The SAMA Cyber Security Framework asks for one thing repeated 32 times: a defined, approved, implemented and monitored set of cyber security controls in every subdomain, operated at maturity level 3 or higher. The Framework is structured around four main domains, each divided into subdomains, and per subdomain it states a principle, an objective and control considerations. It is principle based, also referred to as risk based, so compliance is measured as a maturity level per subdomain rather than as a pass or fail against a checklist.
The part most summaries leave out is that level 3 was never the whole requirement, and for banks it stopped being the requirement in 2019. Circular No. 298140000067 of 17 January 2019 told banks to develop a roadmap to reach maturity level 4 on four operations subdomains, 3.3.14 Cyber Security Event Management, 3.3.15 Cyber Security Incident Management, 3.3.16 Threat Management and 3.3.17 Vulnerability Management, by the end of the third quarter of 2020. If your programme still reports level 3 as the target across the board, it is reporting against a floor SAMA already raised.
| Fact | Detail |
|---|---|
| Governing documents | The SAMA Cyber Security Framework, version 1.0 of May 2017, issued under Circular No. 381000091275 of 24 May 2017, with the maturity level 4 uplift in Circular No. 298140000067 of 17 January 2019. |
| Who it applies to | All Member Organizations regulated by SAMA: all banks, all insurance and reinsurance companies, all financing companies, all credit bureaus operating in Saudi Arabia, and the Financial Market Infrastructure. |
| Structure | Four main domains, divided into 32 subdomains in total. Per subdomain the Framework states a principle, an objective and control considerations. |
| Approach | Principle based, also referred to as risk based. Control considerations are mandated, but they are applied to your own risk picture. |
| The minimum | Member Organizations should at least operate at maturity level 3 or higher. Levels 3, 4 and 5 require all criteria of the preceding levels first. |
| Raised for banks | Maturity level 4 on subdomains 3.3.14 to 3.3.17, roadmap to complete by the end of the third quarter of 2020. |
| How it is assessed | A periodic self assessment by the Member Organization based on a questionnaire, which SAMA then reviews and audits. |
| When a control does not fit | Consider compensating controls, pursue an internal risk acceptance and request a formal waiver from SAMA. The process is in Appendix D. |
What does the SAMA CSF actually require?
Three things, and they are easier to hold together than a control list suggests.
First, coverage. Every one of the 32 subdomains needs controls that are defined, approved and implemented, with compliance monitored. There is no subdomain a Member Organization can simply decline, only control considerations it can tailor, compensate for or seek a waiver on.
Second, evidence of structure rather than of activity. The Framework describes maturity level 3 as controls defined, approved and implemented in a structured and formalized way. In practice that means a board endorsed policy, standards beneath it and procedures beneath those, with key performance indicators defined, monitored and reported. A control that runs well but is not written down and not monitored sits at level 2, which is a finding.
Third, an assessment you produce yourself. Implementation is subject to a periodic self assessment based on a questionnaire, which SAMA reviews and audits. That makes the self assessment the artefact your programme has to be able to produce on demand, per subdomain, with the evidence behind each answer.
What is in each of the four domains?
The Framework names the domains as Cyber Security Leadership and Governance, Cyber Security Risk Management and Compliance, Cyber Security Operations and Technology, and Third Party Cyber Security. They are very unevenly sized, which is the single most useful thing to know before scoping a programme.
3.1 Cyber Security Leadership and Governance: 7 subdomains
3.1.1 Cyber Security Governance, 3.1.2 Cyber Security Strategy, 3.1.3 Cyber Security Policy, 3.1.4 Cyber Security Roles and Responsibilities, 3.1.5 Cyber Security in Project Management, 3.1.6 Cyber Security Awareness and 3.1.7 Cyber Security Training. This is the domain that constrains your org chart rather than your tooling, and 3.1.1 alone carries the CISO, the committee and the independence requirements described further down.
3.2 Cyber Security Risk Management and Compliance: 5 subdomains
3.2.1 Cyber Security Risk Management, 3.2.2 Regulatory Compliance, 3.2.3 Compliance with (Inter)national Industry Standards, 3.2.4 Cyber Security Review and 3.2.5 Cyber Security Audits. Small in count, heavy in recurring cost: reviews and audits here are periodic obligations rather than one off deliverables.
3.3 Cyber Security Operations and Technology: 17 subdomains
3.3.1 Human Resources, 3.3.2 Physical Security, 3.3.3 Asset Management, 3.3.4 Cyber Security Architecture, 3.3.5 Identity and Access Management, 3.3.6 Application Security, 3.3.7 Change Management, 3.3.8 Infrastructure Security, 3.3.9 Cryptography, 3.3.10 Bring Your Own Device (BYOD), 3.3.11 Secure Disposal of Information Assets, 3.3.12 Payment Systems, 3.3.13 Electronic Banking Services, 3.3.14 Cyber Security Event Management, 3.3.15 Cyber Security Incident Management, 3.3.16 Threat Management and 3.3.17 Vulnerability Management. More than half the Framework sits here, and so does the level 4 uplift.
3.4 Third Party Cyber Security: 3 subdomains
3.4.1 Contract and Vendor Management, 3.4.2 Outsourcing and 3.4.3 Cloud Computing. Three subdomains that behave unlike the rest, because two of them make a SAMA approval a precondition of a commercial decision rather than a control you implement afterwards.
What does maturity level 3 mean, and is it enough?
The Framework uses a six level model. Level 0 is non-existent, with no documentation and no awareness. Level 1 is ad-hoc, where controls are not or only partially defined. Level 2 is repeatable but informal, where execution is based on an informal and unwritten though standardized practice. Level 3 is structured and formalized, where controls are defined, approved and implemented in a structured and formalized way. Level 4 is managed and measurable, where the effectiveness of controls is periodically assessed and improved when necessary. Level 5 is adaptive, where controls are subject to a continuous improvement plan.
Two rules make the ladder behave the way it does. To achieve level 3, 4 or 5 you must first meet all criteria of the preceding levels, so there is no skipping. And the Framework states that Member Organizations should at least operate at maturity level 3 or higher, which is a floor expressed as a minimum rather than a target.
Is it enough? For the general requirement, yes, and Circular No. 381000091275 set it as the minimum for all requirements of the CSF. For banks on the four operations subdomains named above, no, and it has not been since January 2019. Level 4 is a different kind of ask: it requires you to measure whether a control is effective, not only that it exists, which usually means defining key risk indicators and reporting against them.
Which requirements apply if you are not a bank?
Nearly all of them. All domains are applicable to the banking sector. Other financial institutions supervised by SAMA get three subdomain exclusions, and each one carries a condition that gives most of it back.
Subdomain 3.2.3, Compliance with (Inter)national Industry Standards, is excluded, though PCI DSS or the SWIFT Customer Security Controls Framework should be implemented if you store, process or transmit cardholder data or use SWIFT services. Subdomain 3.3.12, Payment Systems, is excluded. Subdomain 3.3.13, Electronic Banking Services, is excluded, though a multi factor authentication capability should be implemented if you provide online services to customers.
Read together, that is 29 subdomains rather than 32, with two of the three exclusions replaced by a narrower obligation the moment you touch card data, SWIFT or online customer services. It is not a lighter regime so much as a differently shaped one.
Which requirements cannot be met by writing a document?
Four, and they are the ones that set the critical path on every SAMA programme we see.
The CISO. Subdomain 3.1.1 requires a full time senior manager for the cyber security function, appointed at senior management level. The Member Organization must ensure the CISO has a Saudi nationality, ensure the CISO is sufficiently qualified, and obtain no objection from SAMA to assign the CISO. That is a hiring constraint plus a regulatory approval step, and neither is compressible by effort.
Independence from IT. The cyber security function should be independent from the information technology function, and to avoid a conflict of interest the two should have separate reporting lines, budgets and staff evaluations. The function should report directly to the CEO or managing director, or to the general manager of a control function. This is an organisational change, not a policy paragraph.
The committee. A cyber security committee should be established and mandated by the board, headed by an independent senior manager from a control function, with an approved charter and a meeting frequency of at least quarterly. Internal audit may attend as an observer.
SAMA approvals on third parties. Subdomain 3.4.2 requires approval from SAMA prior to material outsourcing. Subdomain 3.4.3 requires SAMA approval before using cloud services or signing the contract with the cloud provider, and states that in principle only cloud services located in Saudi Arabia should be used, with explicit SAMA approval needed when they are not. Approval time is schedule cost even when nothing is refused.
What the other results get wrong
Four recurring errors, in the order they cause damage.
Reporting level 3 as the requirement, full stop. It is the minimum for all CSF requirements, and for banks it has been overtaken on subdomains 3.3.14 to 3.3.17 since the 2019 circular. A readiness report that says level 3 achieved without naming those four is incomplete for a bank.
Quoting a total control count. The Framework numbers control considerations within each subdomain and nests sub-items beneath them, so any total depends on where you stop counting, and published figures differ widely. The number the Framework does state is 32 subdomains across four domains. Scope on that.
Treating the CSF as a checklist. It is principle based, and assessment is by maturity level per subdomain. Ticking a control that is implemented but neither documented nor monitored produces a level 2 answer to a level 3 question.
Presenting the October 2018 deadline as the end of the matter. That was the date for reaching full compliance under the first circular. The self assessment, the reviews, the audits and the awareness programme are all recurring, which is the same trap we described in SAMA CSF compliance cost.
Check your own position, domain by domain
Fill this in. Any row you cannot answer is a scoping question, not a tooling one.
| Question | Your answer | What it decides |
|---|---|---|
| Which SAMA supervised category are you in? | Banks take all four domains. Other Member Organizations exclude 3.2.3, 3.3.12 and 3.3.13, subject to the PCI DSS, SWIFT and multi factor authentication conditions. | |
| Do you have a full time CISO who meets every condition in 3.1.1? | Saudi nationality, sufficient qualification and SAMA no objection make this the longest lead time in the programme. | |
| Is the cyber security function independent of IT? | Separate reporting lines, budgets and staff evaluations, reporting to the CEO, managing director or a control function head. | |
| Does the board mandated committee meet at least quarterly under an approved charter? | 3.1.1 sets the minimum frequency and requires an independent senior manager from a control function to head it. | |
| What is your maturity level for each of the 32 subdomains? | The self assessment is per subdomain. A domain level average hides exactly the gaps SAMA audits for. | |
| Are subdomains 3.3.14 to 3.3.17 at level 4? | For banks this was the roadmap target for the end of the third quarter of 2020, not an optional stretch. | |
| Which control considerations have you accepted rather than implemented? | Each needs compensating controls, an internal risk acceptance and a formal waiver requested through Appendix D. | |
| Is any material outsourcing or cloud arrangement awaiting SAMA approval? | 3.4.2 and 3.4.3 make the approval a precondition, so it belongs in the schedule rather than in remediation. |
If most rows are blank, start with a gap assessment rather than a tool selection. A free compliance check gives you a starting position, and our SAMA CSF compliance software holds the maturity assessment and its evidence in the structure the self assessment is reported in. If you also answer to the National Cybersecurity Authority, the NCA ECC software comparison covers the overlap, and the SAMA CSF buyer guide covers what to check before you buy anything.
Frequently asked questions
What are the SAMA CSF requirements?
Controls defined, approved, implemented and monitored across four domains and 32 subdomains, operated at maturity level 3 or higher, with a periodic self assessment that SAMA reviews and audits. Each subdomain states a principle, an objective and control considerations, and the Framework is principle based rather than prescriptive.
How many domains and subdomains does the SAMA CSF have?
Four domains and 32 subdomains: seven under Cyber Security Leadership and Governance, five under Cyber Security Risk Management and Compliance, seventeen under Cyber Security Operations and Technology, and three under Third Party Cyber Security. Totals for individual controls vary between publishers because control considerations nest.
What maturity level does SAMA require?
Level 3 as a minimum for all CSF requirements under Circular No. 381000091275. Banks were separately required to roadmap to level 4 on subdomains 3.3.14 to 3.3.17 by the end of the third quarter of 2020 under Circular No. 298140000067.
Does the CSF apply to insurance companies and financing companies?
Yes. The Framework applies to all Member Organizations regulated by SAMA, which it lists as all banks, all insurance and reinsurance companies, all financing companies, all credit bureaus operating in Saudi Arabia, and the Financial Market Infrastructure. Non-banks get three subdomain exclusions, each with a condition.
What happens if a control consideration does not fit our organisation?
The Framework is principle based, so where a control consideration cannot be tailored or implemented it directs you to consider compensating controls, pursue an internal risk acceptance and request a formal waiver from SAMA. The waiver process is set out in Appendix D.
Is SAMA CSF compliance a certification?
No. There is no CSF certificate. Implementation is subject to a periodic self assessment based on a questionnaire, and SAMA reviews and audits that self assessment to determine both compliance and the maturity level actually reached.
Primary sources
Domain and subdomain names, the maturity model definitions, the applicability list, the sector exclusions, the governance requirements in 3.1.1 and the third party requirements in 3.4 are taken from the SAMA Cyber Security Framework, version 1.0 of May 2017, as published on the SAMA Rulebook. The maturity level 3 minimum and the 2017 and 2018 milestones come from Circular No. 381000091275. The level 4 requirement for subdomains 3.3.14 to 3.3.17 comes from Circular No. 298140000067 of 17 January 2019. The Rulebook notes that the governing text is the Arabic one. Confirm the current version before relying on a reference.




