Suspect a breach? Report it immediately — response within 1 hour.Report an incident

SAMA Cybersecurity Framework

Cybersecurity framework issued by the Saudi Arabian Monetary Authority (SAMA), applicable to regulated financial institutions in Saudi Arabia.

Last updatedAugust 22, 2026

Who's affected

Banks, insurance companies, and finance companies under SAMA supervision in Saudi Arabia, as well as their critical IT service providers.

What the framework requires

The SAMA CSF is structured around four domains: cybersecurity governance, cyber risk management, security operations (protection, detection, response), and third-party management. Regulated institutions must formalize a board-approved cybersecurity strategy, map their critical assets, implement technical and organizational controls proportionate to risk, and demonstrate incident detection and response capability.

Compliance steps

01

Gap assessment against the four SAMA CSF domains

02

Asset and cyber risk mapping

03

Governance strengthening and board-level validation

04

Implementation of technical and organizational controls

05

Self-assessment and preparation for SAMA inspections

Common mistakes

  • Treating the SAMA CSF as a technical checklist without governance ownership
  • Overlooking oversight of the third-party and supplier chain
  • Failing to document the compliance evidence expected during inspections

Cross-mapping to other frameworks (UCM)

FrameworkCovered
nca-ecc-2-2024

Downloadable resource

Get the checklist by email.

Frequently asked questions

Does the SAMA CSF apply only to banks?

No — it covers all financial institutions regulated by SAMA, which also includes insurance companies and finance companies.

Does the SAMA CSF replace ISO 27001?

No, they are two distinct frameworks. An institution can leverage existing ISO 27001 controls to cover part of the SAMA CSF requirements, but the SAMA framework remains the applicable regulatory reference for the Saudi financial sector.

Can EBH Security support a non-Saudi institution with a Saudi subsidiary?

Yes, the engagement addresses the compliance of the locally regulated entity, regardless of the nationality of the parent group.

Is there a link between the SAMA CSF and the NCA ECC?

Both Saudi frameworks share common cyber risk management principles; a control mapping between the SAMA CSF and the NCA ECC 2-2024 allows part of the effort to be shared for financial institutions subject to both.