The SAMA Cyber Security Framework applies to banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructure operating in Saudi Arabia. It has four domains: leadership and governance, risk management and compliance, operations and technology, and third-party cyber security. SAMA expects member organisations to operate at maturity level 3 or higher.
SAMA’s Rulebook lists the “Member Organizations” the framework applies to:
The framework carries SAMA reference No. 381000091275, dated 28/8/1438H (24 May 2017). Firms authorised by other regulators, for example the Capital Market Authority, follow those regulators’ requirements, so ask your compliance team which cyber requirements apply to your licence.
| Domain | Subdomains |
|---|---|
| 3.1 Cyber Security Leadership and Governance | Governance, strategy, policy, roles and responsibilities, project management, awareness and training (3.1.1 to 3.1.7). |
| 3.2 Cyber Security Risk Management and Compliance | Risk management, regulatory compliance, industry standards, security review and audits (3.2.1 to 3.2.5). |
| 3.3 Cyber Security Operations and Technology | Thirteen operational subdomains (3.3.1 to 3.3.13), from human resources through to electronic banking. |
| 3.4 Third Party Cyber Security | Third-party cyber security, which includes cloud computing. |
The IT department’s daily work sits mostly in domain 3.3, but domain 3.1 and 3.2 decide whether that work is documented, owned and reviewed.
SAMA says member organisations should at least operate at maturity level 3 or higher. Level 3 is described as “structured and formalized”: policies and standards are documented and approved, and compliance is monitored.
In practice, a reviewer testing a level 3 claim looks for four things for each control area:
That is our reading of what level 3 requires in day-to-day terms, not SAMA’s own wording.
These are typical items for the IT side of an assessment. They are suggestions, not a SAMA checklist.
| Area | Typical evidence |
|---|---|
| Governance | Approved cyber security policy and standards, roles and responsibilities, board or committee reporting. |
| Risk management | Risk register with owners and treatment decisions, dated risk assessments. |
| Operations and technology | Asset inventory, access-review records, patching and vulnerability reports, backup and restore tests, logging and monitoring records, incident response plan and exercise notes. |
| Third parties | Provider register, contract terms, due-diligence and periodic review records. |
Domain 3.4 means your IT provider is inside your assessment, not outside it. Have the contract, the due diligence and the review record ready. Our third-party risk guide sets out what to ask and what to put in the contract.
Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
