M ManySignal

Compliance — SAMA CSF (Saudi Arabia)

SAMA Cyber Security Framework — Domain 3 and 4 monitoring for Saudi financial institutions

SAMA's Cyber Security Framework requires Saudi banks, insurers, and payment companies to maintain continuous security monitoring and respond to critical incidents within hours. ManySignal provides 24x7 AI-powered monitoring, SAMA CSOC notification workflows, and third-party access monitoring — in deployments supporting Saudi data residency requirements.

SAMA CSF domain coverage

Domain 3 — Cyber Security Operations and Technology

  • 24x7 SOC monitoring via AI agents
  • Threat detection and investigation capabilities
  • Incident classification and response automation
  • MTTD and MTTR metrics for SAMA inspection
  • Log management with Saudi data residency

Domain 4 — Third-Party Cyber Security

  • Vendor and supplier access monitoring
  • Third-party credential anomaly detection
  • Data egress monitoring for third-party connections
  • Offboarding verification for terminated vendor access
  • Third-party risk monitoring evidence for SAMA

SAMA CSF compliance — common questions

What is SAMA CSF and which entities must comply?

The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework (2017, updated 2022) applies to all SAMA-regulated entities: banks, insurance companies, financing companies, payment service providers, and capital market institutions operating in the Kingdom. Compliance is assessed by SAMA during regular supervision cycles.

What are SAMA CSF's four domains?

SAMA CSF has four main domains: (1) Cyber Security Leadership and Governance — board oversight and programme management; (2) Cyber Security Risk Management and Compliance — risk assessment and compliance monitoring; (3) Cyber Security Operations and Technology — the operational security controls including SOC monitoring; (4) Third-Party Cyber Security — vendor risk management. ManySignal primarily addresses Domains 3 and 4.

How does ManySignal address SAMA CSF's SOC requirements?

SAMA CSF Domain 3 requires SAMA-regulated entities to establish security monitoring capabilities with defined detection and response times. ManySignal provides: 24x7 autonomous monitoring via AI agents, mean time to detect (MTTD) metrics, mean time to respond (MTTR) metrics, and evidence of the monitoring system operating continuously — all formatted for SAMA inspection review.

What are the cyber incident reporting requirements under SAMA CSF?

SAMA requires regulated entities to report significant cyber incidents to SAMA's Cyber Security Operations Centre (CSOC) within timelines specified in the SAMA CSF. Critical incidents are typically reportable within 2 hours. ManySignal's incident management module tracks SAMA-specific severity classifications and triggers the notification workflow within the applicable timeframe.

Does ManySignal support SAMA's third-party cyber security requirements?

SAMA CSF Domain 4 requires regulated entities to assess and monitor their third-party technology providers. ManySignal monitors vendor access to SAMA-regulated entities' systems — baselining vendor credential usage, detecting access outside business hours, and flagging access to systems outside the vendor's contracted scope. Evidence is formatted for SAMA's third-party risk management assessment.

Deploy SAMA-compliant monitoring in Saudi Arabia

Talk to our Riyadh team about SAMA CSF Domain 3 monitoring, SAMA CSOC incident reporting, and in-Kingdom data deployment options.