NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new

SAMA CSF: four domains, the maturity floor and cost

Work on the SAMA CSF starts from its structure, not a checklist: four domains, 32 subdomains, and a maturity level scored on each one. Two decisions shape the programme. The first is which subdomains apply to you, since non-bank institutions are excused three subdomains, two of which return in narrower form the moment you touch card data, SWIFT or online customer services. The second is the target level, because SAMA set level 3 as the floor and then told banks to reach level 4 on four operations subdomains. Learn the requirements, then price the mandates that create the recurring cost: a cleared full-time CISO, annual penetration tests and independent audits. Only then judge tooling on whether it records maturity as a status rather than a checkbox.

3 pages on SAMA CSF, in the order the work happens. Jump to the stage you are at, or read straight through.

Choose tools

Judge platforms on whether they keep the control tree, record maturity as a status and track evidence expiry per artefact, not on a checkbox count.

Also relevant

These sit under another subject but bear directly on SAMA CSF.

Stop reading. Start scoring.

The free compliance check runs the SAMA CSF gap assessment in about five minutes and gives you a scored report you can take to a board meeting.

14-day free trial · no credit card · unlimited users