There is no published figure for SAMA Cyber Security Framework compliance, and any article that quotes one is quoting itself. What the Saudi Central Bank published is a framework and a circular, and between them they mandate the things that create the cost: a full time CISO who must hold Saudi nationality and be cleared by SAMA before appointment, a cyber security function that is not allowed to sit inside IT, annual reviews and penetration tests on customer and internet facing services, independent audits performed to recognised auditing standards, and a documented maturity level 3 across four domains and 32 subdomains.
So the honest way to budget for the CSF is to price the mandates rather than hunt for a benchmark. Circular No. 381000091275, which issued the Framework, required financial institutions to run a gap assessment, develop a roadmap to meet all requirements of maturity level 3 as a minimum, submit that roadmap to SAMA by the end of August 2017, report quarterly from the end of Q3 2017, and reach full compliance by the end of October 2018. Those dates have passed. The standing obligation has not, and neither has the recurring cost of holding the level once you reach it.
| Fact | Detail |
|---|---|
| Governing documents | The SAMA Cyber Security Framework, version 1.0 of May 2017, issued under Circular No. 381000091275, which the SAMA Rulebook lists as in force. |
| Who it applies to | All banks, all insurance and reinsurance companies, all financing companies, all credit bureaus operating in Saudi Arabia, and the Financial Market Infrastructure. |
| Structure | Four domains divided into 32 subdomains. Each subdomain states a principle, an objective and mandated control considerations. |
| Maturity model | Six levels, 0 to 5. To reach level 3, 4 or 5 you must first meet all criteria of the preceding levels. |
| The minimum | Maturity level 3, described in the Framework as structured and formalized, for all requirements set out in the CSF. |
| Published cost | None. SAMA sets requirements and assesses maturity. It does not price compliance. |
| How it is assessed | A periodic self assessment by the member organisation, which SAMA then reviews and audits. |
| Sector scoping | All domains apply to banks. Other financial institutions exclude subdomains 3.2.3, 3.3.12 and 3.3.13, with conditions. |
What does SAMA CSF compliance cost?
Any single number is wrong until four things are known, and none of them is your revenue.
The first is whether you are a bank. Section 1.4 of the Framework applies all domains to the banking sector, and gives other financial institutions three exclusions: subdomain 3.2.3 is excluded, though PCI DSS or the SWIFT Customer Security Controls Framework should be implemented if you store, process or transmit cardholder data or use SWIFT services; subdomain 3.3.12 is excluded; and subdomain 3.3.13 is excluded, though a multi factor authentication capability should be implemented if you provide online services to customers. Alignment with the banking sector cyber security strategy under subdomain 3.1.2 is mandatory when applicable. Establishing which of those applies to you is an hour of reading that moves the scope of the whole programme.
The second is your starting maturity. The gap between level 2, which the Framework calls repeatable but informal, and level 3 is the gap between doing something and being able to demonstrate it, per subdomain, on demand. The third is whether you already hold certifications with overlapping evidence. The fourth is your target level: level 3 is a floor, not a ceiling, and SAMA measures where you actually are.
Which requirements actually create the cost?
These are the lines that show up in real SAMA programmes, each traced to where the Framework mandates it. The point of reading them as budget lines is that most of them are people and recurring services, not software.
| Budget line | Where the CSF puts it | Why it costs |
|---|---|---|
| The CISO | 3.1.1 Cyber Security Governance | A full time senior manager at senior management level. The Framework requires the member organisation to ensure the CISO holds Saudi nationality, is sufficiently qualified, and to obtain no objection from SAMA to assign them. That is a constrained hiring market and a regulatory approval step, not a job posting. |
| An independent function | 3.1.1 Cyber Security Governance | The cyber security function must be independent from the information technology function, with separate reporting lines, budgets and staff evaluations, reporting to the CEO, managing director or a control function head. You cannot fund this out of the IT budget by design. |
| The committee | 3.1.1 Cyber Security Governance | A cyber security committee mandated by the board, headed by an independent senior manager from a control function, with an approved charter and a minimum of quarterly meetings. The board must allocate sufficient budget to execute the required activities. |
| Documentation to level 3 | 2.4.1 Maturity Level 3 | A board endorsed policy, standards beneath it and procedures beneath those, with compliance monitored, preferably using a governance, risk and compliance tool, and key performance indicators defined, monitored and reported. |
| Reviews and penetration tests | 3.2.4 Cyber Security Review | Periodic reviews of critical information assets, and customer and internet facing services subject to annual review and penetration tests, with recorded results and follow up reviews to confirm issues were actually closed. |
| Independent audits | 3.2.5 Cyber Security Audits | Audits performed independently, according to generally accepted auditing standards and the CSF, and to the organisation's own audit manual and plan. |
| Incident capability | 3.3.15 Cyber Security Incident Management | A designated team, skilled and continuously trained staff, sufficient capacity of certified forensic staff whether internal or contracted, and a restricted area for the response team's workspaces. Medium and high classified incidents go to SAMA IT Risk Supervision immediately, and no objection is required before any media interaction. |
| Awareness | 3.1.6 Cyber Security Awareness | A programme for staff, third parties and customers, conducted throughout the year across multiple channels, and evaluated for effectiveness. The customer limb is the one most budgets miss. |
| Third party and cloud approvals | 3.4.2 and 3.4.3 | SAMA approval is required before material outsourcing and before using cloud services or signing a cloud contract, and in principle only cloud services located in Saudi Arabia should be used. Approval time is schedule cost even when the fee is zero. |
Two of these deserve a second look because they behave unlike anything in an EU regime. The CISO requirement is a hiring constraint written into a cyber security framework, and it interacts with a national talent market rather than with your salary band. The forensic and restricted workspace requirements in 3.3.15 are capital and facilities cost sitting inside a control that most readers scan as process.
Why the recurring number is the real one
The Framework is not built around a submission date. Section 2.3 makes implementation subject to a periodic self assessment based on a questionnaire, which SAMA then reviews and audits to determine both compliance and maturity level. Level 3 itself requires monitored compliance and reported key performance indicators, which is a standing activity rather than a deliverable.
Read the recurring lines together and the shape becomes obvious. Annual penetration tests on customer facing services. Independent audits on a plan. Awareness activities throughout the year. Periodic measurement and evaluation. A self assessment SAMA can review at any point. A programme that treats the CSF as a one off remediation project pays for the same evidence twice, once to build it and again to rebuild it when the next assessment finds it stale. The same trap shows up in EU regimes, and we made the identical argument about NIS2 compliance cost using Germany's own published estimates.
What the other results get wrong
Four things, and the first is the most common.
Quoting a control count as settled fact. Published figures for the number of SAMA CSF controls differ widely, because the Framework numbers control considerations within each subdomain and nests sub-items beneath them, so any total depends on where you stop counting. There is no need for the number at all. Scope your programme on the 32 subdomains, which the Framework does state, and count the considerations you will actually evidence.
Presenting level 3 as the finish line. The circular sets it as the minimum. Levels 4 and 5 exist, level 4 requires defined key risk indicators and trend reporting, and a supervisor comparing peers is not obliged to be satisfied by a floor.
Treating the CSF as a documentation exercise. The nationality requirement and the SAMA no objection for the CISO cannot be written, and neither can certified forensic capacity or an independent function with its own budget.
Reporting the October 2018 deadline as though it closed the matter. It was the date for reaching full compliance, not the date the obligation ended. New entrants and newly licensed institutions face the same requirements today.
Size your own SAMA CSF budget
Fill this in. It will not produce a price, and it is not meant to. It will tell you which of the nine budget lines above is going to dominate yours.
| Question | Your answer | What it decides |
|---|---|---|
| Are you a bank, or another SAMA supervised institution? | Banks take all domains. Others exclude 3.2.3, 3.3.12 and 3.3.13, subject to the PCI DSS, SWIFT and MFA conditions. | |
| Do you have a full time CISO who meets the 3.1.1 conditions? | The longest lead time in the programme, because it needs a qualified Saudi national and SAMA no objection. | |
| Is your cyber security function independent of IT, with its own budget? | If not, this is organisational change and headcount rather than tooling. | |
| What is your current maturity, honestly, per subdomain? | The distance from level 2 to level 3 is documentation plus demonstrable implementation across all 32. | |
| When were your customer facing services last penetration tested? | Subdomain 3.2.4 makes this annual, so it is a recurring line rather than a project cost. | |
| Do you have certified forensic capacity and a restricted response workspace? | Subdomain 3.3.15 asks for both. Contracting the forensic capacity is the usual answer. | |
| Are any material outsourcing or cloud arrangements awaiting SAMA approval? | Approval time is schedule cost, and cloud is in principle expected to be located in Saudi Arabia. |
If several rows are blank, price the gap assessment first and nothing else. A free compliance check gives you a starting position, and our SAMA CSF compliance software holds the maturity assessment and its evidence in the structure the self assessment is actually reported in.
Frequently asked questions
How much does SAMA CSF compliance cost?
SAMA has not published a figure and no reliable public benchmark exists. Cost is driven by whether you are a bank, your current maturity per subdomain, and how much of the mandated structure, meaning a cleared full time CISO, an independent function, forensic capacity and recurring audits, you already have.
What maturity level does SAMA require?
Level 3 as a minimum, for all requirements set out in the CSF, under Circular No. 381000091275. The Framework describes level 3 as controls defined, approved and implemented in a structured and formalized way, with implementation that can be demonstrated.
Does the CSF apply to us if we are not a bank?
If SAMA supervises you, yes. The Framework names banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure. Non-banks get three subdomain exclusions, each with a condition attached.
Can we use a cloud provider outside Saudi Arabia?
The cloud computing policy required by subdomain 3.4.3 states that in principle only cloud services located in Saudi Arabia should be used, and SAMA approval must be obtained before using cloud services or signing the contract. Treat any other arrangement as an approval question rather than a procurement one.
What if a control genuinely does not fit our organisation?
The Framework is principle based. Where a control consideration cannot be tailored or implemented, it directs you to consider compensating controls, pursue an internal risk acceptance and request a formal waiver from SAMA, with the process set out in Appendix D.
Primary sources
Structure, applicability, the maturity model and every control reference above are taken from the SAMA Cyber Security Framework, version 1.0 of May 2017, as published on the SAMA Rulebook. The maturity level 3 minimum and the 2017 and 2018 milestones come from the English text of Circular No. 381000091275 on the same Rulebook, which notes that the governing text is the Arabic one. No cost figure in this article is attributed to SAMA, because SAMA has published none. Confirm the current version of both documents before relying on a reference.





