CompliverseAI
Banking cyber · Saudi Arabia

SAMA CSF

SAMA Cyber Security Framework

The Saudi Central Bank's mandatory cyber security framework for the financial sector, assessed on a maturity model from level 0 to 5.

170
controls
L0-5
maturity model
Level 3
minimum target
SAMA
Leadership & governance
Risk & compliance
Operations & technology
Third-party cyber
Main domains

Why it matters

Compliance is required to operate as a regulated financial institution in Saudi Arabia, with SAMA reviewing maturity directly.

Who it's for

All financial institutions regulated by SAMA: banks, insurance and finance companies operating in the Kingdom.

The journey

How you get to SAMA CSF

  1. 1ScopeInstitution and assets
  2. 2Maturity self-assessmentScore levels 0-5
  3. 3Remediation roadmapReach the target level
  4. 4ImplementAcross all domains
  5. 5SAMA reviewRegulator submission
  6. 6Re-assessAnnual maturity cycle
On Compliverse

SAMA CSF, worked in the platform

SAMA CSF · Assessment
Statement-level status
64% ready
Control areaAI evidence
Leadership & governanceCyber security policy
Risk & complianceSuggested
Operations & technologyCreate
Third-party cyberSuggested

AI recommends evidence for 3 open controls, and flags what is still missing.

Create from standard template
PolicyAssessmentCharter
+Cyber security policy+Maturity assessment+Risk register

Get the evidence you need

The AI recommends which evidence answers each SAMA CSF control, ready to confirm.

See what's missing

Gaps and missing artifacts surface on their own, not the week of the audit.

Create from templates

Spin up policies, assessments and charters from standard templates, then tailor them to your scope.

Collected once, reused

One artifact satisfies this framework and every other it maps to.

Get SAMA CSF-ready on your own stack.

Demos are scoped to your frameworks. Pick a slot and we'll run SAMA CSF live.