A Practical Guide to SAMA Cyber Security Framework (CSF) Compliance Using Picus
| June 29, 2026
What Is the SAMA Cyber Security Framework?
The SAMA Cyber Security Framework (SAMA CSF) is the Saudi Arabian Monetary Authority's mandate for achieving an appropriate and consistent level of cyber security across the Kingdom's financial sector.
It imposes binding obligations on all Member Organizations regulated by SAMA and is built on SAMA requirements and leading industry standards, including NIST, ISF, ISO, BASEL, and PCI.
Who must comply with the SAMA Cyber Security Framework?
The framework applies to all Member Organizations regulated by SAMA, which include all banks operating in Saudi Arabia, all insurance and reinsurance companies, all financing companies, all credit bureaus, and the Financial Market Infrastructure.
Member Organizations are responsible for adopting and implementing the Framework, while SAMA owns it, interprets it, and reviews it periodically.
What Maturity Level Does SAMA Require Financial Institutions to Achieve?
SAMA CSF defines six maturity levels (0 through 5). Member Organizations are expected to operate at maturity level 3 ("Structured and formalized") or higher. To reach level 3, an entity must define, approve, and implement cyber security controls and monitor compliance with its cyber security documentation. Levels 4 ("Managed and measurable") and 5 ("Adaptive") raise the bar further, requiring entities to periodically measure and evaluate the effectiveness of controls using key risk indicators (KRIs) and key performance indicators (KPIs), and ultimately to pursue continuous improvement integrated with enterprise risk management.
The key implication: simply documenting a policy or deploying a tool does not move an entity up the maturity model. SAMA's higher maturity levels explicitly demand that the effectiveness of controls be measured, evaluated, and continuously improved with evidence.
What Evidence Does SAMA Require to Demonstrate Cyber Security Compliance?
The framework is principle-based (also called risk-based). It prescribes key cyber security principles and objectives that each Member Organization must embed and achieve, supported by mandated control considerations that should be applied to meet those objectives.
Crucially, the maturity model ties progression to demonstrable effectiveness. At maturity level 3, the implementation of cyber security controls must be capable of being demonstrated. At level 4, effectiveness must be measured and periodically evaluated, with KRIs and trend reporting used to determine whether controls are working. At level 5, control performance is even evaluated using peer and sector data, and supported with automated real-time monitoring.
The practical takeaway for any Member Organization aiming for level 3 and above: control presence is not control effectiveness. SAMA expects defensible, repeatable, and current evidence that controls work as intended, and that evidence must be available for a self-assessment, a SAMA review, or a SAMA audit at any time.
How Does Picus Support SAMA Cyber Security Framework?
Meeting SAMA CSF requirements means demonstrating control effectiveness to regulators, auditors, and the board.
Picus provides that demonstration continuously, validating security controls against real-world attack techniques and producing the measurable, time-stamped evidence the framework requires at every maturity level.
3.3 Cyber Security Operations and Technology
3.3.14 Cyber Security Event Management & 3.3.15 Cyber Security Incident Management
|
"To ensure timely identification and handling of cyber security incidents in order to reduce the (potential) business impact for the Member Organization." (Subdomain 3.3.15, Objective) |
Subdomain 3.3.14 (Cyber Security Event Management) requires a Security Operations Center (SOC) with 24x7 monitoring, SIEM-based correlation, detection and handling of malicious code and suspicious events, and independent periodic testing of SOC effectiveness, for example red-teaming.
Subdomain 3.3.15 (Cyber Security Incident Management) requires the timely detection, response, and recovery from incidents, along with mandatory reporting obligations to SAMA IT Risk Supervision for medium and high classified incidents.
The effectiveness of incident handling depends entirely on whether the underlying detection and response machinery actually fires when an attack occurs, and whether the people and processes around it respond correctly.
How does Picus exercise SAMA CSF detection and response workflows?
Picus runs production-safe attack scenarios across the full detection stack, testing EDR, XDR, and SIEM pipelines against the specific techniques they are supposed to catch. For each scenario, Picus validates whether security events are detected, whether EDR, XDR, and SIEM rules and alerting pipelines generate alerts with sufficient fidelity. Where the detection breaks, Picus identifies the exact gap, giving the SOC team a precise picture of coverage rather than a general assurance that monitoring is in place.
This is especially consequential for the SAMA incident reporting obligations in subdomain 3.3.15. An entity cannot report what it cannot detect, and the indicators of compromise required for the formal SAMA incident report must be captured at the time of the event. Picus confirms that the detection layer will produce that signal when it matters, not after the fact.
Picus Mitigation Library strengthens this further by delivering ready-to-apply, vendor-specific detection rules and vendor-neutral SIGMA rules for major SIEM and EDR platforms, with each rule mapped to log sources, severity levels, and MITRE ATT&CK techniques. The alerting pipelines Picus tests are built on rules designed to produce high-fidelity, investigation-ready alerts.

Figure 1. Picus Platform provides ready-to-apply, and vendor-based detection suggestions.
3.3.16 Threat Management
|
"To obtain an adequate understanding of the Member Organization's emerging threat posture." (Subdomain 3.3.16, Objective) |
Subdomain 3.3.16 requires a threat intelligence management process that uses internal and external sources, a defined methodology to analyze threat information periodically, and the relevant details on identified threats such as modus operandi, actors, motivation, and type of threats, with relevance and actionability for follow-up by the SOC and Risk Management.
How does Picus operationalize SAMA CSF threat intelligence?
Intelligence reports describe what adversaries are doing. They cannot tell a Member Organization whether its specific controls would stop those adversaries. Picus closes that gap by converting threat intelligence into executable attack scenarios, running the actual techniques attributed to active threat groups against the entity's live controls, and measuring the outcome. The SOC and Risk Management teams receive a direct answer: for each known threat, is the organization currently defended or not?
The Picus Threat Library is continuously updated with new campaigns, malware families, and APT group techniques, keeping validation current with the emerging threat posture subdomain 3.3.16 requires monitoring. Intelligence gathered from SAMA, government agencies, security forums, and specialist sources can be mapped directly to executable scenarios, making the actionability requirement of subdomain 3.3.16 something the entity can measure rather than assert.
3.3.17 Vulnerability Management
|
"To ensure timely identification and effective mitigation of application and infrastructure vulnerabilities in order to reduce the likelihood and business impact for the Member Organization." (Subdomain 3.3.17, Objective) |
Subdomain 3.3.17 requires a vulnerability management process covering all information assets, risk-based scan frequency, classification of vulnerabilities, defined mitigation timelines per classification, prioritization for classified assets, and patch management.
How does Picus prioritize SAMA CSF vulnerability remediation by real exploitability?
Picus connects directly to vulnerability management platforms including Microsoft Defender for Endpoint, Tenable, and Rapid7 InsightVM.

Figure 2. Vulnerability Asset List Provided by Picus Platform Integrations
Rather than treating every finding with equal urgency, the Exposure Validation capability cross-references each vulnerability against actual attack simulation results, surfacing only those that remain genuinely exploitable in the entity's specific control environment. With this capability, vulnerabilities already neutralized by compensating controls are deprioritized regardless of their theoretical severity score.
Figure 3. Picus Platform Assigns a Context-based Picus Score.
This gives Member Organizations the risk-based prioritization and defensible mitigation timelines subdomain 3.3.17 requires, focused on real exposure rather than scanner output volume. After a patch is applied, Picus re-runs the relevant attack scenario to confirm that the exploitation path no longer succeeds, giving the entity documented, time-stamped evidence that the vulnerability has been effectively remediated and not simply marked closed.
3.3.7 Change Management & 3.3.8 Infrastructure Security
|
"The Member Organization should define, approve and implement cyber security standards for their infrastructure components. The compliance with these standards should be monitored and the effectiveness should be measured and periodically evaluated." (Subdomain 3.3.8, Principle) |
Two closely related subdomains govern secure development and operations.
- Subdomain 3.3.7 (Change Management) requires a change management process that controls all changes to information assets.
- Subdomain 3.3.8 (Infrastructure Security) requires standards covering network segmentation, malicious code and APT protection, secure protocols, DDOS protection, and patch management across all infrastructure instances.
How does Picus validate the development and operations surface for SAMA CSF?
Picus tests infrastructure security controls at the point of enforcement. Firewalls and IPS are validated through real network infiltration scenarios. Secure email gateways and firewalls face email-based delivery techniques. WAFs, IPS, and Web Security Gateways are subjected to web application attack scenarios. Each test confirms whether the device is actually stopping the traffic it is configured to stop, not whether the policy is written correctly.
Endpoint and network defenses are tested against current malware families and adversary tooling, including the APT techniques subdomain 3.3.8 specifically calls for, using threat profiles matched to groups active against the financial sector.

Figure 4. Picus Threat Library Updated With the Latest APT Attacks
For change management, Picus re-runs the relevant attack scenarios after each infrastructure change, confirming that updated controls have not introduced new exploitation paths or degraded existing ones. The post-implementation review subdomain 3.3.7 requires is backed by documented test results rather than a sign-off based on configuration review alone.
3.3.5 Identity and Access Management
|
"The Member Organization should restrict access to its information assets in line with their business requirements based on the need-to-have or need-to-know principles." (Subdomain 3.3.5, Principle) |
Subdomain 3.3.5 requires a defined identity and access management policy covering user access management, centralization, multi-factor authentication for sensitive and critical systems, and privileged and remote access management. It explicitly requires multi-factor authentication for all remote access and for privileged access on critical systems based on a risk assessment, along with periodic review of privileged accounts. These controls are frequently strong on paper and weak in practice, with drift, misconfiguration, and over-provisioned privilege among the most commonly exploited weaknesses.
How does Picus test SAMA CSF access controls against real attacker methodology?
Picus Autonomous Pentesting uses AI-driven agents to safely pursue defined objectives, such as reaching a domain controller or a sensitive database, chaining real but controlled exploitation steps across hosts. Every step is traceable, producing a documented attack path with a full chain of custody, not a list of isolated theoretical vulnerabilities.
This approach directly tests whether the access restrictions and authentication mechanisms required by subdomain 3.3.5 hold against credential theft, privilege escalation, and abuse of IAM and Active Directory configurations, or whether they can be bypassed under real attack conditions.
In cloud environments, Picus Platform extends this testing to IAM policies, misconfiguration exploitation, and privilege escalation across AWS, Azure, and GCP.

Figure 5. Picus Platform can simulate cloud-based attacks for Azure, AWS, and GCP.
Member Organizations receive a clear picture of where privilege and authentication controls break down, with specific remediation guidance tied to each finding.
3.2 Cyber Security Risk Management and Compliance
3.2.1 Cyber Security Risk Management
|
"A cyber security risk management process should be defined, approved and implemented, and should be aligned with the Member Organization's enterprise risk management process." (Subdomain 3.2.1, Principle) |
Subdomain 3.2.1 requires a documented risk management process addressing risk identification, analysis, response, and monitoring and review.
- Risk identification (3.2.1.1) must address relevant assets, threats, vulnerabilities, and existing controls.
- Risk analysis (3.2.1.2) must address the level of potential business impact and the likelihood of cyber security threat events materializing.
- Risk response (3.2.1.3) requires evaluating the strengths and weaknesses of controls and documenting residual risk.
How does Picus ground SAMA CSF risk management in reality?
Risk assessments built on theoretical severity scores paint a picture of what could go wrong. They cannot answer the question SAMA's risk management process ultimately demands: what is exploitable right now, in this environment, against these specific controls? CVSS scores and configuration reviews have no visibility into whether the controls already in place neutralize a given threat before it reaches its target.
Picus fills that gap through Adversarial Exposure Validation (AEV), combining agentic, autonomous Breach and Attack Simulation (BAS) and Autonomous Penetration Testing to test whether identified risks are actually exploitable against the entity's live defenses. The Picus Score gives risk owners an evidence-based measure of exposure to bring to senior management, the cybersecurity committee, and SAMA. This way, risk owners can demonstrate that the residual risk they have chosen to accept and sign off reflects operational reality.
This connects the four stages of the risk management lifecycle to tested outcomes. Risk identification gains context from validated exploitability. Risk analysis produces defensible likelihood assessments. Risk response can be verified against the controls chosen to mitigate each risk. And risk monitoring becomes continuous rather than periodic, because Picus tracks control performance against live threats on an ongoing basis.
3.2.4 Cyber Security Review & 3.2.5 Cyber Security Audits
|
"To ascertain whether the cyber security controls are securely designed and implemented, and the effectiveness of these controls is being monitored." (Subdomain 3.2.4, Objective) |
This is the single most consequential capability for SAMA CSF maturity progression. Subdomain 3.2.4 (Cyber Security Review) requires periodic reviews of critical information assets, with customer and internet-facing services subject to annual review and penetration tests. Subdomain 3.2.5 (Cyber Security Audits) requires thorough, independent, and regular audits to ascertain with reasonable assurance whether controls are securely designed, implemented, and monitored for effectiveness.
Underpinning both is the maturity model itself. Reaching level 4 requires that the effectiveness of implemented cyber security controls be periodically measured and evaluated, with KRIs defining thresholds for whether results are below, on, or above the targeted norm. SAMA does not merely permit effectiveness testing for higher maturity. It requires it.
This is precisely the function of the Picus Platform.
How does Picus validate control effectiveness for SAMA CSF?
Security controls do not stay effective by default. Configuration drift, new malware campaigns, and evolving attacker techniques all erode posture between assessments. Picus addresses this by simulating attack techniques against live controls on a continuous basis, measuring at each step whether the controls block, detect, log, and alert on the specific threats they are designed to stop.
The output is an always-current, MITRE ATT&CK-mapped view of control performance, covering prevention scores, detection coverage rates, and remediation tracking, updated as the threat landscape and the entity's configuration change. This is the kind of ongoing measurement and evaluation that subdomains 3.2.4, 3.2.5, and maturity levels 4 and 5 require, not as a one-off exercise but as a continuous operational process.
When SAMA asks a Member Organization to demonstrate not just that it performs cyber security reviews, but that its controls are actually working and that effectiveness is being monitored, the entity can point to a running record of validated test results rather than assembling a narrative for the occasion.
3.1 Cyber Security Leadership and Governance
3.1.1 Cyber Security Governance & 3.1.4 Cyber Security Roles and Responsibilities
|
"A cyber security governance structure should be defined and implemented, and should be endorsed by the board." (Subdomain 3.1.1, Principle) |
SAMA CSF places the ultimate responsibility for cyber security with the board of the Member Organization. Subdomain 3.1.1 requires a board-mandated cyber security committee, an independent cyber security function, and a CISO appointed at senior management level.
Subdomain 3.1.4 makes the Board of Directors responsible for endorsing the cyber security governance, strategy, and policy, and requires the cyber security committee to approve, communicate, support, and monitor these, along with the KRIs and KPIs for cyber security.
What does the board actually need to discharge this duty?
Board-level oversight of cyber security is only meaningful when it is grounded in measurable outcomes. Picus supplies that grounding: prevention and detection scores updated continuously against live attack simulations, posture trend lines that show whether the entity's security is strengthening or eroding over time, and a clear view of which gaps remain open.
The cyber security committee can anchor its endorsement, approval, and monitoring duties in validated evidence rather than assurance narratives. When a KRI threshold is approached or breached, Picus Platform surfaces the signal, giving the committee the timely, objective data subdomain 3.1.4 requires it to act on.
2.3 Self-Assessment, Review and Audit
|
"The implementation of the Framework at the Member Organization will be subject to a periodic self-assessment ... The self-assessments will be reviewed and audited by SAMA to determine the level of compliance with the Framework and the cyber security maturity level of the Member Organization." (Section 2.3) |
SAMA backs its Framework with real supervisory oversight. Member Organizations perform periodic self-assessments, customer and internet-facing services are subject to annual review and penetration tests under subdomain 3.2.4, and cyber security audits under subdomain 3.2.5 must be thorough, independent, and regular. SAMA reviews and audits these results to determine both compliance and maturity level.
How does Picus make SAMA CSF self-assessment and audit defensible?
SAMA's review and audit process asks a straightforward question: do the controls work? Picus answers it with a continuously produced, time-stamped record of actual test results, each mapped to MITRE ATT&CK and tied to a specific control's block, detect, log, or miss outcome. Because the record is generated on an ongoing basis rather than assembled for an assessment, Member Organizations enter every SAMA review with current evidence rather than a summary produced in the days before the audit.

Figure 6. Overview Results of a Simulation Showing Prevention Score Progress
That record shows exactly what was tested, what was blocked, what was detected, what was logged and alerted on, and what was not. This directly supports the internal and independent cyber security audits required by subdomain 3.2.5 and maps to the maturity model's expectation that implementation "can be demonstrated" at level 3 and that effectiveness is "measured and periodically evaluated" at level 4.
Making SAMA CSF Compliance Resilient with Validation
The SAMA Cyber Security Framework was designed to ensure that the information assets and online services underpinning the Saudi financial sector remain resilient because the controls protecting them work in practice, not just on paper. The framework says so in its own structure: the cyber security maturity model ties levels 3, 4, and 5 to demonstrable implementation, measured effectiveness, and continuous improvement, while subdomains 3.2.4 and 3.2.5 empower SAMA to review and audit whether controls are securely designed, implemented, and monitored for effectiveness.
Member Organizations should therefore approach SAMA CSF not as a one-time documentation exercise but as a long-term commitment to continuous assurance. Detection rules degrade, segmentation weakens after changes, access controls drift, and new adversary techniques emerge without being tested against existing defenses. When control effectiveness is assumed rather than proven, SAMA CSF compliance and maturity become fragile precisely at the moment a SAMA reviewer, an auditor, or an attacker tests it.
The Picus Platform helps Member Organizations move from periodic, assumption-based compliance to continuous, evidence-based assurance. By validating control effectiveness against real attack behavior, Picus turns SAMA CSF compliance into a living, defensible security posture, and helps entities progress and sustain higher maturity levels, satisfying SAMA IT Risk Supervision and internal auditors not just at the time of assessment, but continuously.
Get your free demo and see how Picus helps SAMA-regulated Member Organizations meet their Cyber Security Framework obligations with audit-ready evidence.

