Frameworks · Middle East

SAMA Cyber Security Framework compliance, run as a living system

The Saudi Central Bank's Cyber Security Framework sets mandatory cyber security requirements for financial institutions it supervises, organised by domain and assessed against defined maturity levels rather than a simple pass or fail.

Who it applies to

Banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructures supervised by the Saudi Central Bank.

What it demands

Leadership & governance

Board-approved strategy, defined cyber security function, policy set and periodic review.

Risk & compliance

Risk management methodology, regulatory compliance tracking and third-party cyber risk.

Operations & technology

Identity, cryptography, secure configuration, vulnerability management and monitoring.

Third party & maturity

Outsourcing controls and maturity-level assessment across every domain.

How Compli-Once runs it

  • 1

    Every domain modelled with its maturity target, so the dashboard reports the level achieved, not just a percentage.

  • 2

    Crosswalked to ISO 27001 and NIST SP 800-53, so an existing programme starts with measured coverage.

  • 3

    Third-party requirements run on the vendor module with evidence, not questionnaire email threads.

What you already satisfy

SAMA Cyber Security Framework overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.

Implement once, satisfy many

Access control
ISO 27001 A.5.15SOC 2 CC6.1SEBI CSCRF PR.AARBI CSF Access Mgmt
Incident response
ISO 27001 A.5.24SOC 2 CC7.3SEBI CSCRF 6-hour report
Change management
ISO 27001 A.8.32SOC 2 CC8.1PCI DSS v4 6.5

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.

Illustrative, computed live per tenant in the platform.

Frequently asked questions

What is the SAMA Cyber Security Framework?

It is the Saudi Central Bank's mandatory cyber security framework for supervised financial institutions, organised into domains and assessed against defined maturity levels.

How are maturity levels handled?

Each domain carries its required maturity level as a target. Control state rolls up to a computed level with the evidence behind it, so the gap to the target is explicit.

Can it run alongside ISO 27001?

Yes. Overlapping requirements are mapped by the crosswalk, so one implementation satisfies both, and only genuinely new requirements appear as gaps.

Does it cover outsourcing requirements?

Yes. Third-party obligations are modelled as controls linked to vendor assessments, so supplier evidence sits under the same expiry and review machinery.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.