Wadira: Find your way through Saudi data & privacy law.
Home › Frameworks › Financial services › Cyber Resilience Fundamental Requirements (CRFR)
| Type | Instrument |
|---|---|
| Issuing authority | Saudi Central Bank (SAMA) |
| Framework | Financial services |
| Tier | Rules, controls & standards |
| Legal status | Binding |
The Cyber Resilience Fundamental Requirements (CRFR), issued by the Saudi Central Bank in January 2022 (version 1.0), set the minimum cyber-resilience bar for entities entering the financial sector: applicants intending to qualify for SAMA's Regulatory Sandbox and/or seeking a licence to operate in the Kingdom.
The CRFR act as a catalyst for meeting SAMA's minimum cyber-resilience licensing requirements. They are explicitly not a substitute for SAMA's full Cyber Security Framework and Business Continuity Management framework, with which entities must comply once licensed, and are to be read alongside the Regulatory Sandbox Framework.
The control requirements follow a risk-based approach across three domains (Cyber Security Leadership and Governance; Cyber Security Operations and Technology; and Resilience), with compliance verified through entity self-assessment and SAMA audit. In practice the CRFR are the first SAMA cyber instrument a fintech encounters: a compact set of fundamentals bridging the gap between an unregulated start-up and the full CSF obligations that apply after licensing.
Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13