Compliance — SAMA CSF
SAMA Cyber Security Framework — evidence for every domain, continuously
Automated control coverage across Governance, Risk & Compliance, Operations & Technology, and Third-Party — with maturity uplift instrumentation and bilingual reporting for the Saudi Central Bank.
4
SAMA CSF domains with primary or supporting coverage
Level 4
Target maturity — Managed and Measurable
AR + EN
Bilingual assessor reporting for SAMA submissions
24x7
Agentic SOC operations aligned with Domain 3
SAMA CSF coverage designed for the four-domain model
The SAMA Cyber Security Framework mandates coverage across governance, risk, operations, and third-party cybersecurity. ManySignal delivers the operational spine — while surfacing evidence for governance and risk decisions that regulators expect to be data-driven, not attested.
Domain 1 — Governance evidence
Board reporting packs, policy attestation records, and role-based access reviews that align with the Cyber Security Leadership & Governance domain — sourced from platform activity rather than manual attestation.
Domain 2 — Risk & compliance signals
Continuous control monitoring feeds risk registers with real posture data; asset criticality and threat exposure are computed rather than surveyed, keeping the Risk Management & Compliance domain honest between audits.
Domain 3 — Operations & technology core
SOC operations, incident management, threat intelligence, cryptography usage, vulnerability management, and human error monitoring — the operational spine of the SAMA CSF domain three, delivered as an agentic SOC.
Domain 4 — Third-party monitoring
Third-party access, API activity, and outsourced-service events land in the same entity graph as internal telemetry — so Third-Party Cyber Security evidence is continuous, not a quarterly questionnaire.
Maturity uplift instrumentation
The platform surfaces which SAMA CSF sub-controls are at maturity 1-2 and what evidence would move them to 3-4 — turning the maturity model into an operational backlog rather than an audit surprise.
Arabic and English reporting
Assessor packages, board summaries, and control-mapping artefacts render in both Arabic and English for KSA-domiciled institutions submitting evidence to SAMA.
SAMA CSF control mapping
| SAMA CSF requirement | ManySignal capability |
|---|---|
| 3.3.5 Cyber Security Event Management — collect, correlate, and analyse | Entity graph correlates identity, endpoint, network, and cloud events; every alert triaged by AI agent |
| 3.3.6 Cyber Security Incident Management — detect, respond, recover | Case timelines with agent-driven investigation, containment actions, and post-incident evidence |
| 3.3.7 Threat Management — intelligence-driven detection | TI feeds enrich the entity graph continuously; detections retro-hunt across historical telemetry |
| 3.3.8 Vulnerability Management — identify, evaluate, remediate | Vulnerability posture tracked as living data; risk-accepted items expire and re-surface for review |
| 3.3.9 Cryptography — approved algorithms and key lifecycle | Cryptographic usage inventoried across cloud and identity providers; deprecated ciphers flagged |
| 3.3.10 Bring Your Own Device — controlled access and data protection | Managed vs unmanaged device signals in the entity graph; anomalous BYOD access flagged |
| 3.3.14 Physical Security — controlled access to information assets | Physical access system logs correlate with digital identity events to catch tailgate + credential abuse |
| 4.1 Third-Party Cyber Security — assess, monitor, respond | Third-party identity, API, and service events monitored in-line with internal telemetry |
| 3.1 Cyber Security Governance — policies, structure, oversight | Policy attestation, access reviews, and board reporting evidence generated as by-product of platform use |
| 2.3 Cyber Security Awareness — training and phishing simulation signal | Awareness event outcomes tie back to identity risk scores in the entity graph |
The SAMA CSF maturity ladder
- Level 1 — Not Existent: no defined control or process
- Level 2 — Ad-hoc: control exists informally, applied inconsistently
- Level 3 — Structured and Formalised: documented, approved, and applied
- Level 4 — Managed and Measurable: metrics collected, reviewed, and acted on
- Level 5 — Adaptive: continuously improved based on measured outcomes
- SAMA supervisory expectation: Level 3 minimum for critical controls
- Operational core (Domain 3) typically expected at Level 4 or higher
- Independent assessment cycle drives the annual maturity submission
SAMA CSF — buyer questions
What is the SAMA Cyber Security Framework?
The SAMA Cyber Security Framework is a mandatory cybersecurity control framework issued by SAMA — the Saudi Central Bank (formerly Saudi Arabian Monetary Authority) — for all regulated financial institutions operating in the Kingdom of Saudi Arabia. It defines four control domains and a five-level maturity model against which member organisations self-assess and are independently assessed. It has been in force since 2017 and is enforced through supervisory review.
Which entities must comply with the SAMA CSF?
All financial institutions regulated by SAMA — commercial banks, insurance and reinsurance companies, finance companies, credit bureaus, payment services providers, and money exchangers licensed to operate in KSA. Subsidiaries of foreign banks operating branches in Saudi Arabia are also in scope. Non-financial entities in KSA typically follow NCA ECC instead.
What are the four SAMA CSF domains?
Domain 1 — Cyber Security Leadership and Governance (strategy, structure, roles, budget, awareness). Domain 2 — Cyber Security Risk Management and Compliance (risk assessment, compliance monitoring, audit). Domain 3 — Cyber Security Operations and Technology (SOC, incident management, threat management, vulnerability management, cryptography, human resources, physical security, and more). Domain 4 — Third-Party Cyber Security (outsourcing, cloud, and vendor management).
How does the SAMA CSF maturity model work?
Each sub-control is scored on a five-level scale: Level 1 (Not Existent), Level 2 (Ad-hoc), Level 3 (Structured and Formalised), Level 4 (Managed and Measurable), and Level 5 (Adaptive). SAMA typically expects member organisations to operate at Level 3 or higher for critical controls, with Level 4-5 for the operational core. The maturity score is aggregated by domain and reported to SAMA.
How does ManySignal accelerate SAMA CSF maturity?
ManySignal directly delivers the operational evidence for Domain 3 (Operations and Technology) — SOC, incident management, threat management, vulnerability posture, cryptographic monitoring — as continuous data rather than attested policy. This raises baseline maturity from Ad-hoc / Structured (Level 2-3) toward Managed and Measurable (Level 4) because the platform produces quantified metrics on every control it covers, and the evidence is inspectable by assessors on demand.
Prepare your SAMA CSF submission with continuous evidence
Book a working session with our KSA compliance team to walk through your current maturity, gap areas, and the ManySignal evidence package that supports your next SAMA submission.