Gulf — Saudi Arabia
SAMA Cyber Security Framework Assessment
Independent maturity assessment against the Saudi Central Bank's Cyber Security Framework, for the banking, insurance and financing entities it supervises.
The framework
The Saudi Central Bank's Cyber Security Framework applies to the financial institutions it regulates — banks, insurance and reinsurance companies, and financing companies, among others. It is structured around domains covering cyber security leadership and governance, risk management and compliance, operations and technology, and third-party cyber security.
Assessment is maturity-based. Each control is scored against a defined maturity scale rather than assessed as a simple pass or fail, and SAMA sets an expected minimum maturity level that supervised entities are required to reach. This is a meaningful difference from binary compliance frameworks: partial implementation earns partial credit, but so does documentation without operation — which is where a lot of self-assessed scores are inflated.
- Cyber security leadership and governance — strategy, organisation, the CISO role, and board oversight.
- Cyber security risk management and compliance — risk methodology, regulatory compliance and audit.
- Cyber security operations and technology — the operational control set, from identity through to monitoring.
- Third-party cyber security — outsourcing, cloud services and vendor risk.
Why self-assessed maturity scores are usually wrong
Institutions self-assessing consistently over-score, and for an understandable reason: the person assessing the control is often the person who owns it. The most common inflation is scoring a control as mature because a policy mandates it and a tool is deployed, without evidence that the process operates consistently, is measured, and is periodically reviewed — which is what the higher maturity levels actually require.
An independent assessment recalibrates. We evidence every score, and where we disagree with your self-assessment we show you exactly which maturity criterion is not met and what would satisfy it.
Why self-assessed scores inflate
Preparing for supervisory review
We assess against the framework as a supervisor would read it, and report in a structure that maps directly to the domains and controls so your submission does not require translation. Where remediation is needed to reach the expected maturity level, the roadmap is sequenced against your supervisory reporting calendar.
How the engagement runs
-
1
Scope and applicability
Confirm which framework version and control set apply to your entity type and licence.
-
2
Maturity methodology
Agree the scoring approach and evidence standard for each maturity level before assessment begins.
-
3
Evidence-based assessment
Score every control against evidence, not against assertion.
-
4
Gap to target
Identify the specific gap between current and expected maturity per control.
-
5
Roadmap
Build a remediation plan sequenced to reach target maturity within your supervisory cycle.
-
6
Reporting
Report in a structure that maps directly to the framework domains.
What you receive
Frequently asked questions
Related services
Not sure this is the framework that binds you?
Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.
Request a proposal