NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian, Arabic and Chinese.See what’s new →
SAMA CSF vs ISO 27001: What a Certificate Covers
Learn

SAMA CSF vs ISO 27001: What a Certificate Covers

·Alexander Sverdlov

If you are regulated by the Saudi Central Bank, the SAMA Cyber Security Framework is mandatory and ISO 27001 is not. The Framework says Member Organizations "must adopt" it, and SAMA measures you against it through a self assessment it reviews and audits. ISO/IEC 27001 is a voluntary international standard that ends in a certificate if you choose to be audited. The two overlap heavily, because SAMA built the Framework on "industry cyber security standards, such as NIST, ISF, ISO, BASEL and PCI", so an ISO 27001 programme gives you much of the structure SAMA looks for. But no clause in the Framework accepts an ISO certificate in place of the self assessment, and SAMA adds rules the standard never mentions: a Saudi CISO cleared by SAMA, a quarterly committee, annual penetration tests, PCI DSS and SWIFT controls, and SAMA approval before material outsourcing or public cloud.

This guide compares the two from the primary texts: the SAMA Cyber Security Framework, version 1.0 of May 2017, which the SAMA Rulebook lists as in force, the SAMA circulars that set its maturity targets, and ISO's own description of ISO/IEC 27001:2022. What each SAMA domain asks for is in SAMA CSF requirements explained; how the standard is built is in ISO 27001 Annex A explained.

SAMA CSFISO 27001
What it isA regulatory framework issued by SAMA under Circular No. 381000091275 of 24 May 2017An international standard for an information security management system, ISO/IEC 27001:2022, published October 2022
Who must use itAll Member Organizations regulated by SAMA: banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market InfrastructureNobody by law; organisations adopt it, or a customer or contract asks for it
StructureFour domains and 32 subdomains, each with a principle, an objective and control considerationsManagement system requirements in clauses 4 to 10, with a reference list of controls in Annex A
How it is measuredA maturity level from 0 to 5 per subdomain, with level 3 as the minimumConformity, judged by a certification body's audit
What you receiveNo certificate; SAMA reviews and audits your self assessmentA certificate, if the audit finds the system conforms
Who interprets itSAMA alone, as owner of the FrameworkThe certification body applies the standard during the audit
SAMA CSF and ISO 27001 at a glance: the SAMA CSF is mandated for every SAMA Member Organization, ISO 27001 is voluntary unless a contract requires it, SAMA sets maturity level 3 per subdomain as the minimum, and only ISO 27001 ends in a certificate

What is the difference between SAMA CSF and ISO 27001?

One is a regulator's rulebook, the other a management system standard. The SAMA Cyber Security Framework is structured around four domains, Cyber Security Leadership and Governance, Cyber Security Risk Management and Compliance, Cyber Security Operations and Technology, and Third Party Cyber Security, split into 32 subdomains. For each subdomain it states a principle, an objective and control considerations, which it describes as "the mandated cyber security controls that should be considered". It calls itself principle based, also referred to as risk based, and it scores you on a six level maturity model rather than pass or fail.

ISO/IEC 27001:2022 asks you to run a management system: define its scope, assess and treat risk, set objectives, audit yourself internally and review the results at management level. Its Annex A is a reference list of controls that you compare your risk treatment against, keeping the ones you need and justifying the ones you exclude. ISO's page for the standard describes certification as "one way to demonstrate to stakeholders and customers that you are committed and able to manage information securely and safely", not as a requirement. The current edition was published in October 2022, and Amendment 1 of 2024 added climate action changes.

The practical difference is who decides whether you are done. Under ISO 27001 you define the scope and a certification body you engage audits it. Under the SAMA CSF the scope is your whole Member Organization, the target is set by SAMA, and SAMA is "solely responsible for providing interpretations" of the Framework.

Does an ISO 27001 certificate satisfy SAMA?

No, and nothing in the Framework says it does. Section 2.3 says implementation "will be subject to a periodic self-assessment", performed by the Member Organization "based on a questionnaire", which SAMA reviews and audits "to determine the level of compliance with the Framework and the cyber security maturity level". The Framework names ISO only as one of the standards it is based on. It contains no clause that treats a certificate as evidence of a maturity level.

What the certificate does give you is most of what maturity level 3 describes. Level 3 means controls that are "defined, approved and implemented in a structured and formalized way", with policies, standards and procedures established, compliance with them monitored and key performance indicators "defined, monitored and reported". A working ISO 27001 system already has a policy, documented procedures, measured objectives and an internal audit. What it may lack is the SAMA structure: evidence filed per subdomain, a maturity score on each one, and the SAMA only controls described below. For banks, four operations subdomains, 3.3.14 to 3.3.17, carry a level 4 target under Circular No. 298140000067 of 17 January 2019, which asks for effectiveness measured with key risk indicators, not only controls in place.

How each one is proven: the SAMA CSF through a self assessment questionnaire that SAMA reviews, with maturity scored from 0 to 5 on every subdomain, and ISO 27001 through an audit by a certification body; no clause in the Framework accepts the certificate in its place
Venvera SAMA Cyber Security Framework assessment showing overall and target maturity, the four domains and subdomain maturity scoring

Where do SAMA CSF and ISO 27001 overlap?

In the management core. SAMA subdomain 3.2.1 asks for cyber security risk identification, analysis, response and monitoring, with risks "accepted, avoided, transferred or mitigated" and treatment actions "documented in a risk treatment plan". ISO 27001 clause 6.1 asks for a risk assessment and a risk treatment plan built the same way. SAMA's documentation pyramid, a board endorsed policy with standards and procedures beneath it, corresponds to the ISO policy in clause 5.2 and the documented information the standard requires. SAMA 3.2.5 asks for independent audits "according to generally accepted auditing standards"; ISO clause 9.2 asks for an internal audit programme. Access control, asset management, cryptography, change management, physical security, incident management and supplier management appear in both.

That overlap is why the sensible order for most institutions is one control set mapped to both, rather than two programmes. The ISO work supplies the system; the SAMA work decides whether each subdomain reaches the level SAMA set.

What does SAMA require that ISO 27001 does not?

Six things stand out, and most of them have long lead times.

The CISO. Subdomain 3.1.1 requires "a full-time senior manager for the cyber security function, referred to as CISO", appointed at senior management level. The Member Organization must ensure the CISO "has a Saudi nationality", is "sufficiently qualified", and must "obtain no objection from SAMA to assign the CISO". ISO 27001 asks for roles and responsibilities, not a nationality or a regulator's consent.

Independence and the committee. The cyber security function "should be independent from the information technology function", with "separate reporting lines, budgets and staff evaluations", and should report to the CEO or managing director or the general manager of a control function. A board mandated committee, headed by an independent senior manager from a control function, must meet at least quarterly.

Testing on a fixed clock. Under 3.2.4, "customer and internet facing services should be subject to annual review and penetration tests". ISO 27001 sets no testing frequency.

Named industry standards. Subdomain 3.2.3 requires compliance with PCI DSS, the EMV technical standard and the SWIFT Customer Security Controls Framework. Institutions other than banks are excused 3.2.3, but must still implement PCI DSS or the SWIFT framework if they handle cardholder data or SWIFT services. How PCI DSS itself compares with the standard is in PCI DSS vs ISO 27001.

Monitoring and incidents. Subdomain 3.3.14 expects a security operations centre with resources for "continuous security event monitoring activities (24x7)". Under 3.3.15 you must inform SAMA IT Risk Supervision "immediately when a medium or high classified security incident has occurred and identified", obtain its no objection before any media interaction, and file a formal incident report after resuming operations.

Approval before outsourcing and cloud. Subdomain 3.4.2 requires "the approval from SAMA prior to material outsourcing". For hybrid and public cloud, 3.4.3 requires SAMA approval "prior to using cloud services or signing the contract", and says that "in principle only cloud services should be used that are located in Saudi Arabia", with explicit SAMA approval needed otherwise.

SAMA only items that ISO 27001 does not ask for: a Saudi CISO with SAMA no objection, a committee meeting at least quarterly, annual penetration tests of customer and internet facing services, PCI DSS, EMV and SWIFT, SAMA approval for cloud, and telling SAMA immediately about medium or high incidents

What does ISO 27001 give you that SAMA does not?

A credential you can show outside Saudi Arabia. A SAMA self assessment is a supervisory document, not something you hand to a customer or a parent group abroad, while a certificate is public. ISO reports that the ISO Survey 2022 recorded "over 70 000 certificates" in 150 countries, which is why international counterparties ask for it. The standard also makes you define a scope, set measurable objectives and run management review as a cycle, which tends to keep a programme alive between SAMA reviews. If your group operates across the Gulf, the same certificate supports conversations with other regulators and customers that the SAMA assessment cannot.

What the other results get wrong

Page one for this query is mostly vendor and consultancy pages, and three errors recur. One guide lists seven core control domains for the SAMA CSF. The Framework has four, and the number that matters for scoping is its 32 subdomains. The same guide names the maturity levels Initial, Developing, Defined, Managed and Optimized. SAMA's own labels are Non-existent, Ad-hoc, Repeatable but informal, Structured and formalized, Managed and measurable, and Adaptive, and the definitions behind them are what SAMA scores against, so borrowed labels from other models mislead. And business continuity is often presented as a CSF domain. The Framework covers cyber security in business continuity under its governance controls, but for business continuity requirements it says "please refer to the SAMA Business Continuity Minimum Requirements", a separate instrument.

How do you run SAMA CSF and ISO 27001 together?

Start from SAMA, because it is the obligation. Scope all 32 subdomains, or 29 if you are not a bank and the three exclusions apply. Map your ISO controls and documents to each subdomain, then add what has no ISO counterpart: the CISO conditions, the committee, the annual tests, PCI DSS and SWIFT, the SOC and the SAMA approvals. Score maturity per subdomain using SAMA's definitions, and keep the certificate running on its own audit cycle. If you also fall within the National Cybersecurity Authority's scope, the Saudi NCA ECC vs SAMA CSF comparison covers the third layer.

Build once, report twice: scope the 32 subdomains, map your ISO controls to them, add the SAMA only items, score maturity per subdomain, and keep the ISO certificate running
An illustrative view of one programme serving SAMA CSF and ISO 27001: subdomains at level 3 or higher, ISO controls mapped to a subdomain, cloud contracts awaiting SAMA approval, and days until the self assessment is due
Venvera ISO 27001:2022 dashboard showing control coverage, audits and control status by category

Check your own position

Fill in the middle column. Any row you cannot answer is a gap SAMA will find before an ISO auditor does.

QuestionYour answerWhy it matters
Which SAMA category are you in?Banks take all 32 subdomains; other Member Organizations exclude 3.2.3, 3.3.12 and 3.3.13, with conditions.
Does your ISO scope cover the whole Member Organization?SAMA assesses the institution, not a scope you chose.
Is your CISO Saudi, full time, and cleared by SAMA?Subdomain 3.1.1; ISO 27001 asks for none of it.
Were customer and internet facing services pen tested this year?Subdomain 3.2.4 sets an annual minimum.
Do you handle cardholder data or SWIFT?Subdomain 3.2.3 brings in PCI DSS, EMV and the SWIFT framework.
Is any outsourcing or public cloud contract awaiting SAMA approval?3.4.2 and 3.4.3 make approval a precondition.
What maturity level does each subdomain reach, with evidence?The self assessment is per subdomain; a certificate does not answer it.

If most rows are blank, the free compliance check gives you a baseline. SAMA CSF in Venvera scores the 32 subdomains on the six level maturity model against your target, applies bank or non-bank scope, and keeps evidence at each control consideration, while the ISO 27001 module tracks the certification work. What a SAMA review looks like is in SAMA CSF audit: what to expect, and the budget in SAMA CSF compliance cost.

The bottom line on SAMA CSF vs ISO 27001: ISO 27001 builds most of the system, and SAMA decides whether it is enough

Frequently asked questions

Is ISO 27001 mandatory in Saudi Arabia?

Not under the SAMA CSF. The Framework is mandatory for SAMA Member Organizations and names ISO only as one of the standards it is based on. A customer, a parent company or a contract may still require a certificate.

Does ISO 27001 certification mean SAMA compliance?

No. SAMA determines compliance and maturity from your self assessment, which it reviews and audits. A certificate helps you produce the evidence, but no Framework clause accepts it as a substitute.

Is there a SAMA CSF certificate?

No. Compliance is measured as a maturity level per subdomain, through the periodic self assessment that SAMA reviews and audits.

What maturity level does SAMA require?

At least level 3 for all Member Organizations. Banks were also required to roadmap to level 4 on subdomains 3.3.14 to 3.3.17 by the end of the third quarter of 2020.

Which should we do first?

The SAMA CSF, because it is the legal obligation and its scope is the whole institution. Build the controls so they also meet ISO 27001, and certification becomes an audit rather than a second project.

Primary sources

SAMA requirements are quoted from the SAMA Cyber Security Framework, version 1.0 of May 2017, sections 1.1, 1.3, 1.4, 1.6, 2.1 to 2.4, and subdomains 3.1.1, 3.2.1, 3.2.3, 3.2.4, 3.2.5, 3.3.14, 3.3.15, 3.4.2 and 3.4.3; the adoption circular is Circular No. 381000091275 and the level 4 requirement is Circular No. 298140000067 of 17 January 2019. ISO facts are from ISO's ISO/IEC 27001 page. Confirm the current SAMA text before relying on a reference.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING