Banking cyber · Saudi ArabiaSAMA CSF
The Saudi Central Bank's mandatory cyber security framework for the financial sector, assessed on a maturity model from level 0 to 5.
Why it matters
Compliance is required to operate as a regulated financial institution in Saudi Arabia, with SAMA reviewing maturity directly.
Who it's for
All financial institutions regulated by SAMA: banks, insurance and finance companies operating in the Kingdom.
How you get to SAMA CSF
- 1ScopeInstitution and assets
- 2Maturity self-assessmentScore levels 0-5
- 3Remediation roadmapReach the target level
- 4ImplementAcross all domains
- 5SAMA reviewRegulator submission
- 6Re-assessAnnual maturity cycle
SAMA CSF, worked in the platform
Get the evidence you need
The AI recommends which evidence answers each SAMA CSF control, ready to confirm.
See what's missing
Gaps and missing artifacts surface on their own, not the week of the audit.
Create from templates
Spin up policies, assessments and charters from standard templates, then tailor them to your scope.
Collected once, reused
One artifact satisfies this framework and every other it maps to.
Get SAMA CSF-ready on your own stack.
Demos are scoped to your frameworks. Pick a slot and we'll run SAMA CSF live.