SAMA · Version 1.0

SAMA Cyber Security Framework

The framework the Saudi Central Bank mandates for the institutions it regulates: four domains and a maturity target.

Last verified against official sources: 26 September 2026

Key facts

Issued by
Saudi Central Bank (SAMA)
Version
Version 1.0, issued May 2017
Applies to
Financial institutions regulated by SAMA, referred to in the framework as member organizations
Structure
4 main domains
Maturity target
At least maturity level 3

The four domains

  • Cyber Security Leadership and Governance
  • Cyber Security Risk Management and Compliance
  • Cyber Security Operations and Technology
  • Third Party Cyber Security

The fourth domain, Third Party Cyber Security, is the one institutions most often underweight. Your suppliers and service providers are part of your security posture, and the framework treats them that way.

The maturity target

SAMA's maturity model asks member organizations to operate at least at maturity level 3. In the framework's own words, to achieve level 3 a member organization should define, approve and implement cyber security controls.

The practical meaning: documented intent is not enough. The controls have to be approved and in operation, and you need the evidence to show it.

Card, EMV and SWIFT standards

Section 3.2.3 of the framework, on compliance with national and international industry standards, states that banks should comply with PCI DSS, the EMV standard and the SWIFT Customer Security Controls Framework. For other institutions SAMA regulates, section 1.4 excludes 3.2.3, but PCI DSS and/or the SWIFT framework still apply where the institution stores, processes or transmits cardholder data or uses SWIFT services.

Running it alongside other Saudi rules

The SAMA framework governs the institutions SAMA regulates. It does not replace the national rules: a regulated institution also has obligations under the Personal Data Protection Law, and some institutions also fall within the NCA's scope. Map all of them to one control set instead of running parallel programs.

Where to start

  1. Assess each domain against evidence, and rate your current maturity honestly.
  2. Close the gaps that keep you below maturity level 3 first.
  3. Give the third-party domain the same attention as the other three: inventory your suppliers, set requirements in contracts, and review them.
  4. Keep the evidence current so a review is a routine exercise, not a scramble.

AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the NCA, SDAIA, SAMA, CST, DGA or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. Always confirm current requirements against the official source.

Sources

  1. SAMA Rulebook, Cyber Security Framework (opens in a new tab)
  2. PCI Security Standards Council, PCI DSS (opens in a new tab)

Ten minutes to know exactly where you stand

Tell us what you do and who regulates you. We will show you which Saudi rules apply, where the gaps usually are, and the shortest route to ready. No slides, no pitch.