Cybersecurity framework issued by the Saudi Arabian Monetary Authority (SAMA), applicable to regulated financial institutions in Saudi Arabia.
Last updated — August 22, 2026
Banks, insurance companies, and finance companies under SAMA supervision in Saudi Arabia, as well as their critical IT service providers.
The SAMA CSF is structured around four domains: cybersecurity governance, cyber risk management, security operations (protection, detection, response), and third-party management. Regulated institutions must formalize a board-approved cybersecurity strategy, map their critical assets, implement technical and organizational controls proportionate to risk, and demonstrate incident detection and response capability.
Deadlines
Compliance timelines and self-assessment schedules are set by SAMA directly with each regulated institution; there is no single publicly disclosed regulatory deadline.
Sanctions
SAMA holds prudential supervisory authority over financial institutions under its jurisdiction, including the ability to require corrective measures and impose administrative sanctions where deficiencies are identified during inspections; the exact terms are set by SAMA and are not publicly detailed in a single published scale.
Gap assessment against the four SAMA CSF domains
Asset and cyber risk mapping
Governance strengthening and board-level validation
Implementation of technical and organizational controls
Self-assessment and preparation for SAMA inspections
| Framework | Covered |
|---|---|
| nca-ecc-2-2024 | ✓ |
Get the checklist by email.
No — it covers all financial institutions regulated by SAMA, which also includes insurance companies and finance companies.
No, they are two distinct frameworks. An institution can leverage existing ISO 27001 controls to cover part of the SAMA CSF requirements, but the SAMA framework remains the applicable regulatory reference for the Saudi financial sector.
Yes, the engagement addresses the compliance of the locally regulated entity, regardless of the nationality of the parent group.
Both Saudi frameworks share common cyber risk management principles; a control mapping between the SAMA CSF and the NCA ECC 2-2024 allows part of the effort to be shared for financial institutions subject to both.