Security HubSAMA CSF: What Maturity Level 3 Requires

SAMA CSF: What Maturity Level 3 Requires

Netru Compliance9 min read

The SAMA Cyber Security Framework governs cyber security for Saudi Arabia's financial sector, and it works differently from the certifications most organisations arrive with. It is not pass or fail. Every control is scored on a maturity scale, a minimum of level 3 is mandatory across all four domains, and anything below that is non-compliance rather than a finding to improve on. This covers what level 3 actually asks for, how much of an existing programme transfers, and why suppliers who have never heard of SAMA end up in scope.

Who it binds

SAMA regulates the Saudi financial sector, and the framework applies to what it calls Member Organisations: banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructure. If SAMA licenses you, the framework binds you.

The name causes confusion worth clearing up. The Saudi Arabian Monetary Authority became the Saudi Central Bank in 2021, but the abbreviation SAMA stayed and the framework is still universally called the SAMA CSF. You will see both names used for the same regulator.

It is also not the only Saudi framework. The National Cybersecurity Authority Essential Cybersecurity Controls apply to government bodies and critical national infrastructure. Financial institutions follow SAMA instead. Some organisations touch both, and the first question in any Saudi engagement is which regime actually applies, because the answer determines the control set.

The structure

Four domains, subdivided into around thirty-two subdomains. Cyber Security Leadership and Governance covers the management system: strategy, roles, policy, and board oversight. Cyber Security Risk Management and Compliance covers risk process, regulatory compliance and audit. Cyber Security Operations and Technology is the technical bulk, from identity and access through to detection and response. Third Party Cyber Security is a domain in its own right, which is unusual and consequential.

That fourth domain is why organisations with no Saudi presence end up inside this. A Member Organisation is accountable for the cyber security of its suppliers, and it discharges that by pushing requirements into contracts and assurance questionnaires. If you provide software or services to a Saudi bank, insurer or financing company, you will be assessed against SAMA expectations whether or not you have ever read the framework.

Maturity, and why certification does not answer it

Every control is scored on a maturity scale running from zero to five. Zero is non-existent, one is ad hoc, two is repeatable but informal, three is defined and documented, four is managed and measurable, five is adaptive.

SAMA mandates a minimum of level 3 across all four domains. This is the point most organisations underestimate. Level 3 is not "we do this". It requires documentation that states why, what and how, expressed as policies, standards and procedures, implemented consistently, with compliance to that documentation actively monitored. A control that works reliably because a capable engineer runs it well scores two, not three.

Below level 3 is non-compliance rather than an improvement opportunity, and it is raised formally during supervisory examination.

This is the same trap TISAX sets and for the same reason. ISO 27001 asks whether a control exists and operates. A maturity model asks how well, against a defined scale. An organisation can hold ISO 27001 certification and still score two on controls the auditor was entirely satisfied with, because the certification standard and the maturity target are asking different questions.

How it maps to what you already hold

ISO 27001 is the strongest starting position. The management system, risk methodology, asset management, access control, supplier management, incident handling and internal audit all correspond to SAMA domains, and the governance structure in domain one is close to the ISO clauses. What does not transfer is the maturity evidence: you will have the control, and you will need documentation and monitoring evidence to demonstrate level 3 for each one.

NIST CSF maps reasonably at the level of subject matter, since both cover govern, protect, detect and respond territory. But NIST describes outcomes and SAMA scores maturity, so a CSF profile does not convert into SAMA scores without rework.

PCI DSS overlaps meaningfully for anything touching payment card data, and most Saudi financial institutions hold it, so evidence is often reusable in both directions.

SOC 2 helps least of the major frameworks, despite being the most common credential for software suppliers. It is an auditor opinion over a period against criteria you partly select, which is a different artefact from a maturity score against a fixed control set. It demonstrates seriousness. It does not answer the question SAMA asks.

NCA ECC and SAMA overlap substantially in subject matter, being two Saudi frameworks addressing the same national concerns. An organisation that has done one will find the second largely an exercise in re-expressing evidence, which is worth knowing if you serve both government and financial customers in the Kingdom.

Where suppliers get caught

The most common surprise is scope. A supplier assumes SAMA applies to its customer and discovers the customer is contractually required to hold it accountable for the same controls on the service it provides. The obligations arrive as a questionnaire with no negotiation available, because the Member Organisation cannot waive what its regulator requires.

The second is the maturity language. A supplier answers "yes, we do that" and is asked to evidence level 3. Yes is not a maturity score, and the response is rejected as incomplete rather than inadequate, which wastes a cycle.

The third is data residency. Saudi expectations around where data is stored and processed are firm in the financial sector, and this is the item most likely to require an architectural change rather than documentation. It should be established before contracting, because retrofitting a regional deployment after signing is where Gulf projects overrun.

A realistic route

Establish which regime applies before anything else. SAMA for financial, NCA ECC for government and critical infrastructure, and occasionally both.

If you hold ISO 27001, run a maturity assessment against the SAMA domains rather than a gap analysis against the control list. The controls will largely exist. The gap will be documentation, consistency and monitoring evidence, which is a different and usually smaller piece of work than it first appears, but not one a certificate discharges.

If you hold nothing, build the management system first. Every Saudi framework, and every other framework worth holding, becomes an exercise in expressing evidence once that exists. Attempting SAMA directly without one means building a management system anyway, while under regulatory scrutiny.

For suppliers, the durable asset is a maturity-mapped evidence pack that answers at control level with the documentation attached. It is reusable across every Member Organisation you serve, and it is what turns a six-week questionnaire cycle into a two-day one.

Related services

Talk to an engineer

We respond to every enquiry within one business day, and return a scoped proposal with fixed pricing within 48 hours.

Book a discovery call