Venvera is SAMA CSF compliance software for the Saudi Central Bank’s Cyber Security Framework, keeping its domains, subdomains, controls and maturity levels audit-ready for your SAMA supervision, without rebuilding the evidence every review cycle.
Venvera is SAMA CSF compliance software for the Member Organizations supervised by the Saudi Central Bank: banks, insurers and reinsurers, financing companies, credit bureaus and the Financial Market Infrastructure. It carries the Cyber Security Framework as 4 domains and 32 subdomains, scores each one against the 6-level maturity model SAMA assesses you on, and names the evidence behind every score. Because SAMA expects Level 3 or higher, the shortfall against target stays visible per subdomain, and the periodic self-assessment workbook exports from the same live record.
The SAMA Cyber Security Framework (v1.0, May 2017) is the Saudi Central Bank’s mandatory cyber security regime for every organisation it supervises - banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure. It is principle-based, structured around 4 domains, 32 subdomains and roughly 118 control considerations, and it is assessed against a 6-level maturity model from 0 Non-existent to 5 Adaptive. This is not a badge you choose to pursue: SAMA mandates it for its Member Organizations, your maturity is measured against a target of Level 3 or higher, and shortfalls surface in a supervisory review and draw supervisory action. Venvera keeps every subdomain scored, every control evidenced and the periodic self-assessment workbook ready to submit, so the next review is a report you export rather than a project you start.

SAMA requires a periodic self-assessment scored on its 6-level maturity model, from 0 Non-existent to 5 Adaptive, with Member Organizations expected to hold Level 3 or higher. Venvera scores every subdomain against current versus target maturity, computes per-domain and overall scores in real time, and surfaces the gaps that pull you below target - so the annual spreadsheet sprint becomes a live dashboard.

Section 3.1 puts the board on the hook for cyber security and requires a committee chaired by an independent senior manager. Venvera tracks the committee charter, meeting cadence and agenda, the CISO appointment requirement including the Saudi-nationality consideration, and the full cyber security policy lifecycle with board endorsement - all evidenced for the SAMA reviewer.

Section 3.2 asks for a structured risk process, ongoing monitoring of SAMA and Kingdom regulatory change, alignment to international standards, periodic effectiveness reviews and independent audits. Venvera couples its risk register, a regulatory updates feed and the audit log so the whole domain runs as a single programme instead of five disconnected efforts.

Section 3.3 is the operational heart of the framework - 17 subdomains from HR screening to vulnerability management, payment systems and electronic banking. Venvera renders each as a checklist of control considerations with status, owner and evidence link, and applies the bank versus non-bank exclusions for 3.3.12 and 3.3.13 automatically, so scope reflects your entity type without manual reasoning.

Section 3.4 - vendor contracts, outsourcing governance and cloud - is one of the most-cited gaps in SAMA assessments. Venvera wires its third-party module directly to the outsourcing subdomains: every supplier carries the SAMA-required clauses, questionnaire results and sub-outsourcing visibility, and cloud providers are tracked separately with data-localisation status and shared-responsibility evidence.

SAMA expects an actively engaged board and a clean self-assessment. Venvera produces the cyber security committee deck, the periodic self-assessment workbook for submission and the auditor evidence package, each pre-filled from your live data - no copy-paste between the GRC tool and Word the week before a review.

Start with a free gap report across the SAMA CSF domains - 10 minutes, no email to start.
✓ Every paid plan: audit-ready in 90 days, or your money back*
10 minutes · no email to start · no credit card · yours to keep