If you are regulated by the Saudi Central Bank, the SAMA Cyber Security Framework is mandatory and ISO 27001 is not. The Framework says Member Organizations "must adopt" it, and SAMA measures you against it through a self assessment it reviews and audits. ISO/IEC 27001 is a voluntary international standard that ends in a certificate if you choose to be audited. The two overlap heavily, because SAMA built the Framework on "industry cyber security standards, such as NIST, ISF, ISO, BASEL and PCI", so an ISO 27001 programme gives you much of the structure SAMA looks for. But no clause in the Framework accepts an ISO certificate in place of the self assessment, and SAMA adds rules the standard never mentions: a Saudi CISO cleared by SAMA, a quarterly committee, annual penetration tests, PCI DSS and SWIFT controls, and SAMA approval before material outsourcing or public cloud.
This guide compares the two from the primary texts: the SAMA Cyber Security Framework, version 1.0 of May 2017, which the SAMA Rulebook lists as in force, the SAMA circulars that set its maturity targets, and ISO's own description of ISO/IEC 27001:2022. What each SAMA domain asks for is in SAMA CSF requirements explained; how the standard is built is in ISO 27001 Annex A explained.
| SAMA CSF | ISO 27001 | |
|---|---|---|
| What it is | A regulatory framework issued by SAMA under Circular No. 381000091275 of 24 May 2017 | An international standard for an information security management system, ISO/IEC 27001:2022, published October 2022 |
| Who must use it | All Member Organizations regulated by SAMA: banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure | Nobody by law; organisations adopt it, or a customer or contract asks for it |
| Structure | Four domains and 32 subdomains, each with a principle, an objective and control considerations | Management system requirements in clauses 4 to 10, with a reference list of controls in Annex A |
| How it is measured | A maturity level from 0 to 5 per subdomain, with level 3 as the minimum | Conformity, judged by a certification body's audit |
| What you receive | No certificate; SAMA reviews and audits your self assessment | A certificate, if the audit finds the system conforms |
| Who interprets it | SAMA alone, as owner of the Framework | The certification body applies the standard during the audit |
What is the difference between SAMA CSF and ISO 27001?
One is a regulator's rulebook, the other a management system standard. The SAMA Cyber Security Framework is structured around four domains, Cyber Security Leadership and Governance, Cyber Security Risk Management and Compliance, Cyber Security Operations and Technology, and Third Party Cyber Security, split into 32 subdomains. For each subdomain it states a principle, an objective and control considerations, which it describes as "the mandated cyber security controls that should be considered". It calls itself principle based, also referred to as risk based, and it scores you on a six level maturity model rather than pass or fail.
ISO/IEC 27001:2022 asks you to run a management system: define its scope, assess and treat risk, set objectives, audit yourself internally and review the results at management level. Its Annex A is a reference list of controls that you compare your risk treatment against, keeping the ones you need and justifying the ones you exclude. ISO's page for the standard describes certification as "one way to demonstrate to stakeholders and customers that you are committed and able to manage information securely and safely", not as a requirement. The current edition was published in October 2022, and Amendment 1 of 2024 added climate action changes.
The practical difference is who decides whether you are done. Under ISO 27001 you define the scope and a certification body you engage audits it. Under the SAMA CSF the scope is your whole Member Organization, the target is set by SAMA, and SAMA is "solely responsible for providing interpretations" of the Framework.
Does an ISO 27001 certificate satisfy SAMA?
No, and nothing in the Framework says it does. Section 2.3 says implementation "will be subject to a periodic self-assessment", performed by the Member Organization "based on a questionnaire", which SAMA reviews and audits "to determine the level of compliance with the Framework and the cyber security maturity level". The Framework names ISO only as one of the standards it is based on. It contains no clause that treats a certificate as evidence of a maturity level.
What the certificate does give you is most of what maturity level 3 describes. Level 3 means controls that are "defined, approved and implemented in a structured and formalized way", with policies, standards and procedures established, compliance with them monitored and key performance indicators "defined, monitored and reported". A working ISO 27001 system already has a policy, documented procedures, measured objectives and an internal audit. What it may lack is the SAMA structure: evidence filed per subdomain, a maturity score on each one, and the SAMA only controls described below. For banks, four operations subdomains, 3.3.14 to 3.3.17, carry a level 4 target under Circular No. 298140000067 of 17 January 2019, which asks for effectiveness measured with key risk indicators, not only controls in place.

Where do SAMA CSF and ISO 27001 overlap?
In the management core. SAMA subdomain 3.2.1 asks for cyber security risk identification, analysis, response and monitoring, with risks "accepted, avoided, transferred or mitigated" and treatment actions "documented in a risk treatment plan". ISO 27001 clause 6.1 asks for a risk assessment and a risk treatment plan built the same way. SAMA's documentation pyramid, a board endorsed policy with standards and procedures beneath it, corresponds to the ISO policy in clause 5.2 and the documented information the standard requires. SAMA 3.2.5 asks for independent audits "according to generally accepted auditing standards"; ISO clause 9.2 asks for an internal audit programme. Access control, asset management, cryptography, change management, physical security, incident management and supplier management appear in both.
That overlap is why the sensible order for most institutions is one control set mapped to both, rather than two programmes. The ISO work supplies the system; the SAMA work decides whether each subdomain reaches the level SAMA set.
What does SAMA require that ISO 27001 does not?
Six things stand out, and most of them have long lead times.
The CISO. Subdomain 3.1.1 requires "a full-time senior manager for the cyber security function, referred to as CISO", appointed at senior management level. The Member Organization must ensure the CISO "has a Saudi nationality", is "sufficiently qualified", and must "obtain no objection from SAMA to assign the CISO". ISO 27001 asks for roles and responsibilities, not a nationality or a regulator's consent.
Independence and the committee. The cyber security function "should be independent from the information technology function", with "separate reporting lines, budgets and staff evaluations", and should report to the CEO or managing director or the general manager of a control function. A board mandated committee, headed by an independent senior manager from a control function, must meet at least quarterly.
Testing on a fixed clock. Under 3.2.4, "customer and internet facing services should be subject to annual review and penetration tests". ISO 27001 sets no testing frequency.
Named industry standards. Subdomain 3.2.3 requires compliance with PCI DSS, the EMV technical standard and the SWIFT Customer Security Controls Framework. Institutions other than banks are excused 3.2.3, but must still implement PCI DSS or the SWIFT framework if they handle cardholder data or SWIFT services. How PCI DSS itself compares with the standard is in PCI DSS vs ISO 27001.
Monitoring and incidents. Subdomain 3.3.14 expects a security operations centre with resources for "continuous security event monitoring activities (24x7)". Under 3.3.15 you must inform SAMA IT Risk Supervision "immediately when a medium or high classified security incident has occurred and identified", obtain its no objection before any media interaction, and file a formal incident report after resuming operations.
Approval before outsourcing and cloud. Subdomain 3.4.2 requires "the approval from SAMA prior to material outsourcing". For hybrid and public cloud, 3.4.3 requires SAMA approval "prior to using cloud services or signing the contract", and says that "in principle only cloud services should be used that are located in Saudi Arabia", with explicit SAMA approval needed otherwise.
What does ISO 27001 give you that SAMA does not?
A credential you can show outside Saudi Arabia. A SAMA self assessment is a supervisory document, not something you hand to a customer or a parent group abroad, while a certificate is public. ISO reports that the ISO Survey 2022 recorded "over 70 000 certificates" in 150 countries, which is why international counterparties ask for it. The standard also makes you define a scope, set measurable objectives and run management review as a cycle, which tends to keep a programme alive between SAMA reviews. If your group operates across the Gulf, the same certificate supports conversations with other regulators and customers that the SAMA assessment cannot.
What the other results get wrong
Page one for this query is mostly vendor and consultancy pages, and three errors recur. One guide lists seven core control domains for the SAMA CSF. The Framework has four, and the number that matters for scoping is its 32 subdomains. The same guide names the maturity levels Initial, Developing, Defined, Managed and Optimized. SAMA's own labels are Non-existent, Ad-hoc, Repeatable but informal, Structured and formalized, Managed and measurable, and Adaptive, and the definitions behind them are what SAMA scores against, so borrowed labels from other models mislead. And business continuity is often presented as a CSF domain. The Framework covers cyber security in business continuity under its governance controls, but for business continuity requirements it says "please refer to the SAMA Business Continuity Minimum Requirements", a separate instrument.
How do you run SAMA CSF and ISO 27001 together?
Start from SAMA, because it is the obligation. Scope all 32 subdomains, or 29 if you are not a bank and the three exclusions apply. Map your ISO controls and documents to each subdomain, then add what has no ISO counterpart: the CISO conditions, the committee, the annual tests, PCI DSS and SWIFT, the SOC and the SAMA approvals. Score maturity per subdomain using SAMA's definitions, and keep the certificate running on its own audit cycle. If you also fall within the National Cybersecurity Authority's scope, the Saudi NCA ECC vs SAMA CSF comparison covers the third layer.

Check your own position
Fill in the middle column. Any row you cannot answer is a gap SAMA will find before an ISO auditor does.
| Question | Your answer | Why it matters |
|---|---|---|
| Which SAMA category are you in? | Banks take all 32 subdomains; other Member Organizations exclude 3.2.3, 3.3.12 and 3.3.13, with conditions. | |
| Does your ISO scope cover the whole Member Organization? | SAMA assesses the institution, not a scope you chose. | |
| Is your CISO Saudi, full time, and cleared by SAMA? | Subdomain 3.1.1; ISO 27001 asks for none of it. | |
| Were customer and internet facing services pen tested this year? | Subdomain 3.2.4 sets an annual minimum. | |
| Do you handle cardholder data or SWIFT? | Subdomain 3.2.3 brings in PCI DSS, EMV and the SWIFT framework. | |
| Is any outsourcing or public cloud contract awaiting SAMA approval? | 3.4.2 and 3.4.3 make approval a precondition. | |
| What maturity level does each subdomain reach, with evidence? | The self assessment is per subdomain; a certificate does not answer it. |
If most rows are blank, the free compliance check gives you a baseline. SAMA CSF in Venvera scores the 32 subdomains on the six level maturity model against your target, applies bank or non-bank scope, and keeps evidence at each control consideration, while the ISO 27001 module tracks the certification work. What a SAMA review looks like is in SAMA CSF audit: what to expect, and the budget in SAMA CSF compliance cost.
Frequently asked questions
Is ISO 27001 mandatory in Saudi Arabia?
Not under the SAMA CSF. The Framework is mandatory for SAMA Member Organizations and names ISO only as one of the standards it is based on. A customer, a parent company or a contract may still require a certificate.
Does ISO 27001 certification mean SAMA compliance?
No. SAMA determines compliance and maturity from your self assessment, which it reviews and audits. A certificate helps you produce the evidence, but no Framework clause accepts it as a substitute.
Is there a SAMA CSF certificate?
No. Compliance is measured as a maturity level per subdomain, through the periodic self assessment that SAMA reviews and audits.
What maturity level does SAMA require?
At least level 3 for all Member Organizations. Banks were also required to roadmap to level 4 on subdomains 3.3.14 to 3.3.17 by the end of the third quarter of 2020.
Which should we do first?
The SAMA CSF, because it is the legal obligation and its scope is the whole institution. Build the controls so they also meet ISO 27001, and certification becomes an audit rather than a second project.
Primary sources
SAMA requirements are quoted from the SAMA Cyber Security Framework, version 1.0 of May 2017, sections 1.1, 1.3, 1.4, 1.6, 2.1 to 2.4, and subdomains 3.1.1, 3.2.1, 3.2.3, 3.2.4, 3.2.5, 3.3.14, 3.3.15, 3.4.2 and 3.4.3; the adoption circular is Circular No. 381000091275 and the level 4 requirement is Circular No. 298140000067 of 17 January 2019. ISO facts are from ISO's ISO/IEC 27001 page. Confirm the current SAMA text before relying on a reference.





