Compliance — SAMA CSF checklist
SAMA CSF compliance checklist — every domain, every evidence artefact
A domain-by-domain readiness checklist for KSA financial institutions preparing for SAMA Cyber Security Framework assessment — covering governance artefacts, risk evidence, operational controls, and third-party assurance.
8
Checklist sections spanning the four SAMA CSF domains
40+
Evidence artefacts defined with owner and format
Level 4
Managed and Measurable — the maturity most items target
Bilingual
Arabic and English evidence exports for assessors
The checklist that ticks itself as the SOC runs
A SAMA CSF checklist is only useful if the evidence behind each item is real, current, and inspectable. ManySignal produces the operational evidence as a by-product of running the SOC — so the checklist stays green between assessment cycles rather than sprinting in the last month.
Automated evidence collection
ManySignal writes the operational evidence — event correlation logs, incident timelines, vulnerability posture snapshots, cryptographic inventory — as the platform runs, so the checklist ticks itself as work happens.
Bilingual assessor package
Every checklist item exports with both Arabic and English descriptions, control mapping, and evidence hash — formatted for the SAMA assessor's working paper structure.
Gap register with owner and ETA
Items marked Not Ready generate a gap record with default owner, target maturity level, and evidence definition — so the checklist doubles as a remediation plan.
Retention aligned with SAMA cycle
Evidence retained for the SAMA-required period with immutable signed hashes; historical maturity submissions remain replayable years after the fact.
Assessor read-only workspace
Give your independent assessor a scoped, read-only view of the platform to inspect evidence directly — reducing back-and-forth on artefact requests during assessment.
Common gap heuristics
The platform highlights the checklist items that SAMA assessors most frequently mark deficient — third-party monitoring evidence, cryptographic inventory completeness, incident post-mortems — so you triage those first.
SAMA CSF readiness — item by item
Use this as your working checklist ahead of the SAMA CSF self-assessment and independent assessment. Group ownership by domain — governance items to CISO, operational items to SOC lead, third-party items to procurement plus security.
Domain 1 — Cyber Security Leadership and Governance
- ✓ Board-approved cybersecurity strategy on file with review date within the SAMA-required cycle
- ✓ Cybersecurity organisational structure documented with CISO reporting line above the CIO
- ✓ Cybersecurity policies approved, version-controlled, and attested by relevant staff
- ✓ Cybersecurity budget separately identified in the annual financial plan
- ✓ Cybersecurity awareness programme with participation records and phishing simulation outcomes
Domain 2 — Cyber Security Risk Management and Compliance
- ✓ Enterprise cyber risk register with owner, likelihood, impact, and treatment for each entry
- ✓ Risk assessment methodology documented and applied to new systems and changes
- ✓ Compliance monitoring evidence — including regulatory obligations beyond SAMA CSF
- ✓ Internal audit plan covering all cybersecurity domains on a rotating basis
- ✓ Audit findings tracked to closure with milestone evidence
Domain 3 — Human Resources and Awareness
- ✓ Background checks completed for all personnel with access to sensitive systems
- ✓ Cybersecurity clauses in employment contracts and NDAs
- ✓ Onboarding and offboarding checklists that revoke access on the same day
- ✓ Role-based awareness training completion records — general, IT, and privileged users
- ✓ Phishing simulation results with follow-up training for repeat clickers
Domain 3 — Operations and Technology
- ✓ 24x7 SOC operational with incident classification, escalation, and evidence retention
- ✓ Cyber incident management runbooks tested annually with tabletop or live exercise
- ✓ Threat intelligence feeds integrated into detection and vulnerability prioritisation
- ✓ Vulnerability management programme with SLAs by severity and asset criticality
- ✓ Cryptographic inventory covering algorithms, key lifecycle, and approved use
- ✓ Log retention meeting SAMA duration requirements with tamper-evident storage
- ✓ Change management records tied to production deployments and rollback capability
Domain 3 — Physical and Environmental Security
- ✓ Data centre access controls with individually attributable entry records
- ✓ Correlation of physical access events with digital identity events for anomaly detection
- ✓ Environmental monitoring — power, cooling, fire — with alerting to operations
- ✓ Media handling procedures for magnetic and solid-state storage disposal
Domain 3 — Business Continuity and Cyber Resilience
- ✓ Business continuity plan tested with a cyber scenario in the last twelve months
- ✓ Backup integrity tested via full restore in the last twelve months
- ✓ Ransomware recovery playbook with immutable backup and clean-room restore capability
- ✓ RTO and RPO defined per critical service and validated against BC test results
Domain 4 — Third-Party Cyber Security
- ✓ Third-party register with cyber risk rating per vendor
- ✓ Cybersecurity clauses in third-party contracts including audit rights
- ✓ Right-to-audit exercised or independent assurance report reviewed for critical vendors
- ✓ Third-party access to internal systems logged and reviewed on a defined cadence
- ✓ Cloud service provider security assessments aligned to SAMA cloud-specific expectations
Assessment logistics
- ✓ Independent assessor engaged from the SAMA-approved list where required
- ✓ Evidence workspace provisioned with read-only assessor account and scope
- ✓ Self-assessment maturity score prepared per domain with justification
- ✓ Prior assessment findings addressed with evidence of closure
- ✓ Executive summary and remediation roadmap prepared for board submission
Legacy prep vs ManySignal-supported prep
| Traditional SAMA CSF prep | With ManySignal |
|---|---|
| Assemble evidence in a shared drive across dozens of tools | Evidence generated in-platform, tagged to the SAMA sub-control, retrievable by assessor query |
| Discover control gaps three weeks before the assessment | Gap register live at all times, with owner and ETA per gap |
| Translate every artefact into Arabic manually before submission | Bilingual export baked into the evidence generator |
| Post-incident review as a Word document in a folder | Post-incident review generated from the case timeline with signed hashes |
| Vendor questionnaire refreshed once a year | Third-party activity monitored continuously; questionnaire evidence is a data extract |
Common gaps SAMA assessors flag
- Cryptographic inventory incomplete — TLS versions and cipher suites unknown for legacy systems
- Third-party monitoring based only on annual questionnaires, no telemetry
- Post-incident reviews present but not linked to case timeline evidence
- Awareness training records do not cover contractors and temporary staff
- Vulnerability programme measures scan coverage but not remediation SLA adherence
- Board reporting cadence documented but recent minutes lack cyber agenda items
- Change management records exist but not tied to security review sign-off
- Access reviews performed but re-certification evidence not retained per SAMA cycle
SAMA CSF checklist — buyer questions
How often does SAMA require a CSF assessment?
Regulated entities submit a self-assessment annually against the SAMA CSF maturity model, and undergo independent assessment on the cycle SAMA specifies for their category — typically every one to two years for banks and critical financial infrastructure. SAMA may also request out-of-cycle assessment following a significant incident or supervisory concern.
What are the most common gaps SAMA assessors find?
Recurring findings include incomplete cryptographic inventory (Domain 3), gaps in third-party monitoring evidence beyond questionnaires (Domain 4), post-incident reviews that are not tied to case timelines, awareness training records that do not cover all in-scope staff, and vulnerability programmes that measure scan coverage but not remediation SLA adherence. Governance items — policy versioning and board reporting cadence — are often technically present but poorly evidenced.
What evidence do I need for each maturity level?
Level 2 (Ad-hoc) needs proof the control exists in some form — an email, a runbook draft, a screenshot. Level 3 (Structured) needs an approved document, defined ownership, and evidence of application. Level 4 (Managed and Measurable) needs metrics collected over time with review records. Level 5 (Adaptive) needs evidence that measured outcomes drove improvement changes. ManySignal's evidence generation targets Level 4 by default because the platform naturally produces quantified, time-series data on every control it covers.
Can I use ManySignal evidence directly in the SAMA submission?
Yes. Evidence exports include the SAMA sub-control identifier, description in Arabic and English, the underlying data with a signed hash, and the time range covered. The format matches what SAMA-approved assessors expect to receive as working papers — you can either export to file or grant the assessor a scoped read-only workspace to inspect evidence in place.
How long does it take to reach SAMA CSF readiness with ManySignal?
For Domain 3 (Operations and Technology) — the largest domain by control count — most customers reach Level 3 within one quarter of deployment because the evidence generates as the SOC runs. Domain 1 and 2 (governance and risk) depend on organisational artefacts the platform does not produce directly but does help evidence application of. Domain 4 (third-party) accelerates as vendor telemetry lands in the entity graph. A realistic end-to-end readiness horizon is six to nine months from a Level 2 baseline.
Walk your SAMA CSF checklist with our KSA compliance team
Bring your last assessment findings and current maturity scores — we will map them against the ManySignal evidence generator and identify which items can move to Level 4 in the next quarter.