Wadira: Find your way through Saudi data & privacy law.
Home › Frameworks › Financial services › SAMA Cyber Security Framework (CSF)
| Type | Instrument |
|---|---|
| Issuing authority | Saudi Central Bank (SAMA) |
| Framework | Financial services |
| Tier | Rules, controls & standards |
| Legal status | Guidance |
The SAMA Cyber Security Framework (CSF), version 1.0 of May 2017, is the Saudi Central Bank's sector-wide cyber-security baseline for its regulated "Member Organisations": all banks, insurance and reinsurance companies, financing companies, credit bureaus and financial-market infrastructure operating in Saudi Arabia.
Principle-based and risk-oriented, it prescribes cyber-security principles and objectives across four domains (Cyber Security Leadership and Governance; Cyber Security Risk Management and Compliance; Cyber Security Operations and Technology; and Third-Party Cyber Security), each broken into sub-domains with mandated control considerations, covering information assets from electronic records to technical infrastructure.
Implementation is measured against a six-level maturity model (0–5) through periodic self-assessment reviewed and audited by SAMA; where a control cannot be implemented, entities may apply compensating controls and request a formal waiver. The Framework is mandated and maintained by SAMA under the supervisory powers of the Saudi Central Bank Law; for licence applicants it is preceded by the Cyber Resilience Fundamental Requirements.
Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13