Skip to content

Gulf — Saudi Arabia

SAMA Cyber Security Framework Assessment

Independent maturity assessment against the Saudi Central Bank's Cyber Security Framework, for the banking, insurance and financing entities it supervises.

The framework

The Saudi Central Bank's Cyber Security Framework applies to the financial institutions it regulates — banks, insurance and reinsurance companies, and financing companies, among others. It is structured around domains covering cyber security leadership and governance, risk management and compliance, operations and technology, and third-party cyber security.

Assessment is maturity-based. Each control is scored against a defined maturity scale rather than assessed as a simple pass or fail, and SAMA sets an expected minimum maturity level that supervised entities are required to reach. This is a meaningful difference from binary compliance frameworks: partial implementation earns partial credit, but so does documentation without operation — which is where a lot of self-assessed scores are inflated.

  • Cyber security leadership and governance — strategy, organisation, the CISO role, and board oversight.
  • Cyber security risk management and compliance — risk methodology, regulatory compliance and audit.
  • Cyber security operations and technology — the operational control set, from identity through to monitoring.
  • Third-party cyber security — outsourcing, cloud services and vendor risk.

Why self-assessed maturity scores are usually wrong

Institutions self-assessing consistently over-score, and for an understandable reason: the person assessing the control is often the person who owns it. The most common inflation is scoring a control as mature because a policy mandates it and a tool is deployed, without evidence that the process operates consistently, is measured, and is periodically reviewed — which is what the higher maturity levels actually require.

An independent assessment recalibrates. We evidence every score, and where we disagree with your self-assessment we show you exactly which maturity criterion is not met and what would satisfy it.

Why self-assessed scores inflate

1. Defined A document exists and is approved 2. Implemented Operates across the full scope 3. Measured A metric exists and is acted on 4. Reviewed Assessed, and something changed THE COMMONOVER-SCORE Levels 3 and 4claimed on theevidence of levels1 and 2.
The upper levels require measurement and review — not a policy and a deployed tool.

Preparing for supervisory review

We assess against the framework as a supervisor would read it, and report in a structure that maps directly to the domains and controls so your submission does not require translation. Where remediation is needed to reach the expected maturity level, the roadmap is sequenced against your supervisory reporting calendar.

How the engagement runs

  1. 1

    Scope and applicability

    Confirm which framework version and control set apply to your entity type and licence.

  2. 2

    Maturity methodology

    Agree the scoring approach and evidence standard for each maturity level before assessment begins.

  3. 3

    Evidence-based assessment

    Score every control against evidence, not against assertion.

  4. 4

    Gap to target

    Identify the specific gap between current and expected maturity per control.

  5. 5

    Roadmap

    Build a remediation plan sequenced to reach target maturity within your supervisory cycle.

  6. 6

    Reporting

    Report in a structure that maps directly to the framework domains.

What you receive

Control-by-control maturity assessment with evidence for every score
Domain-level maturity profile against the expected target level
Gap analysis identifying the specific criteria not met per control
Prioritised roadmap to reach target maturity
Board and executive reporting pack
Reassessment of remediated controls at an agreed interval

Frequently asked questions

They overlap substantially in control content but differ in scope, structure and who mandates them. SAMA CSF applies to SAMA-supervised financial institutions and is maturity-scored. NCA ECC applies more broadly across national and critical entities. ISO 27001 is a voluntary certifiable management system standard. An institution may be subject to more than one, and we map controls across frameworks so a single piece of evidence satisfies multiple requirements rather than being gathered three times.

SAMA sets an expected minimum maturity level for supervised entities. Confirm the current expectation applicable to your entity type and reporting cycle — this has been subject to change and we verify it at scoping rather than assuming.

Yes, where they have Saudi operations or a Saudi licence that brings them within scope. We work remotely and onsite across the Kingdom.

Related services

Not sure this is the framework that binds you?

Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.

Request a proposal
Top