Work on the SAMA CSF starts from its structure, not a checklist: four domains, 32 subdomains, and a maturity level scored on each one. Two decisions shape the programme. The first is which subdomains apply to you, since non-bank institutions are excused three subdomains, two of which return in narrower form the moment you touch card data, SWIFT or online customer services. The second is the target level, because SAMA set level 3 as the floor and then told banks to reach level 4 on four operations subdomains. Learn the requirements, then price the mandates that create the recurring cost: a cleared full-time CISO, annual penetration tests and independent audits. Only then judge tooling on whether it records maturity as a status rather than a checkbox.
3 pages on SAMA CSF, in the order the work happens. Jump to the stage you are at, or read straight through.
Score your position subdomain by subdomain against the right target level, and budget the CISO, testing and audit mandates that create the recurring cost.
Judge platforms on whether they keep the control tree, record maturity as a status and track evidence expiry per artefact, not on a checkbox count.
These sit under another subject but bear directly on SAMA CSF.
The free compliance check runs the SAMA CSF gap assessment in about five minutes and gives you a scored report you can take to a board meeting.
14-day free trial · no credit card · unlimited users