NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
SAMA CSF Compliance Cost: What Drives It
Learn

SAMA CSF Compliance Cost: What Drives It

·Alexander Sverdlov

There is no published figure for SAMA Cyber Security Framework compliance, and any article that quotes one is quoting itself. What the Saudi Central Bank published is a framework and a circular, and between them they mandate the things that create the cost: a full time CISO who must hold Saudi nationality and be cleared by SAMA before appointment, a cyber security function that is not allowed to sit inside IT, annual reviews and penetration tests on customer and internet facing services, independent audits performed to recognised auditing standards, and a documented maturity level 3 across four domains and 32 subdomains.

So the honest way to budget for the CSF is to price the mandates rather than hunt for a benchmark. Circular No. 381000091275, which issued the Framework, required financial institutions to run a gap assessment, develop a roadmap to meet all requirements of maturity level 3 as a minimum, submit that roadmap to SAMA by the end of August 2017, report quarterly from the end of Q3 2017, and reach full compliance by the end of October 2018. Those dates have passed. The standing obligation has not, and neither has the recurring cost of holding the level once you reach it.

FactDetail
Governing documentsThe SAMA Cyber Security Framework, version 1.0 of May 2017, issued under Circular No. 381000091275, which the SAMA Rulebook lists as in force.
Who it applies toAll banks, all insurance and reinsurance companies, all financing companies, all credit bureaus operating in Saudi Arabia, and the Financial Market Infrastructure.
StructureFour domains divided into 32 subdomains. Each subdomain states a principle, an objective and mandated control considerations.
Maturity modelSix levels, 0 to 5. To reach level 3, 4 or 5 you must first meet all criteria of the preceding levels.
The minimumMaturity level 3, described in the Framework as structured and formalized, for all requirements set out in the CSF.
Published costNone. SAMA sets requirements and assesses maturity. It does not price compliance.
How it is assessedA periodic self assessment by the member organisation, which SAMA then reviews and audits.
Sector scopingAll domains apply to banks. Other financial institutions exclude subdomains 3.2.3, 3.3.12 and 3.3.13, with conditions.
SAMA CSF cost drivers: maturity level 3 as the minimum, four domains and 32 subdomains to evidence, annual review and penetration tests, and a full time Saudi national CISO cleared by SAMA

What does SAMA CSF compliance cost?

Any single number is wrong until four things are known, and none of them is your revenue.

The first is whether you are a bank. Section 1.4 of the Framework applies all domains to the banking sector, and gives other financial institutions three exclusions: subdomain 3.2.3 is excluded, though PCI DSS or the SWIFT Customer Security Controls Framework should be implemented if you store, process or transmit cardholder data or use SWIFT services; subdomain 3.3.12 is excluded; and subdomain 3.3.13 is excluded, though a multi factor authentication capability should be implemented if you provide online services to customers. Alignment with the banking sector cyber security strategy under subdomain 3.1.2 is mandatory when applicable. Establishing which of those applies to you is an hour of reading that moves the scope of the whole programme.

The second is your starting maturity. The gap between level 2, which the Framework calls repeatable but informal, and level 3 is the gap between doing something and being able to demonstrate it, per subdomain, on demand. The third is whether you already hold certifications with overlapping evidence. The fourth is your target level: level 3 is a floor, not a ceiling, and SAMA measures where you actually are.

The SAMA CSF maturity model above the minimum, from level 2 repeatable but informal through level 3 structured, level 4 managed and measurable, to level 5 adaptive

Which requirements actually create the cost?

These are the lines that show up in real SAMA programmes, each traced to where the Framework mandates it. The point of reading them as budget lines is that most of them are people and recurring services, not software.

Budget lineWhere the CSF puts itWhy it costs
The CISO3.1.1 Cyber Security GovernanceA full time senior manager at senior management level. The Framework requires the member organisation to ensure the CISO holds Saudi nationality, is sufficiently qualified, and to obtain no objection from SAMA to assign them. That is a constrained hiring market and a regulatory approval step, not a job posting.
An independent function3.1.1 Cyber Security GovernanceThe cyber security function must be independent from the information technology function, with separate reporting lines, budgets and staff evaluations, reporting to the CEO, managing director or a control function head. You cannot fund this out of the IT budget by design.
The committee3.1.1 Cyber Security GovernanceA cyber security committee mandated by the board, headed by an independent senior manager from a control function, with an approved charter and a minimum of quarterly meetings. The board must allocate sufficient budget to execute the required activities.
Documentation to level 32.4.1 Maturity Level 3A board endorsed policy, standards beneath it and procedures beneath those, with compliance monitored, preferably using a governance, risk and compliance tool, and key performance indicators defined, monitored and reported.
Reviews and penetration tests3.2.4 Cyber Security ReviewPeriodic reviews of critical information assets, and customer and internet facing services subject to annual review and penetration tests, with recorded results and follow up reviews to confirm issues were actually closed.
Independent audits3.2.5 Cyber Security AuditsAudits performed independently, according to generally accepted auditing standards and the CSF, and to the organisation's own audit manual and plan.
Incident capability3.3.15 Cyber Security Incident ManagementA designated team, skilled and continuously trained staff, sufficient capacity of certified forensic staff whether internal or contracted, and a restricted area for the response team's workspaces. Medium and high classified incidents go to SAMA IT Risk Supervision immediately, and no objection is required before any media interaction.
Awareness3.1.6 Cyber Security AwarenessA programme for staff, third parties and customers, conducted throughout the year across multiple channels, and evaluated for effectiveness. The customer limb is the one most budgets miss.
Third party and cloud approvals3.4.2 and 3.4.3SAMA approval is required before material outsourcing and before using cloud services or signing a cloud contract, and in principle only cloud services located in Saudi Arabia should be used. Approval time is schedule cost even when the fee is zero.

Two of these deserve a second look because they behave unlike anything in an EU regime. The CISO requirement is a hiring constraint written into a cyber security framework, and it interacts with a national talent market rather than with your salary band. The forensic and restricted workspace requirements in 3.3.15 are capital and facilities cost sitting inside a control that most readers scan as process.

Where a SAMA CSF budget goes, from gap assessment against the framework through a roadmap to maturity level 3 and an independent function to documentation, GRC tooling and annual audits

Why the recurring number is the real one

The Framework is not built around a submission date. Section 2.3 makes implementation subject to a periodic self assessment based on a questionnaire, which SAMA then reviews and audits to determine both compliance and maturity level. Level 3 itself requires monitored compliance and reported key performance indicators, which is a standing activity rather than a deliverable.

Read the recurring lines together and the shape becomes obvious. Annual penetration tests on customer facing services. Independent audits on a plan. Awareness activities throughout the year. Periodic measurement and evaluation. A self assessment SAMA can review at any point. A programme that treats the CSF as a one off remediation project pays for the same evidence twice, once to build it and again to rebuild it when the next assessment finds it stale. The same trap shows up in EU regimes, and we made the identical argument about NIS2 compliance cost using Germany's own published estimates.

What the other results get wrong

Four things, and the first is the most common.

Quoting a control count as settled fact. Published figures for the number of SAMA CSF controls differ widely, because the Framework numbers control considerations within each subdomain and nests sub-items beneath them, so any total depends on where you stop counting. There is no need for the number at all. Scope your programme on the 32 subdomains, which the Framework does state, and count the considerations you will actually evidence.

Presenting level 3 as the finish line. The circular sets it as the minimum. Levels 4 and 5 exist, level 4 requires defined key risk indicators and trend reporting, and a supervisor comparing peers is not obliged to be satisfied by a floor.

Treating the CSF as a documentation exercise. The nationality requirement and the SAMA no objection for the CISO cannot be written, and neither can certified forensic capacity or an independent function with its own budget.

Reporting the October 2018 deadline as though it closed the matter. It was the date for reaching full compliance, not the date the obligation ended. New entrants and newly licensed institutions face the same requirements today.

A SAMA CSF programme view tracking subdomains at maturity level 3 or above, control items with evidence, open waivers awaiting SAMA and days to produce the self assessment

Size your own SAMA CSF budget

Fill this in. It will not produce a price, and it is not meant to. It will tell you which of the nine budget lines above is going to dominate yours.

QuestionYour answerWhat it decides
Are you a bank, or another SAMA supervised institution?Banks take all domains. Others exclude 3.2.3, 3.3.12 and 3.3.13, subject to the PCI DSS, SWIFT and MFA conditions.
Do you have a full time CISO who meets the 3.1.1 conditions?The longest lead time in the programme, because it needs a qualified Saudi national and SAMA no objection.
Is your cyber security function independent of IT, with its own budget?If not, this is organisational change and headcount rather than tooling.
What is your current maturity, honestly, per subdomain?The distance from level 2 to level 3 is documentation plus demonstrable implementation across all 32.
When were your customer facing services last penetration tested?Subdomain 3.2.4 makes this annual, so it is a recurring line rather than a project cost.
Do you have certified forensic capacity and a restricted response workspace?Subdomain 3.3.15 asks for both. Contracting the forensic capacity is the usual answer.
Are any material outsourcing or cloud arrangements awaiting SAMA approval?Approval time is schedule cost, and cloud is in principle expected to be located in Saudi Arabia.

If several rows are blank, price the gap assessment first and nothing else. A free compliance check gives you a starting position, and our SAMA CSF compliance software holds the maturity assessment and its evidence in the structure the self assessment is actually reported in.

The bottom line on SAMA CSF cost: SAMA never published a price, only the requirements that create one

Frequently asked questions

How much does SAMA CSF compliance cost?

SAMA has not published a figure and no reliable public benchmark exists. Cost is driven by whether you are a bank, your current maturity per subdomain, and how much of the mandated structure, meaning a cleared full time CISO, an independent function, forensic capacity and recurring audits, you already have.

What maturity level does SAMA require?

Level 3 as a minimum, for all requirements set out in the CSF, under Circular No. 381000091275. The Framework describes level 3 as controls defined, approved and implemented in a structured and formalized way, with implementation that can be demonstrated.

Does the CSF apply to us if we are not a bank?

If SAMA supervises you, yes. The Framework names banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure. Non-banks get three subdomain exclusions, each with a condition attached.

Can we use a cloud provider outside Saudi Arabia?

The cloud computing policy required by subdomain 3.4.3 states that in principle only cloud services located in Saudi Arabia should be used, and SAMA approval must be obtained before using cloud services or signing the contract. Treat any other arrangement as an approval question rather than a procurement one.

What if a control genuinely does not fit our organisation?

The Framework is principle based. Where a control consideration cannot be tailored or implemented, it directs you to consider compensating controls, pursue an internal risk acceptance and request a formal waiver from SAMA, with the process set out in Appendix D.

Primary sources

Structure, applicability, the maturity model and every control reference above are taken from the SAMA Cyber Security Framework, version 1.0 of May 2017, as published on the SAMA Rulebook. The maturity level 3 minimum and the 2017 and 2018 milestones come from the English text of Circular No. 381000091275 on the same Rulebook, which notes that the governing text is the Arabic one. No cost figure in this article is attributed to SAMA, because SAMA has published none. Confirm the current version of both documents before relying on a reference.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING