SAMA Cyber Resilience Fundamental Requirements (CRFR) Compliance

Ensure your cybersecurity controls meet the Saudi Central Bank (SAMA) Cyber Resilience Fundamental Requirements (CRFR). Validate the effectiveness of your security posture against real attacks to demonstrate control effectiveness, satisfy your licensing-stage obligations, and produce audit-ready evidence year-round.

 

What Are the SAMA Cyber Resilience Fundamental Requirements (CRFR)?

The SAMA Cyber Resilience Fundamental Requirements (SAMA CRFR) are the Saudi Central Bank's baseline cybersecurity and resilience rules for entities entering the Kingdom's financial sector.

They set a prioritized set of mandatory controls for newly established entities operating in the early stages of their lifecycle, organized across three control areas and aligned with SAMA's broader regulatory frameworks. The CRFR is not a replacement for the Cyber Security Framework (CSF) or the Business Continuity Management Framework (BCMF); it is a foundational, licensing-stage requirement that maps directly to those larger frameworks.

Demonstrate control effectiveness and meet your SAMA CRFR licensing obligations with autonomous validation

Why It Matters

Why SAMA CRFR Compliance Is Important

The financial sector is one of the most targeted industries in the Kingdom, and SAMA created the CRFR so that entities entering it are genuinely resilient before they go live. The framework is the gateway: entities seeking to qualify for SAMA's Regulatory Sandbox or a license to operate in Saudi Arabia must satisfy these fundamental requirements, and meeting them is what clears the path to sandbox graduation and licensing.

But resilience proven at the licensing stage does not stay proven on its own. As systems change, new exploits appear, and coverage drifts, controls that passed once can stop performing without anyone noticing. The CRFR anticipates this through its risk-based design, asking entities to track the evolving threat landscape, surface new and emerging risks, and treat their fundamental controls as something to keep verifying in practice, not file away on paper. Section 2.3 gives that expectation teeth: SAMA can examine an entity's self-assessment and audit its compliance whenever it chooses.

This is why continuously validating security posture has become central to how entities approach the SAMA CRFR. A validation-led approach delivers:

  • Proof that the controls SAMA expects at the licensing stage actually work, clearing the path through sandbox graduation and licensing.
  • Focused use of limited resources on the prioritized controls that matter most, exactly what the CRFR intends for new entities.
  • Continuous readiness for the self-assessment questionnaire and unannounced SAMA audits, backed by current evidence.
  • Resilience that holds after go-live, as controls are shown to keep working while threats evolve.

What SAMA CRFR Compliance Requires

The CRFR is built on a risk-based approach and organized across three control domains: Cyber Security Leadership and Governance, Cyber Security Operations and Technology, and Resilience. The controls set the essential mandatory requirements, but SAMA expects more than a paper exercise; controls must be implemented, monitored, and shown to work. The following shows which controls Picus helps with.

SAMA CRFR Controls Supported by Picus:

Domain 3.2 (Cyber Security Operations and Technology)

  • 3.2.11–3.2.14 Logging, SIEM, Continuous Monitoring, and Incident Management
  • 3.2.5 & 3.2.7 Vulnerability Assessment and Patch Management
  • 3.2.10 Endpoint Security and Malware Protection
  • 3.2.3 Secure Network Architecture
  • 3.2.6 Penetration Testing
  • 3.2.1 Identity and Access Management
  • 3.2.16 Incident Notification to SAMA

Domain 3.1 (Cyber Security Leadership and Governance)

  • 3.1.6 IT and Cyber Security Risk Assessments
  • 3.1.1 Cyber Security Leadership and Governance

Cross-Cutting Requirements

  • Section 2.3 Self-Assessment and SAMA Audit
mid-strip-gray-mobile mid-strip-gray

Benefits of Security Validation for SAMA CRFR Compliance

For a new entity, the CRFR is both a licensing hurdle and the foundation of its security program, all to be met with a lean team. By validating the fundamental controls against real attacks, the Picus Platform helps these entities clear the licensing gate, build their risk program on real evidence, and stay ready for SAMA, without the overhead of a large security function.

Clear the Licensing Gate with Evidence, Not Paperwork

For a CRFR entity, the controls are what stand between it and market entry. Picus produces demonstrable proof that the fundamental controls actually work, evidence that holds up when sandbox graduation or a license depends on it.

Stretch a Lean Security Team Further

The CRFR was written for new, resource-constrained entities. Picus automates the repetitive validation work, from breach and attack simulation to the penetration testing the framework expects, freeing a small team to focus its manual effort where human expertise counts most.

Build the Risk Register on Real Exploitability

Control 3.1.6 expects a central risk register kept under review. Picus tests live controls to find which risks are genuinely exploitable and scores each accordingly, so the register reflects real operating conditions rather than theoretical CVSS or EPSS severity.

Stay Ready for an Unannounced SAMA Review

Section 2.3 lets SAMA review an entity's self-assessment and audit it at any time. Picus generates continuous, time-stamped evidence that feeds the questionnaire and answers a short-notice "prove it works" request without a scramble.

Requirements

SAMA CRFR Controls Supported by Picus Security

Below is a list of the SAMA CRFR controls supported by Picus, highlighting where it contributes to demonstrating control effectiveness and supporting licensing-stage compliance.

SAMA CRFR 3.2.11–3.2.14 Logging, SIEM, Continuous Monitoring & Incident Management
SAMA CRFR 3.2.5 & 3.2.7 Vulnerability Assessment & Patch Management
SAMA CRFR 3.2.10 Endpoint Security & Malware Protection
SAMA CRFR 3.2.3 Secure Network Architecture
SAMA CRFR 3.2.6 Penetration Testing
SAMA CRFR 3.2.1 Identity & Access Management
SAMA CRFR 3.2.16 Incident Notification to SAMA
SAMA CRFR 3.1.6 IT & Cyber Security Risk Assessments
SAMA CRFR 3.1.1 Cyber Security Leadership & Governance
SAMA CRFR Section 2.3 Self-Assessment & SAMA Audit
PRACTICAL GUIDE

A Practical Guide to SAMA Cyber Resilience Fundamental Requirements (CRFR) Compliance Using Picus

Meeting the CRFR takes more than a completed questionnaire. This guide breaks down each of the framework's fundamental controls and shows how a new entity can prove they work under real attack conditions, turn that proof into the evidence SAMA's self-assessment and audits call for, and keep it current rather than rebuilding it before each review.

VALIDATED & COMPLIANT
mid-strip-gray-mobile mid-strip-gray
mid-strip-gray-mobile mid-strip-gray

gartner-logo-2025 1 (1)

Customer's Choice

2026 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation

mid-strip-gray-mobile mid-strip-gray
mid-strip-gray-mobile mid-strip-gray

G2-spring-2026-badge-low (1)

BAS Category Leader

Ranked #1 by Users on G2

What Our Customers Say

resources

Picus for Compliance

Pattern-mobile Pattern(1)

See the
Picus Security Validation Platform

Request a Demo

Submit a request and we'll share answers to your top security validation and exposure management questions.

Get Threat-ready

Simulate real-world cyber threats in minutes and see a holistic view of your security effectiveness.

Frequently Asked Questions

SAMA CRFR compliance means meeting the Cyber Resilience Fundamental Requirements set by the Saudi Central Bank (SAMA), the regulator responsible for the stability and security of the Kingdom's financial sector. Published in January 2022, the CRFR is a risk-based, prioritized set of mandatory controls organized across three domains, intended to ensure that entities entering the financial sector are genuinely resilient before they go live.

The framework applies to entities intending to qualify for SAMA's Regulatory Sandbox environment and to entities seeking a license to operate in the Kingdom of Saudi Arabia. It acts as a catalyst that enables these entities to meet SAMA's minimum cyber resilience licensing requirements. SAMA owns the framework and is responsible for periodically updating it.

The CRFR was published in January 2022 and was developed and is owned by the Saudi Central Bank (SAMA), which is responsible for periodically updating it. Entities adopt and implement the framework, while SAMA interprets and reviews it.

The CRFR is not a replacement for SAMA's Cyber Security Framework (CSF) or Business Continuity Management Framework (BCMF). It is a foundational, licensing-stage requirement that maps directly to those larger frameworks. Once an entity is licensed, it is expected to comply with the full set of relevant SAMA regulatory requirements.

Implementation of the CRFR is subject to periodic self-assessment based on a questionnaire, a copy of which is sent to SAMA. SAMA reserves the right to review that self-assessment to confirm compliance at its discretion, and it can also audit an entity's compliance at any time. An entity that cannot demonstrate compliance risks having its sandbox graduation or license request prohibited.

A control is "present" when an entity can point to a written policy or an installed tool. It is "effective" only when, put under real attack, it does what it was meant to, blocking, detecting, logging, and raising an alert. The CRFR's expectation sits on the second of these: a fundamental control that lives only on paper does not meet the framework, which asks for controls that are implemented, kept under watch, and demonstrably working whenever SAMA looks.

Validation puts an entity's live controls under emulated adversary activity safely and records what each one actually stops, catches, logs, and alerts on. That converts a posture built on assumptions into one built on observed results: a continuously refreshed, time-stamped record mapped to MITRE ATT&CK that an entity can feed straight into its self-assessment and place in front of a SAMA reviewer or auditor whenever asked, not only on assessment day.

Picus runs real attack techniques against an entity's defenses and turns the outcome into the dated, measurable evidence the CRFR's risk-based approach calls for. Across the controls in scope, from governance and risk assessment through identity and access, network, endpoint, and detection, to incident notification, it shows where defenses hold and where they fail, then returns vendor-specific and vendor-neutral fixes for the gaps. A continuously updated threat library keeps that testing current, so an entity stays audit-ready as new attacks emerge.