber Security Governance
- 3.1.2 Cyber Security Strategy
- 3.1.3 Cyber Security Policy
- 3.1.4 Cyber Security Roles and Responsibilities
- 3.1.5 Cyber Security in Project Management
- 3.1.6 Cyber Security Awareness
- 3.1.7 Cyber Security Training
3.2 Cyber Security Risk Management and Compliance
- 3.2.1 Cyber Security Risk Management
- 3.2.2 Regulatory Compliance
- 3.2.3 Compliance with (Inter)national Industry Standards Excluded for non-banking member organisations, unless cardholder data or SWIFT services are involved
- 3.2.4 Cyber Security Review
- 3.2.5 Cyber Security Audits
3.3 Cyber Security Operations and Technology
- 3.3.1 Human Resources
- 3.3.2 Physical Security
- 3.3.3 Asset Management
- 3.3.4 Cyber Security Architecture
- 3.3.5 Identity and Access Management
- 3.3.6 Application Security
- 3.3.7 Change Management
- 3.3.8 Infrastructure Security
- 3.3.9 Cryptography
- 3.3.10 Bring Your Own Device (BYOD)
- 3.3.11 Secure Disposal of Information Assets
- 3.3.12 Payment Systems Excluded for non-banking member organisations
- 3.3.13 Electronic Banking Services
- 3.3.14 Cyber Security Event Management
- 3.3.15 Cyber Security Incident Management
- 3.3.16 Threat Management
- 3.3.17 Vulnerability Management
3.4 Third Party Cyber Security
- 3.4.1 Contract and Vendor Management
- 3.4.2 Outsourcing
- 3.4.3 Cloud Computing
About the SAMA maturity model
The SAMA Cyber Security Framework is assessed against a six-level maturity model. Reaching levels 3, 4 or 5 requires first meeting all criteria of the preceding levels — you cannot skip a level.
| Level | What it means |
|---|---|
| 0 — Non-existent | No documentation; no awareness or attention |
| 1 — Ad-hoc | Controls partially defined, performed inconsistently |
| 2 — Repeatable but informal | Informal, unwritten but standardised practice |
| 3 — Structured and formalized | Defined, approved, implemented; compliance monitored |
| 4 — Managed and measurable | Effectiveness periodically measured and improved |
| 5 — Adaptive | Continuous improvement; integrated with enterprise risk |
SAMA states that member organisations should operate at maturity level 3 or higher. Level 3 requires cyber security controls to be defined, approved and implemented in a structured way, with compliance monitored — the framework notes this monitoring is preferably done using a governance, risk and compliance (GRC) tool, with key performance indicators defined and reported.
The framework applies to all SAMA-regulated member organisations: banks, insurance and reinsurance companies, financing companies, credit bureaus and the financial market infrastructure. Some subdomains are excluded for non-banking organisations — those are flagged above; mark them "Not applicable" to keep them out of your score.
This is not an official SAMA instrument. SAMA member organisations complete a periodic self-assessment based on SAMA's own questionnaire, which is then reviewed and audited by SAMA. Use this page to find gaps early, and work from the official framework document for compliance purposes.
For platforms that maintain SAMA CSF control libraries and evidence continuously, see our compliance software comparison and GRC platform rankings. Also try the NCA ECC self-assessment — most Saudi organisations need both.