SAMA Cyber Security Framework (CSF) Compliance
Ensure your cybersecurity controls meet the Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework (CSF) requirements. Validate the effectiveness of your security posture against real attacks to demonstrate control effectiveness, progress through the maturity model, and produce audit-ready evidence year-round.
What Is the SAMA Cyber Security Framework (CSF)?
The SAMA Cyber Security Framework (SAMA CSF) is the Saudi Arabian Monetary Authority's mandate for achieving an appropriate and consistent level of cyber security across the Kingdom's financial sector.
It imposes binding obligations on all Member Organizations regulated by SAMA and is built on SAMA requirements and leading industry standards, including NIST, ISF, ISO, BASEL, and PCI.
Demonstrate control effectiveness and progress SAMA CSF maturity with autonomous validation
Why SAMA CSF Compliance Is Important
The financial sector is one of the most targeted industries in the Kingdom, and SAMA holds its Member Organizations to a higher bar than a list of boxes to tick. What ultimately matters to the regulator is assurance: confidence that the defenses guarding customer data, payment systems, and online services hold up against the threats they are meant to stop.
That assurance is difficult to sustain because security posture is never static. A control validated today can quietly fail tomorrow after a configuration change, a new exploit, or an unnoticed gap in coverage. The maturity model reflects this reality by rewarding evidence over intent: at level 3, an entity must be able to show its controls are implemented, and at level 4, it must measure and regularly reassess how well they perform. A single annual check cannot answer that question for the other 364 days of the year.
This is why continuously validating security posture has become central to how leading Member Organizations approach the SAMA CSF. A validation-led approach delivers:
- Hard proof that defenses actually stop today's attacks, instead of assurances on paper.
- Compliance evidence that stays fresh between assessments rather than going stale after each audit.
- A faster, evidence-backed path to reaching and holding higher maturity levels.
- Reporting that stands up to scrutiny from SAMA IT Risk Supervision, internal audit, and the board.
Domain 3.3 (Cyber Security Operations and Technology)
- 3.3.14 Cyber Security Event Management
- 3.3.15 Cyber Security Incident Management
- 3.3.16 Threat Management
- 3.3.17 Vulnerability Management
- 3.3.7 Change Management
- 3.3.8 Infrastructure Security
- 3.3.5 Identity and Access Management
Domain 3.2 (Cyber Security Risk Management and Compliance)
- 3.2.1 Cyber Security Risk Management
- 3.2.4 Cyber Security Review
- 3.2.5 Cyber Security Audits
Domain 3.1 (Cyber Security Leadership and Governance)
- 3.1.1 Cyber Security Governance
- 3.1.4 Cyber Security Policy and Board Oversight
Benefits of Security Validation for SAMA CSF Compliance
The Picus Platform helps SAMA-regulated Member Organizations test the effectiveness of the controls the framework requires, supporting regulatory compliance and maturity progression while reducing the risk of breaches, data tampering, and disruption to financial services.
Produce the measurable, time-stamped evidence the maturity model requires, demonstrating that implementation can be shown at level 3 and that effectiveness is measured and periodically evaluated at levels 4 and 5.
Replace theoretical scanner findings with a single Picus Score that blends CVSS, EPSS, KEV data, validated control effectiveness, and asset criticality, focusing remediation on the vulnerabilities that are genuinely exploitable in your environment.
Picus Autonomous Penetration Testing uses AI-driven agents to safely chain real exploitation steps toward critical assets on any schedule, turning periodic manual testing into continuous, evidence-backed proof of how your defenses hold against real attacks.
Validate that SIEM, EDR, and XDR controls capture logs and alert on the latest adversary behavior, flagging missing or obsolete rules so the SOC can detect and report incidents within the timelines SAMA requires.
SAMA CSF Subdomains Supported by Picus Security
Below is a list of the SAMA CSF subdomains supported by Picus, highlighting where it contributes to demonstrating control effectiveness and supporting compliance and maturity efforts.
A Practical Guide to SAMA Cyber Security Framework (CSF) Compliance Using Picus
SAMA CSF compliance does not stop at documentation. This guide walks through how Member Organizations can validate every control against real attack behavior, satisfy the effectiveness obligations of the framework and its maturity model, and produce audit-ready evidence in real time throughout the year.
Customer's Choice
2026 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation
What Our Customers Say
Picus is very good attack simulation tool in overall. It shows all security vulnerabilities and guides..
Sr. Information Security & Risk Officer
The implementation was very fast, the platform is easy to integrate and results quite intuitive to be analyzed.
CIO
A very successful platform where we can test the accuracy of our security investments and see their scores.
Manager, IT Security and Risk Management
Picus is one of the best BAS solution on the market today. The threat database it is constantly updated..
ICT Security Engineer
There is a very nice team from which I can get quick support. The application provides us with great convenience and confidence in our work.
Information Security Specialist
With the help of this product we can perform continuosly endpoint attack via latest tactics and techniques which are used by threat actors..
Manager, IT Security and Risk Management
.. It is possible to customise the campaign or schedule the assessment periodically, to test protection measure implemented on network, endpoint and email.
ICT Security Engineer
Picus is such a great product for organizations that are looking to have constant checks and validation on their security posture in the organization.
Cybersecuirty Pre-sales Engineer
Picus is a real safety measurement tool. Ever since we took Picus into our inventory, Security has helped significantly to increase our maturity level.
Cyber Defense Senior Specialist
It strengthened our security perspective and allowed us to follow trend attacks. We can test zeroday malicious threats very early because Picus could add them their attack database quickly.
Security Specialist
Picus for Compliance
See the
Picus Security Validation Platform
Request a Demo
Submit a request and we'll share answers to your top security validation and exposure management questions.
Get Threat-ready
Simulate real-world cyber threats in minutes and see a holistic view of your security effectiveness.
Frequently Asked Questions
SAMA CSF compliance means meeting the requirements of the Cyber Security Framework set by the Saudi Arabian Monetary Authority (SAMA), the regulator responsible for the stability and security of the Kingdom's financial sector. The framework is principle-based and ties compliance to a six-level cyber security maturity model, with Member Organizations expected to reach maturity level 3 or higher.
The framework applies to all Member Organizations regulated by SAMA, including all banks operating in Saudi Arabia, all insurance and reinsurance companies, all financing companies, all credit bureaus, and the Financial Market Infrastructure. Member Organizations adopt and implement the framework, while SAMA owns, interprets, and periodically reviews it.
SAMA CSF defines six maturity levels (0 through 5), and Member Organizations are expected to operate at level 3 ("Structured and formalized") or higher. Level 3 requires that controls be defined, approved, implemented, and demonstrable. Level 4 requires effectiveness to be measured and periodically evaluated with KRIs and KPIs, and level 5 requires continuous improvement supported by automated real-time monitoring.
SAMA expects defensible, repeatable, and current evidence that controls work as intended. The maturity model ties progression to demonstrable effectiveness: implementation must be capable of being demonstrated at level 3, and effectiveness must be measured and periodically evaluated at level 4. That evidence must be available for a self-assessment, a SAMA review, or a SAMA audit at any time.
Control presence means a policy is written or a tool is deployed. Control effectiveness means the control actually blocks, detects, logs, and alerts on real attacks. SAMA's higher maturity levels explicitly demand effectiveness, not just presence, which is why documenting a policy or deploying a tool alone does not move an entity up the maturity model.
Security validation runs adversary-emulated attacks against live controls to see whether they actually block and detect real threats. It turns periodic, assumption-based compliance into continuous, evidence-based assurance, producing scored, time-stamped reports mapped to MITRE ATT&CK that satisfy SAMA IT Risk Supervision, internal auditors, and the board, not just at assessment time but continuously, while helping entities progress and sustain higher maturity levels.
The Picus Platform validates control effectiveness against real-world attack techniques and produces the measurable, time-stamped evidence the framework requires at every maturity level. It maps attack paths, simulates real threats, validates control effectiveness across governance, risk management, identity and access, infrastructure, detection and response, threat management, and vulnerability management, and returns vendor-specific and vendor-neutral mitigation guidance, with new threats added on an ongoing basis to keep effectiveness testing sustainable and audit-ready.
.png?width=161&height=136&name=gartner-logo-2025%201%20(1).png)
.png?width=133&height=153&name=G2-spring-2026-badge-low%20(1).png)