Insights · SAMA

SAMA Cyber Security Framework: what Saudi financial institutions need to evidence

Who the SAMA Cyber Security Framework applies to, its four domains, the maturity level SAMA expects and the IT evidence a member organisation keeps.
The short answer

The SAMA Cyber Security Framework applies to banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructure operating in Saudi Arabia. It has four domains: leadership and governance, risk management and compliance, operations and technology, and third-party cyber security. SAMA expects member organisations to operate at maturity level 3 or higher.

Key points
  • The framework covers banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructure operating in Saudi Arabia.
  • It has four domains, numbered 3.1 to 3.4, and SAMA expects member organisations to operate at least at maturity level 3.
  • Level 3 means “structured and formalized”: documented, approved and monitored, not just done.
  • Domain 3.4 covers third-party cyber security, so your IT provider is part of your assessment.
  • Confirm with your compliance team which further requirements apply to you. Firms regulated by other authorities follow those authorities’ rules too.

Who the framework applies to

SAMA’s Rulebook lists the “Member Organizations” the framework applies to:

  • All banks operating in Saudi Arabia
  • All insurance and reinsurance companies operating in Saudi Arabia
  • All financing companies operating in Saudi Arabia
  • All credit bureaus operating in Saudi Arabia
  • Financial market infrastructure

The framework carries SAMA reference No. 381000091275, dated 28/8/1438H (24 May 2017). Firms authorised by other regulators, for example the Capital Market Authority, follow those regulators’ requirements, so ask your compliance team which cyber requirements apply to your licence.

The four domains

DomainSubdomains
3.1 Cyber Security Leadership and GovernanceGovernance, strategy, policy, roles and responsibilities, project management, awareness and training (3.1.1 to 3.1.7).
3.2 Cyber Security Risk Management and ComplianceRisk management, regulatory compliance, industry standards, security review and audits (3.2.1 to 3.2.5).
3.3 Cyber Security Operations and TechnologyThirteen operational subdomains (3.3.1 to 3.3.13), from human resources through to electronic banking.
3.4 Third Party Cyber SecurityThird-party cyber security, which includes cloud computing.

The IT department’s daily work sits mostly in domain 3.3, but domain 3.1 and 3.2 decide whether that work is documented, owned and reviewed.

What “maturity level 3” asks of you

SAMA says member organisations should at least operate at maturity level 3 or higher. Level 3 is described as “structured and formalized”: policies and standards are documented and approved, and compliance is monitored.

In practice, a reviewer testing a level 3 claim looks for four things for each control area:

  1. A documented, approved policy or standard.
  2. An owner who is named and accountable.
  3. Proof the control operates: a report, log or record with a date.
  4. Evidence that someone reviews it and acts on exceptions.

That is our reading of what level 3 requires in day-to-day terms, not SAMA’s own wording.

IT evidence worth keeping

These are typical items for the IT side of an assessment. They are suggestions, not a SAMA checklist.

AreaTypical evidence
GovernanceApproved cyber security policy and standards, roles and responsibilities, board or committee reporting.
Risk managementRisk register with owners and treatment decisions, dated risk assessments.
Operations and technologyAsset inventory, access-review records, patching and vulnerability reports, backup and restore tests, logging and monitoring records, incident response plan and exercise notes.
Third partiesProvider register, contract terms, due-diligence and periodic review records.

Third parties and your IT provider

Domain 3.4 means your IT provider is inside your assessment, not outside it. Have the contract, the due diligence and the review record ready. Our third-party risk guide sets out what to ask and what to put in the contract.

Sources and further reading

Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Is the SAMA Cyber Security Framework mandatory?

It applies to the member organisations SAMA lists: banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructure operating in Saudi Arabia. Your compliance team should confirm how it applies to your licence.

What maturity level does SAMA expect?

SAMA says member organisations should at least operate at maturity level 3 or higher, which it describes as structured and formalized.

Does ISO 27001 satisfy the SAMA framework?

No. The framework has its own domains and maturity model, so you assess against it directly. An ISO 27001 management system can help you organise policies, risk and evidence.

Does SAMA’s framework cover our IT provider?

Yes. Domain 3.4 is dedicated to third-party cyber security.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
Audit readiness

Audit readiness for NCA and SAMA reviews: the IT evidence checklist

How the NCA assesses ECC compliance, what control 1-8 requires, the evidence pack to build and how ISO 27001:2022 fits alongside.
3 min read · Reviewed 20 September 2026
Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026
PDPL

Saudi PDPL: an IT checklist for the Personal Data Protection Law

What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
4 min read · Reviewed 20 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.