SAMA Cyber Security Framework (CSF) for Fintechs: What You Need and a Compliance Checklist
The SAMA Cyber Security Framework (CSF), issued in May 2017, is the cybersecurity baseline for organizations regulated by the Saudi Central Bank. It has 4 domains and 32 subdomains, and firms are expected to reach at least maturity Level 3. Payment service providers are bound to it through SAMA's PSP Regulations, and sandbox and licence applicants must meet SAMA's Cyber Resilience Fundamental Requirements. Compliance is shown through periodic self-assessment and documented evidence, not a certificate.
| Issued by | Saudi Central Bank (SAMA) |
|---|---|
| Version | 1.0, May 2017 (in force) |
| Structure | 4 domains · 32 subdomains |
| Maturity model | Levels 0–5; minimum expected: Level 3 (structured and formalized) |
| Applies to | Banks, financing companies, credit bureaus, financial market infrastructure; payment service providers via the PSP Regulations |
| Sandbox / licence applicants | Cyber Resilience Fundamental Requirements (CRFR), January 2022 |
| Assessment | Periodic self-assessment shared with SAMA; SAMA may review or audit at any time |
| Certificate | None |
What is the SAMA Cyber Security Framework?
The Saudi Central Bank (SAMA) issued version 1.0 of its Cyber Security Framework on 24 May 2017. It gives regulated financial institutions a common way to identify and address cyber risk. It remains in force and is the reference that SAMA's other rulebooks, licensing guidelines and supervisors point to.
Saudi fintech has grown fast. According to the Financial Sector Development Program, 261 fintech companies were operating in the Kingdom at the end of 2024. For most of them, "show us your CSF compliance" is now a standard question from SAMA, partner banks and investors.
The 4 domains of the SAMA CSF
| Domain | What it covers |
|---|---|
| 1. Cyber Security Leadership and Governance (7 subdomains) | Cybersecurity governance, strategy, policy, roles and responsibilities, cybersecurity in the project lifecycle, awareness and training |
| 2. Cyber Security Risk Management and Compliance (5 subdomains) | Risk management, regulatory compliance, compliance with international standards, cybersecurity review and audit |
| 3. Cyber Security Operations and Technology (17 subdomains) | Asset management, architecture, identity and access, application and change security, infrastructure, cryptography, mobile and BYOD, data protection, secure disposal, payment systems, e-banking services, event, incident, threat and vulnerability management |
| 4. Third Party Cyber Security (3 subdomains) | Contract and vendor management, outsourcing, cloud computing |
Maturity levels: why Level 3 matters
The CSF measures each control on a six-level maturity scale:
- Non-existent
- Ad-hoc
- Repeatable but informal
- Structured and formalized
- Managed and measurable
- Adaptive
The minimum expected level is Level 3: structured and formalized. At this level, controls are written down as approved policies and procedures, applied consistently and backed by evidence. This is where most young fintechs fall short: engineering teams often do good security work that is simply not documented.
Does the SAMA CSF apply to your fintech?
- Banks, financing companies, credit bureaus and financial market infrastructure are named directly in the CSF.
- Payment service providers are brought in by SAMA's PSP Regulations. Article 15.6 requires PSPs to "put in place and maintain cyber security requirements in accordance with SAMA's cyber security framework". Article 11.6(d) ties data protection controls to the CSF. The regulations also require business continuity arrangements (Art. 15.5), notification of material outsourcing changes (Art. 15.8) and notification to SAMA within 14 days of events that disrupt payment services (Art. 6.18(a)).
- Insurance companies are now supervised by the Insurance Authority, which became the sector's sole regulator in March 2024. SAMA's existing insurance rules stay in force until the Insurance Authority replaces them, so check with your regulator.
The CSF also requires that cyber incidents rated medium or above be reported to SAMA immediately.
Sandbox and licence applications
If you are entering SAMA's regulatory sandbox or applying for a licence, SAMA's Cyber Resilience Fundamental Requirements (CRFR), issued January 2022, apply to you. SAMA's sandbox guidance notes list the cyber and resilience areas that applicants must address:
- cybersecurity policy, standards and processes;
- cybersecurity regulatory compliance, with the SAMA CSF as the reference;
- vulnerability assessment and penetration testing;
- data privacy compliance and data sovereignty;
- cyber response and business continuity plans (with the SAMA BCM Framework as the reference);
- technology and cyber risk management, with a governance and operational risk matrix;
- security monitoring and incident management;
- change and release management.
Preparing this documentation early is one of the easiest ways to avoid delays in the operational readiness stage.
Other SAMA requirements that sit alongside the CSF
- Business Continuity Management Framework (February 2017): BCM governance, plans and testing.
- IT Governance Framework (November 2021): IT strategy, risk and operations governance.
- Cloud computing: covered under the CSF's third-party domain, including requirements that apply before you adopt cloud services.
SAMA CSF, NCA controls and the PDPL
A SAMA-regulated fintech falls under NCA's ECC-2:2024 only if it owns, operates or hosts critical national infrastructure. Its SAMA obligations apply either way. Every fintech that handles customer data must also comply with the Saudi Personal Data Protection Law, including 72-hour breach notification to SDAIA. And NCA's new NCNICC-1:2025 private-sector controls set the baseline for non-CNI private companies generally. The frameworks overlap heavily, so a single well-structured policy set mapped to all of them saves significant effort.
SAMA CSF checklist for fintechs
- Board-approved cybersecurity strategy and policy
- Cybersecurity function with defined roles, including a CISO or equivalent
- CSF gap assessment against all applicable subdomains, rated by maturity level
- Remediation plan to reach at least Level 3 for every applicable control
- Cyber risk assessment and risk register
- Identity and access management with MFA for privileged and remote access
- Data protection controls aligned with the CSF and the PDPL
- Vulnerability management and penetration testing programme
- Event, incident and threat management, with a SAMA reporting procedure
- Business continuity and disaster recovery plans, tested
- Third-party, outsourcing and cloud security requirements in contracts
- Staff awareness programme with records
- Periodic self-assessment, with evidence kept ready for SAMA review
Frequently Asked Questions
What is the SAMA Cyber Security Framework?
It is the cybersecurity framework issued by the Saudi Central Bank in May 2017 for the organizations it regulates. It has 4 domains and 32 subdomains, with a maturity model from Level 0 to Level 5.
What maturity level does SAMA expect?
The minimum expected maturity level is Level 3, meaning controls are structured and formalized: documented, approved and consistently applied.
Do payment companies have to comply with the SAMA CSF?
Yes. SAMA's Payment Service Provider Regulations require PSPs to put in place and maintain cybersecurity requirements in accordance with SAMA's Cyber Security Framework.
Is there a SAMA CSF certificate?
No. Compliance is demonstrated through periodic self-assessment shared with SAMA and documented evidence, and SAMA may review or audit at any time.
What do sandbox applicants need for cybersecurity?
Sandbox and licence applicants must meet SAMA's Cyber Resilience Fundamental Requirements and address areas such as cybersecurity policy, CSF compliance, penetration testing, data privacy, business continuity and incident management.
Does the NCA ECC apply to fintechs?
Only if the fintech owns, operates or hosts critical national infrastructure. SAMA requirements apply regardless, and the PDPL applies to all personal data processing.
Related guides
Sources
- SAMA Rulebook — Cyber Security Framework
- SAMA — Payment Service Provider Regulations (PDF)
- SAMA — Cyber Resilience Fundamental Requirements (PDF)
- SAMA — Regulatory Sandbox Application Guidance Notes (PDF)
- SAMA Rulebook — Business Continuity Management Framework
- SAMA Rulebook — IT Governance Framework
- Mubasher — 261 operating fintechs at end of 2024 (FSDP)
- Al Tamimi — Insurance Authority becomes sole insurance regulator
This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.