ManySignal

Compliance — SAMA CSF checklist

SAMA CSF compliance checklist — every domain, every evidence artefact

A domain-by-domain readiness checklist for KSA financial institutions preparing for SAMA Cyber Security Framework assessment — covering governance artefacts, risk evidence, operational controls, and third-party assurance.

8

Checklist sections spanning the four SAMA CSF domains

40+

Evidence artefacts defined with owner and format

Level 4

Managed and Measurable — the maturity most items target

Bilingual

Arabic and English evidence exports for assessors

How ManySignal helps

The checklist that ticks itself as the SOC runs

A SAMA CSF checklist is only useful if the evidence behind each item is real, current, and inspectable. ManySignal produces the operational evidence as a by-product of running the SOC — so the checklist stays green between assessment cycles rather than sprinting in the last month.

Automated evidence collection

ManySignal writes the operational evidence — event correlation logs, incident timelines, vulnerability posture snapshots, cryptographic inventory — as the platform runs, so the checklist ticks itself as work happens.

Bilingual assessor package

Every checklist item exports with both Arabic and English descriptions, control mapping, and evidence hash — formatted for the SAMA assessor's working paper structure.

Gap register with owner and ETA

Items marked Not Ready generate a gap record with default owner, target maturity level, and evidence definition — so the checklist doubles as a remediation plan.

Retention aligned with SAMA cycle

Evidence retained for the SAMA-required period with immutable signed hashes; historical maturity submissions remain replayable years after the fact.

Assessor read-only workspace

Give your independent assessor a scoped, read-only view of the platform to inspect evidence directly — reducing back-and-forth on artefact requests during assessment.

Common gap heuristics

The platform highlights the checklist items that SAMA assessors most frequently mark deficient — third-party monitoring evidence, cryptographic inventory completeness, incident post-mortems — so you triage those first.

The checklist

SAMA CSF readiness — item by item

Use this as your working checklist ahead of the SAMA CSF self-assessment and independent assessment. Group ownership by domain — governance items to CISO, operational items to SOC lead, third-party items to procurement plus security.

Domain 1 — Cyber Security Leadership and Governance

  • ✓ Board-approved cybersecurity strategy on file with review date within the SAMA-required cycle
  • ✓ Cybersecurity organisational structure documented with CISO reporting line above the CIO
  • ✓ Cybersecurity policies approved, version-controlled, and attested by relevant staff
  • ✓ Cybersecurity budget separately identified in the annual financial plan
  • ✓ Cybersecurity awareness programme with participation records and phishing simulation outcomes

Domain 2 — Cyber Security Risk Management and Compliance

  • ✓ Enterprise cyber risk register with owner, likelihood, impact, and treatment for each entry
  • ✓ Risk assessment methodology documented and applied to new systems and changes
  • ✓ Compliance monitoring evidence — including regulatory obligations beyond SAMA CSF
  • ✓ Internal audit plan covering all cybersecurity domains on a rotating basis
  • ✓ Audit findings tracked to closure with milestone evidence

Domain 3 — Human Resources and Awareness

  • ✓ Background checks completed for all personnel with access to sensitive systems
  • ✓ Cybersecurity clauses in employment contracts and NDAs
  • ✓ Onboarding and offboarding checklists that revoke access on the same day
  • ✓ Role-based awareness training completion records — general, IT, and privileged users
  • ✓ Phishing simulation results with follow-up training for repeat clickers

Domain 3 — Operations and Technology

  • ✓ 24x7 SOC operational with incident classification, escalation, and evidence retention
  • ✓ Cyber incident management runbooks tested annually with tabletop or live exercise
  • ✓ Threat intelligence feeds integrated into detection and vulnerability prioritisation
  • ✓ Vulnerability management programme with SLAs by severity and asset criticality
  • ✓ Cryptographic inventory covering algorithms, key lifecycle, and approved use
  • ✓ Log retention meeting SAMA duration requirements with tamper-evident storage
  • ✓ Change management records tied to production deployments and rollback capability

Domain 3 — Physical and Environmental Security

  • ✓ Data centre access controls with individually attributable entry records
  • ✓ Correlation of physical access events with digital identity events for anomaly detection
  • ✓ Environmental monitoring — power, cooling, fire — with alerting to operations
  • ✓ Media handling procedures for magnetic and solid-state storage disposal

Domain 3 — Business Continuity and Cyber Resilience

  • ✓ Business continuity plan tested with a cyber scenario in the last twelve months
  • ✓ Backup integrity tested via full restore in the last twelve months
  • ✓ Ransomware recovery playbook with immutable backup and clean-room restore capability
  • ✓ RTO and RPO defined per critical service and validated against BC test results

Domain 4 — Third-Party Cyber Security

  • ✓ Third-party register with cyber risk rating per vendor
  • ✓ Cybersecurity clauses in third-party contracts including audit rights
  • ✓ Right-to-audit exercised or independent assurance report reviewed for critical vendors
  • ✓ Third-party access to internal systems logged and reviewed on a defined cadence
  • ✓ Cloud service provider security assessments aligned to SAMA cloud-specific expectations

Assessment logistics

  • ✓ Independent assessor engaged from the SAMA-approved list where required
  • ✓ Evidence workspace provisioned with read-only assessor account and scope
  • ✓ Self-assessment maturity score prepared per domain with justification
  • ✓ Prior assessment findings addressed with evidence of closure
  • ✓ Executive summary and remediation roadmap prepared for board submission

Legacy prep vs ManySignal-supported prep

Traditional SAMA CSF prep With ManySignal
Assemble evidence in a shared drive across dozens of tools Evidence generated in-platform, tagged to the SAMA sub-control, retrievable by assessor query
Discover control gaps three weeks before the assessment Gap register live at all times, with owner and ETA per gap
Translate every artefact into Arabic manually before submission Bilingual export baked into the evidence generator
Post-incident review as a Word document in a folder Post-incident review generated from the case timeline with signed hashes
Vendor questionnaire refreshed once a year Third-party activity monitored continuously; questionnaire evidence is a data extract

Common gaps SAMA assessors flag

  • Cryptographic inventory incomplete — TLS versions and cipher suites unknown for legacy systems
  • Third-party monitoring based only on annual questionnaires, no telemetry
  • Post-incident reviews present but not linked to case timeline evidence
  • Awareness training records do not cover contractors and temporary staff
  • Vulnerability programme measures scan coverage but not remediation SLA adherence
  • Board reporting cadence documented but recent minutes lack cyber agenda items
  • Change management records exist but not tied to security review sign-off
  • Access reviews performed but re-certification evidence not retained per SAMA cycle

SAMA CSF checklist — buyer questions

How often does SAMA require a CSF assessment?

Regulated entities submit a self-assessment annually against the SAMA CSF maturity model, and undergo independent assessment on the cycle SAMA specifies for their category — typically every one to two years for banks and critical financial infrastructure. SAMA may also request out-of-cycle assessment following a significant incident or supervisory concern.

What are the most common gaps SAMA assessors find?

Recurring findings include incomplete cryptographic inventory (Domain 3), gaps in third-party monitoring evidence beyond questionnaires (Domain 4), post-incident reviews that are not tied to case timelines, awareness training records that do not cover all in-scope staff, and vulnerability programmes that measure scan coverage but not remediation SLA adherence. Governance items — policy versioning and board reporting cadence — are often technically present but poorly evidenced.

What evidence do I need for each maturity level?

Level 2 (Ad-hoc) needs proof the control exists in some form — an email, a runbook draft, a screenshot. Level 3 (Structured) needs an approved document, defined ownership, and evidence of application. Level 4 (Managed and Measurable) needs metrics collected over time with review records. Level 5 (Adaptive) needs evidence that measured outcomes drove improvement changes. ManySignal's evidence generation targets Level 4 by default because the platform naturally produces quantified, time-series data on every control it covers.

Can I use ManySignal evidence directly in the SAMA submission?

Yes. Evidence exports include the SAMA sub-control identifier, description in Arabic and English, the underlying data with a signed hash, and the time range covered. The format matches what SAMA-approved assessors expect to receive as working papers — you can either export to file or grant the assessor a scoped read-only workspace to inspect evidence in place.

How long does it take to reach SAMA CSF readiness with ManySignal?

For Domain 3 (Operations and Technology) — the largest domain by control count — most customers reach Level 3 within one quarter of deployment because the evidence generates as the SOC runs. Domain 1 and 2 (governance and risk) depend on organisational artefacts the platform does not produce directly but does help evidence application of. Domain 4 (third-party) accelerates as vendor telemetry lands in the entity graph. A realistic end-to-end readiness horizon is six to nine months from a Level 2 baseline.

Walk your SAMA CSF checklist with our KSA compliance team

Bring your last assessment findings and current maturity scores — we will map them against the ManySignal evidence generator and identify which items can move to Level 4 in the next quarter.