Wadira: Find your way through Saudi data & privacy law.

HomeFrameworksFinancial services › SAMA Cyber Security Framework (CSF)

SAMA Cyber Security Framework (CSF)

TypeInstrument
Issuing authoritySaudi Central Bank (SAMA)
FrameworkFinancial services
TierRules, controls & standards
Legal statusGuidance

The SAMA Cyber Security Framework (CSF), version 1.0 of May 2017, is the Saudi Central Bank's sector-wide cyber-security baseline for its regulated "Member Organisations": all banks, insurance and reinsurance companies, financing companies, credit bureaus and financial-market infrastructure operating in Saudi Arabia.

Principle-based and risk-oriented, it prescribes cyber-security principles and objectives across four domains (Cyber Security Leadership and Governance; Cyber Security Risk Management and Compliance; Cyber Security Operations and Technology; and Third-Party Cyber Security), each broken into sub-domains with mandated control considerations, covering information assets from electronic records to technical infrastructure.

Implementation is measured against a six-level maturity model (0–5) through periodic self-assessment reviewed and audited by SAMA; where a control cannot be implemented, entities may apply compensating controls and request a formal waiver. The Framework is mandated and maintained by SAMA under the supervisory powers of the Saudi Central Bank Law; for licence applicants it is preceded by the Cyber Resilience Fundamental Requirements.

Documents

In this framework


Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13