Cybersecurity
DETAIL

Saudi Arabia SAMA Cybersecurity Framework v1.0

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The Saudi ArabiaSAMA Cybersecurity Framework v1.0 is a regulatory framework thathelps financial institutions in Saudi Arabia establish, implement,and maintain effective cybersecurity controls to protect theirinformation assets and ensure regulatory compliance. The frameworkaims to enhance the overall cyber resilience of the financial sectorand reduce risks associated with cyber threats.

Published by theSaudi Arabian Monetary Authority (SAMA), the framework is mandatoryfor banks, insurance companies, and other financial institutionsregulated by SAMA. It covers critical focus areas such ascybersecurity governance, risk management, operational resilience,incident management, and compliance oversight, aligning nationalrequirements with global security best practices.

Organizationsimplement the SAMA Cybersecurity Framework by conductingself-assessments, establishing required security controls, andintegrating the framework into ongoing risk management and complianceprograms. The framework supports audit readiness and helps financialorganizations coordinate their cybersecurity efforts with otherinternational standards, such as ISO 27001 and NIST frameworks.

Why it Matters

The SAMACybersecurity Framework establishes a unified foundation forprotecting the Saudi financial sector’s critical assets andensuring regulatory compliance.

Key benefitsinclude:

•  Strengthen cybersecurity governance

Promote clearleadership accountability and structured management of cybersecurityrisks throughout the entire organization.

•  Enhance regulatory alignment

Supportinstitutions in meeting SAMA and national requirements, minimizingcompliance gaps and legal exposure.

•  Promote operational resilience

Helporganizations withstand and recover from cyber incidents, ensuringcontinuity of financial services and operations.

•  Improve risk-based decision making

Enable proactiveidentification, assessment, and mitigation of threats by integratingrisk management into business processes.

•  Increase audit readiness

Ensure robustdocumentation and repeatable controls, streamlining internal andexternal audit cycles and reducing regulatory scrutiny.

How it Works

The Saudi ArabiaSAMA Cybersecurity Framework v1.0 structures cybersecurityrequirements into six main domains: Cybersecurity Governance,Cybersecurity Risk Management, Cybersecurity Operations, Third PartySecurity, Cybersecurity Resilience, and Cybersecurity Compliance.Within these domains, the framework outlines specific controlobjectives and related controls, supported by a maturity model thatenables organizations to assess and improve their cybersecurityposture over time.

Organizationsimplement the SAMA Cybersecurity Framework by mapping its controlobjectives to their internal security controls, policies, and riskmanagement practices. Typical activities include conducting riskassessments, addressing regulatory requirements, strengtheninggovernance structures, monitoring cybersecurity operations, andperforming regular compliance assessments. The framework supportscontinuous improvement through periodic reviews, fostering a cycle ofevaluation and enhancement of security practices to align withregulatory and industry standards.

With SmartSuite,organizations can operationalize the SAMA Cybersecurity Framework byleveraging control libraries for framework mapping, utilizing riskregisters for risk management, and enabling policy governanceworkflows. SmartSuite further streamlines evidence collection,compliance tracking, and remediation management while providingdashboards for monitoring security posture and audit readiness acrossgovernance programs.

Key Elements

•  Cybersecurity Leadership and Strategy

Specifies roles,responsibilities, and overall governance structure for managingcybersecurity within the organization.

•  Risk Management and Assessment

Establishessystematic processes for identifying, evaluating, and mitigatingcybersecurity risks specific to the entity.

•  Cybersecurity Operations and Controls

Describestechnical and procedural measures required to protect, detect, andrespond to cyber threats and incidents.

•  Technology and Asset Protection

Outlinesrequirements for safeguarding information assets, critical systems,and supporting technologies.

•  Third Party and Outsourcing Management

Defines controlsfor assessing, monitoring, and securing outsourced services andpartnerships involving external parties.

•  Awareness and Human Resource Security

Providesguidance for training personnel, promoting security culture, andprotecting against human-related threats.

•  Compliance and Audit Requirements

Organizesmechanisms for verifying adherence to legal, regulatory, andframework-specific cybersecurity obligations.

Framework Scope

The Saudi ArabiaSAMA Cybersecurity Framework v1.0 is adopted by financialinstitutions, banks, and insurance firms operating within theKingdom. It governs the security of information systems, paymentplatforms, and data assets, and is typically implemented whenfulfilling regulatory mandates, improving risk management, orsupporting assurance programs for regulatory and industry compliance.

Framework Objectives

The Saudi ArabiaSAMA Cybersecurity Framework provides a comprehensive basis formanaging cybersecurity risks, compliance, and organizationalresilience.

•  Strengthen cybersecurity governance and risk management acrossfinancial institutions

•  Safeguard sensitive data through effective security controls anddata protection measures

•  Enhance regulatory compliance with national standards andsupervisory requirements

•  Promote operational resilience by ensuring continuity andincident response readiness

•  Enable improved audit readiness and transparent oversight ofcybersecurity maturity The SAMA Cybersecurity Framework v1.0 isaligned with standards like ISO 27001, NIST Cybersecurity Framework,and the NCA ECC. Financial institutions in Saudi Arabia typicallyimplement it to meet regulatory requirements, strengthen securitygovernance, and ensure operational security in line with the SaudiArabian Monetary Authority’s expectations.

Common Framework Mappings

The SAMACybersecurity Framework is often mapped to globally recognizedstandards to support cross-border compliance, streamline assessments,and enhance organizational security posture within both local andinternational regulatory environments.

Mappedframeworks include:

CIS Controls

COBIT

CSA CloudControls Matrix

ISO/IEC 27001

ISO/IEC 27002

NISTCybersecurity Framework

NIST SP 800-53

PCI DSS

SOC 2

At a Glance
SAMA Cybersecurity Framework v1.0
  • checklist
    Classicifation
    Category
    info
    Cybersecurity
    Domain
    info
    Cybersecurity
    Framework Family
    info
    Other
  • info
    Regulatory Context
    Type
    info
    Control Framework
    Legal Instrument
    info
    Framework
    Sector
    info
    Financial Sector
    Industry
    info
    Financial Services
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Europe
    Region Detail
    info
    Saudi Arabia
    Publisher
    info
    Saudi Arabian Monetary Authority (SAMA)
  • published_with_changes
    Versioning
    Version
    info
    v1.0
    Effective Date
    info
    May 2017
    Issue Date
    info
    May 2017
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

Saudi Arabian Monetary Authority (SAMA) publishes the SAMA Cybersecurity Framework v1.0 and it's publicly available for download from SAMA's official website. License included with platform

Official Resources
SAMA Cybersecurity Framework v1.0
Provides detailed requirements and guidelines for cybersecurity in the financial sector in Saudi Arabia.
chevron_forward
SAMA Cybersecurity Implementation Guide
Outlines the implementation process for organizations adhering to the SAMA Cybersecurity Framework.
chevron_forward
SAMA Cybersecurity Control Catalogue
Defines specific technical controls required for compliance with the SAMA Cybersecurity Framework.
chevron_forward
SMARTSUITE

How SmartSuite Supports SAMA CSF

Manage Saudi Arabia SAMA Cybersecurity Framework (v1.0) by organizing financial sector security controls, tracking implementation across systems, and maintaining evidence supporting regulatory compliance and operational resilience.

Financial Control Framework Library

Structure SAMA control domains with ownership, scope, and implementation status across systems.

Risk Assessment and Regulatory Mapping

Link cybersecurity risks to SAMA controls and financial regulatory requirements.

Policy and Governance Management

Centralize security policies, standards, and approvals aligned to SAMA expectations.

Authentication, Access, and Operations Management

Manage authentication, privileged access, monitoring, and operational controls across environments.

Incident Response and Threat Management

Track incidents, investigations, and response workflows aligned to financial sector requirements.

SAMA Audit Readiness Reporting

Provide dashboards showing control coverage, risk posture, and readiness for SAMA audits.

Related frameworks

COBIT 2019

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
PCI DSS 4.0.1

PCI DSS v4.0.1 defines security requirements organizations must follow to protect payment card data during storage, processing, and transmission.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
SWIFT CSCF

SWIFT Customer Security Framework establishes baseline cybersecurity controls for organizations using the SWIFT network to secure financial transactions.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For Saudi Arabia SAMA Cybersecurity Framework v1.0

What is the SAMA Cybersecurity Framework v1.0 used for?

The SAMA Cybersecurity Framework v1.0 is designed to help financial institutions in Saudi Arabia establish and maintain effective cybersecurity controls. It aims to protect critical banking and financial sector assets from cyber threats and ensure regulatory compliance with the Saudi Arabian Monetary Authority’s requirements.

Is compliance with the SAMA Cybersecurity Framework mandatory?

Yes, compliance is mandatory for all SAMA-regulated entities, including banks, insurance companies, and finance companies operating in Saudi Arabia. Organizations are required to implement the framework’s controls and report on their compliance status to SAMA periodically.

Who does the SAMA Cybersecurity Framework apply to?

The framework applies to all banking, insurance, and finance entities regulated by SAMA, regardless of size or ownership structure. Vendors and third parties providing services to these entities may also be subject to relevant controls as part of the broader security program.

What are the key requirements of the SAMA Cybersecurity Framework?

Key requirements include establishing a cybersecurity governance structure, performing regular risk assessments, implementing technical and organizational cybersecurity controls, reporting incidents, and developing a continuous monitoring and improvement program. Documentation such as policies, procedures, and control evidences are required as part of compliance.

How should organizations approach implementing the SAMA Cybersecurity Framework?

Implementation should begin with a gap assessment against the framework’s controls, followed by prioritizing remediation based on identified risks. Organizations should tailor control implementation to their risk profile but must address all mandatory requirements, ensuring that responsibilities are clearly assigned and tracked.

How does the SAMA Cybersecurity Framework relate to other standards like ISO 27001 or NCA ECC?

While the SAMA Cybersecurity Framework shares similarities with international standards such as ISO 27001 and the National Cybersecurity Authority Essential Cybersecurity Controls (NCA ECC), it is specifically tailored to the Saudi financial sector. Organizations may leverage previous work on these standards but must address all unique SAMA requirements.

What are the ongoing compliance obligations under the SAMA Cybersecurity Framework?

Entities are expected to maintain compliance through annual self-assessments, formal attestation by executive management, and prompt reporting of any significant cybersecurity incidents. Continuous monitoring, regular updates to controls, and ongoing awareness training are required to maintain the security and compliance posture.

How would SmartSuite support Saudi Arabia SAMA Cybersecurity Framework v1.0?

SmartSuite can help organizations manage SAMA Cybersecurity Framework compliance by enabling centralized risk tracking, facilitating control documentation and assignment, and streamlining evidence collection. The platform supports audit readiness through automated workflows, status dashboards, and comprehensive reporting, making it easier to demonstrate compliance to regulators.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward