Saudi Arabia SAMA Cybersecurity Framework v1.0

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The Saudi ArabiaSAMA Cybersecurity Framework v1.0 is a regulatory framework thathelps financial institutions in Saudi Arabia establish, implement,and maintain effective cybersecurity controls to protect theirinformation assets and ensure regulatory compliance. The frameworkaims to enhance the overall cyber resilience of the financial sectorand reduce risks associated with cyber threats.
Published by theSaudi Arabian Monetary Authority (SAMA), the framework is mandatoryfor banks, insurance companies, and other financial institutionsregulated by SAMA. It covers critical focus areas such ascybersecurity governance, risk management, operational resilience,incident management, and compliance oversight, aligning nationalrequirements with global security best practices.
Organizationsimplement the SAMA Cybersecurity Framework by conductingself-assessments, establishing required security controls, andintegrating the framework into ongoing risk management and complianceprograms. The framework supports audit readiness and helps financialorganizations coordinate their cybersecurity efforts with otherinternational standards, such as ISO 27001 and NIST frameworks.
Why it Matters
The SAMACybersecurity Framework establishes a unified foundation forprotecting the Saudi financial sector’s critical assets andensuring regulatory compliance.
Key benefitsinclude:
• Strengthen cybersecurity governance
Promote clearleadership accountability and structured management of cybersecurityrisks throughout the entire organization.
• Enhance regulatory alignment
Supportinstitutions in meeting SAMA and national requirements, minimizingcompliance gaps and legal exposure.
• Promote operational resilience
Helporganizations withstand and recover from cyber incidents, ensuringcontinuity of financial services and operations.
• Improve risk-based decision making
Enable proactiveidentification, assessment, and mitigation of threats by integratingrisk management into business processes.
• Increase audit readiness
Ensure robustdocumentation and repeatable controls, streamlining internal andexternal audit cycles and reducing regulatory scrutiny.
How it Works
The Saudi ArabiaSAMA Cybersecurity Framework v1.0 structures cybersecurityrequirements into six main domains: Cybersecurity Governance,Cybersecurity Risk Management, Cybersecurity Operations, Third PartySecurity, Cybersecurity Resilience, and Cybersecurity Compliance.Within these domains, the framework outlines specific controlobjectives and related controls, supported by a maturity model thatenables organizations to assess and improve their cybersecurityposture over time.
Organizationsimplement the SAMA Cybersecurity Framework by mapping its controlobjectives to their internal security controls, policies, and riskmanagement practices. Typical activities include conducting riskassessments, addressing regulatory requirements, strengtheninggovernance structures, monitoring cybersecurity operations, andperforming regular compliance assessments. The framework supportscontinuous improvement through periodic reviews, fostering a cycle ofevaluation and enhancement of security practices to align withregulatory and industry standards.
With SmartSuite,organizations can operationalize the SAMA Cybersecurity Framework byleveraging control libraries for framework mapping, utilizing riskregisters for risk management, and enabling policy governanceworkflows. SmartSuite further streamlines evidence collection,compliance tracking, and remediation management while providingdashboards for monitoring security posture and audit readiness acrossgovernance programs.
Key Elements
• Cybersecurity Leadership and Strategy
Specifies roles,responsibilities, and overall governance structure for managingcybersecurity within the organization.
• Risk Management and Assessment
Establishessystematic processes for identifying, evaluating, and mitigatingcybersecurity risks specific to the entity.
• Cybersecurity Operations and Controls
Describestechnical and procedural measures required to protect, detect, andrespond to cyber threats and incidents.
• Technology and Asset Protection
Outlinesrequirements for safeguarding information assets, critical systems,and supporting technologies.
• Third Party and Outsourcing Management
Defines controlsfor assessing, monitoring, and securing outsourced services andpartnerships involving external parties.
• Awareness and Human Resource Security
Providesguidance for training personnel, promoting security culture, andprotecting against human-related threats.
• Compliance and Audit Requirements
Organizesmechanisms for verifying adherence to legal, regulatory, andframework-specific cybersecurity obligations.
Framework Scope
The Saudi ArabiaSAMA Cybersecurity Framework v1.0 is adopted by financialinstitutions, banks, and insurance firms operating within theKingdom. It governs the security of information systems, paymentplatforms, and data assets, and is typically implemented whenfulfilling regulatory mandates, improving risk management, orsupporting assurance programs for regulatory and industry compliance.
Framework Objectives
The Saudi ArabiaSAMA Cybersecurity Framework provides a comprehensive basis formanaging cybersecurity risks, compliance, and organizationalresilience.
• Strengthen cybersecurity governance and risk management acrossfinancial institutions
• Safeguard sensitive data through effective security controls anddata protection measures
• Enhance regulatory compliance with national standards andsupervisory requirements
• Promote operational resilience by ensuring continuity andincident response readiness
• Enable improved audit readiness and transparent oversight ofcybersecurity maturity The SAMA Cybersecurity Framework v1.0 isaligned with standards like ISO 27001, NIST Cybersecurity Framework,and the NCA ECC. Financial institutions in Saudi Arabia typicallyimplement it to meet regulatory requirements, strengthen securitygovernance, and ensure operational security in line with the SaudiArabian Monetary Authority’s expectations.
Common Framework Mappings
The SAMACybersecurity Framework is often mapped to globally recognizedstandards to support cross-border compliance, streamline assessments,and enhance organizational security posture within both local andinternational regulatory environments.
Mappedframeworks include:
CIS Controls
COBIT
CSA CloudControls Matrix
ISO/IEC 27001
ISO/IEC 27002
NISTCybersecurity Framework
NIST SP 800-53
PCI DSS
SOC 2
- ClassicifationCategoryCybersecurityDomainCybersecurityFramework FamilyOther
- Regulatory ContextTypeControl FrameworkLegal InstrumentFrameworkSectorFinancial SectorIndustryFinancial Services
- Region / PublisherRegionEuropeRegion DetailSaudi ArabiaPublisherSaudi Arabian Monetary Authority (SAMA)
- VersioningVersionv1.0Effective DateMay 2017Issue DateMay 2017
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
Saudi Arabian Monetary Authority (SAMA) publishes the SAMA Cybersecurity Framework v1.0 and it's publicly available for download from SAMA's official website. License included with platform
How SmartSuite Supports SAMA CSF
Manage Saudi Arabia SAMA Cybersecurity Framework (v1.0) by organizing financial sector security controls, tracking implementation across systems, and maintaining evidence supporting regulatory compliance and operational resilience.
Financial Control Framework Library
Structure SAMA control domains with ownership, scope, and implementation status across systems.
Risk Assessment and Regulatory Mapping
Link cybersecurity risks to SAMA controls and financial regulatory requirements.
Policy and Governance Management
Centralize security policies, standards, and approvals aligned to SAMA expectations.
Authentication, Access, and Operations Management
Manage authentication, privileged access, monitoring, and operational controls across environments.
Incident Response and Threat Management
Track incidents, investigations, and response workflows aligned to financial sector requirements.
SAMA Audit Readiness Reporting
Provide dashboards showing control coverage, risk posture, and readiness for SAMA audits.
Related frameworks

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

PCI DSS v4.0.1 defines security requirements organizations must follow to protect payment card data during storage, processing, and transmission.
Frequently Asked Questions For Saudi Arabia SAMA Cybersecurity Framework v1.0
The SAMA Cybersecurity Framework v1.0 is designed to help financial institutions in Saudi Arabia establish and maintain effective cybersecurity controls. It aims to protect critical banking and financial sector assets from cyber threats and ensure regulatory compliance with the Saudi Arabian Monetary Authority’s requirements.
Yes, compliance is mandatory for all SAMA-regulated entities, including banks, insurance companies, and finance companies operating in Saudi Arabia. Organizations are required to implement the framework’s controls and report on their compliance status to SAMA periodically.
The framework applies to all banking, insurance, and finance entities regulated by SAMA, regardless of size or ownership structure. Vendors and third parties providing services to these entities may also be subject to relevant controls as part of the broader security program.
Key requirements include establishing a cybersecurity governance structure, performing regular risk assessments, implementing technical and organizational cybersecurity controls, reporting incidents, and developing a continuous monitoring and improvement program. Documentation such as policies, procedures, and control evidences are required as part of compliance.
Implementation should begin with a gap assessment against the framework’s controls, followed by prioritizing remediation based on identified risks. Organizations should tailor control implementation to their risk profile but must address all mandatory requirements, ensuring that responsibilities are clearly assigned and tracked.
While the SAMA Cybersecurity Framework shares similarities with international standards such as ISO 27001 and the National Cybersecurity Authority Essential Cybersecurity Controls (NCA ECC), it is specifically tailored to the Saudi financial sector. Organizations may leverage previous work on these standards but must address all unique SAMA requirements.
Entities are expected to maintain compliance through annual self-assessments, formal attestation by executive management, and prompt reporting of any significant cybersecurity incidents. Continuous monitoring, regular updates to controls, and ongoing awareness training are required to maintain the security and compliance posture.
SmartSuite can help organizations manage SAMA Cybersecurity Framework compliance by enabling centralized risk tracking, facilitating control documentation and assignment, and streamlining evidence collection. The platform supports audit readiness through automated workflows, status dashboards, and comprehensive reporting, making it easier to demonstrate compliance to regulators.
Put CRI Profile into action with SmartSuite
Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

