Frameworks · Middle East
SAMA Cyber Security Framework compliance, run as a living system
The Saudi Central Bank's Cyber Security Framework sets mandatory cyber security requirements for financial institutions it supervises, organised by domain and assessed against defined maturity levels rather than a simple pass or fail.
Who it applies to
Banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructures supervised by the Saudi Central Bank.
What it demands
Leadership & governance
Board-approved strategy, defined cyber security function, policy set and periodic review.
Risk & compliance
Risk management methodology, regulatory compliance tracking and third-party cyber risk.
Operations & technology
Identity, cryptography, secure configuration, vulnerability management and monitoring.
Third party & maturity
Outsourcing controls and maturity-level assessment across every domain.
How Compli-Once runs it
- 1
Every domain modelled with its maturity target, so the dashboard reports the level achieved, not just a percentage.
- 2
Crosswalked to ISO 27001 and NIST SP 800-53, so an existing programme starts with measured coverage.
- 3
Third-party requirements run on the vendor module with evidence, not questionnaire email threads.
What you already satisfy
SAMA Cyber Security Framework overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.
Implement once, satisfy many
In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.
Illustrative, computed live per tenant in the platform.
Frequently asked questions
What is the SAMA Cyber Security Framework?
It is the Saudi Central Bank's mandatory cyber security framework for supervised financial institutions, organised into domains and assessed against defined maturity levels.
How are maturity levels handled?
Each domain carries its required maturity level as a target. Control state rolls up to a computed level with the evidence behind it, so the gap to the target is explicit.
Can it run alongside ISO 27001?
Yes. Overlapping requirements are mapped by the crosswalk, so one implementation satisfies both, and only genuinely new requirements appear as gaps.
Does it cover outsourcing requirements?
Yes. Third-party obligations are modelled as controls linked to vendor assessments, so supplier evidence sits under the same expiry and review machinery.
