SAMA Cyber Security Framework (CSF) Compliance

Ensure your cybersecurity controls meet the Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework (CSF) requirements. Validate the effectiveness of your security posture against real attacks to demonstrate control effectiveness, progress through the maturity model, and produce audit-ready evidence year-round.

 

What Is the SAMA Cyber Security Framework (CSF)?

The SAMA Cyber Security Framework (SAMA CSF) is the Saudi Arabian Monetary Authority's mandate for achieving an appropriate and consistent level of cyber security across the Kingdom's financial sector.

It imposes binding obligations on all Member Organizations regulated by SAMA and is built on SAMA requirements and leading industry standards, including NIST, ISF, ISO, BASEL, and PCI.

Demonstrate control effectiveness and progress SAMA CSF maturity with autonomous validation

Why It Matters

Why SAMA CSF Compliance Is Important

The financial sector is one of the most targeted industries in the Kingdom, and SAMA holds its Member Organizations to a higher bar than a list of boxes to tick. What ultimately matters to the regulator is assurance: confidence that the defenses guarding customer data, payment systems, and online services hold up against the threats they are meant to stop.

That assurance is difficult to sustain because security posture is never static. A control validated today can quietly fail tomorrow after a configuration change, a new exploit, or an unnoticed gap in coverage. The maturity model reflects this reality by rewarding evidence over intent: at level 3, an entity must be able to show its controls are implemented, and at level 4, it must measure and regularly reassess how well they perform. A single annual check cannot answer that question for the other 364 days of the year.

This is why continuously validating security posture has become central to how leading Member Organizations approach the SAMA CSF. A validation-led approach delivers:

  • Hard proof that defenses actually stop today's attacks, instead of assurances on paper.
  • Compliance evidence that stays fresh between assessments rather than going stale after each audit.
  • A faster, evidence-backed path to reaching and holding higher maturity levels.
  • Reporting that stands up to scrutiny from SAMA IT Risk Supervision, internal audit, and the board.

What SAMA CSF Compliance Requires

SAMA CSF compliance is governed by the framework's principles, objectives, and control considerations, underpinned by the cybersecurity maturity model. The following shows which subdomains Picus helps with.

Domain 3.3 (Cyber Security Operations and Technology)

  • 3.3.14 Cyber Security Event Management
  • 3.3.15 Cyber Security Incident Management
  • 3.3.16 Threat Management
  • 3.3.17 Vulnerability Management
  • 3.3.7 Change Management
  • 3.3.8 Infrastructure Security
  • 3.3.5 Identity and Access Management

Domain 3.2 (Cyber Security Risk Management and Compliance)

  • 3.2.1 Cyber Security Risk Management
  • 3.2.4 Cyber Security Review
  • 3.2.5 Cyber Security Audits

Domain 3.1 (Cyber Security Leadership and Governance)

  • 3.1.1 Cyber Security Governance
  • 3.1.4 Cyber Security Policy and Board Oversight
mid-strip-gray-mobile mid-strip-gray

Benefits of Security Validation for SAMA CSF Compliance

The Picus Platform helps SAMA-regulated Member Organizations test the effectiveness of the controls the framework requires, supporting regulatory compliance and maturity progression while reducing the risk of breaches, data tampering, and disruption to financial services.

Progress and Sustain SAMA CSF Maturity

Produce the measurable, time-stamped evidence the maturity model requires, demonstrating that implementation can be shown at level 3 and that effectiveness is measured and periodically evaluated at levels 4 and 5.

Prioritize Real, Exploitable Risk

Replace theoretical scanner findings with a single Picus Score that blends CVSS, EPSS, KEV data, validated control effectiveness, and asset criticality, focusing remediation on the vulnerabilities that are genuinely exploitable in your environment.

Automate Penetration Testing for Continuous Assurance

Picus Autonomous Penetration Testing uses AI-driven agents to safely chain real exploitation steps toward critical assets on any schedule, turning periodic manual testing into continuous, evidence-backed proof of how your defenses hold against real attacks.

Shorten Detection and Response Gaps

Validate that SIEM, EDR, and XDR controls capture logs and alert on the latest adversary behavior, flagging missing or obsolete rules so the SOC can detect and report incidents within the timelines SAMA requires.

Requirements

SAMA CSF Subdomains Supported by Picus Security

Below is a list of the SAMA CSF subdomains supported by Picus, highlighting where it contributes to demonstrating control effectiveness and supporting compliance and maturity efforts.

SAMA CSF 3.3.14 / 3.3.15 Cyber Security Event & Incident Management
SAMA CSF 3.3.16 Threat Management
SAMA CSF 3.3.17 Vulnerability Management
SAMA CSF 3.3.7 / 3.3.8 Change Management & Infrastructure Security
SAMA CSF 3.3.5 Identity & Access Management
SAMA CSF 3.2.1 Cyber Security Risk Management
SAMA CSF 3.2.4 / 3.2.5 Cyber Security Review & Audits
SAMA CSF 3.1.1 / 3.1.4 Cyber Security Governance & Roles
PRACTICAL GUIDE

A Practical Guide to SAMA Cyber Security Framework (CSF) Compliance Using Picus

SAMA CSF compliance does not stop at documentation. This guide walks through how Member Organizations can validate every control against real attack behavior, satisfy the effectiveness obligations of the framework and its maturity model, and produce audit-ready evidence in real time throughout the year.

VALIDATED & COMPLIANT
mid-strip-gray-mobile mid-strip-gray
mid-strip-gray-mobile mid-strip-gray

gartner-logo-2025 1 (1)

Customer's Choice

2026 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation

mid-strip-gray-mobile mid-strip-gray
mid-strip-gray-mobile mid-strip-gray

G2-spring-2026-badge-low (1)

BAS Category Leader

Ranked #1 by Users on G2

What Our Customers Say

resources

Picus for Compliance

Pattern-mobile Pattern(1)

See the
Picus Security Validation Platform

Request a Demo

Submit a request and we'll share answers to your top security validation and exposure management questions.

Get Threat-ready

Simulate real-world cyber threats in minutes and see a holistic view of your security effectiveness.

Frequently Asked Questions

SAMA CSF compliance means meeting the requirements of the Cyber Security Framework set by the Saudi Arabian Monetary Authority (SAMA), the regulator responsible for the stability and security of the Kingdom's financial sector. The framework is principle-based and ties compliance to a six-level cyber security maturity model, with Member Organizations expected to reach maturity level 3 or higher.

The framework applies to all Member Organizations regulated by SAMA, including all banks operating in Saudi Arabia, all insurance and reinsurance companies, all financing companies, all credit bureaus, and the Financial Market Infrastructure. Member Organizations adopt and implement the framework, while SAMA owns, interprets, and periodically reviews it.

SAMA CSF defines six maturity levels (0 through 5), and Member Organizations are expected to operate at level 3 ("Structured and formalized") or higher. Level 3 requires that controls be defined, approved, implemented, and demonstrable. Level 4 requires effectiveness to be measured and periodically evaluated with KRIs and KPIs, and level 5 requires continuous improvement supported by automated real-time monitoring.

SAMA expects defensible, repeatable, and current evidence that controls work as intended. The maturity model ties progression to demonstrable effectiveness: implementation must be capable of being demonstrated at level 3, and effectiveness must be measured and periodically evaluated at level 4. That evidence must be available for a self-assessment, a SAMA review, or a SAMA audit at any time.

Control presence means a policy is written or a tool is deployed. Control effectiveness means the control actually blocks, detects, logs, and alerts on real attacks. SAMA's higher maturity levels explicitly demand effectiveness, not just presence, which is why documenting a policy or deploying a tool alone does not move an entity up the maturity model.

Security validation runs adversary-emulated attacks against live controls to see whether they actually block and detect real threats. It turns periodic, assumption-based compliance into continuous, evidence-based assurance, producing scored, time-stamped reports mapped to MITRE ATT&CK that satisfy SAMA IT Risk Supervision, internal auditors, and the board, not just at assessment time but continuously, while helping entities progress and sustain higher maturity levels.

The Picus Platform validates control effectiveness against real-world attack techniques and produces the measurable, time-stamped evidence the framework requires at every maturity level. It maps attack paths, simulates real threats, validates control effectiveness across governance, risk management, identity and access, infrastructure, detection and response, threat management, and vulnerability management, and returns vendor-specific and vendor-neutral mitigation guidance, with new threats added on an ongoing basis to keep effectiveness testing sustainable and audit-ready.