ManySignal

Compliance — SAMA CSF

SAMA Cyber Security Framework — evidence for every domain, continuously

Automated control coverage across Governance, Risk & Compliance, Operations & Technology, and Third-Party — with maturity uplift instrumentation and bilingual reporting for the Saudi Central Bank.

4

SAMA CSF domains with primary or supporting coverage

Level 4

Target maturity — Managed and Measurable

AR + EN

Bilingual assessor reporting for SAMA submissions

24x7

Agentic SOC operations aligned with Domain 3

Framework coverage

SAMA CSF coverage designed for the four-domain model

The SAMA Cyber Security Framework mandates coverage across governance, risk, operations, and third-party cybersecurity. ManySignal delivers the operational spine — while surfacing evidence for governance and risk decisions that regulators expect to be data-driven, not attested.

Domain 1 — Governance evidence

Board reporting packs, policy attestation records, and role-based access reviews that align with the Cyber Security Leadership & Governance domain — sourced from platform activity rather than manual attestation.

Domain 2 — Risk & compliance signals

Continuous control monitoring feeds risk registers with real posture data; asset criticality and threat exposure are computed rather than surveyed, keeping the Risk Management & Compliance domain honest between audits.

Domain 3 — Operations & technology core

SOC operations, incident management, threat intelligence, cryptography usage, vulnerability management, and human error monitoring — the operational spine of the SAMA CSF domain three, delivered as an agentic SOC.

Domain 4 — Third-party monitoring

Third-party access, API activity, and outsourced-service events land in the same entity graph as internal telemetry — so Third-Party Cyber Security evidence is continuous, not a quarterly questionnaire.

Maturity uplift instrumentation

The platform surfaces which SAMA CSF sub-controls are at maturity 1-2 and what evidence would move them to 3-4 — turning the maturity model into an operational backlog rather than an audit surprise.

Arabic and English reporting

Assessor packages, board summaries, and control-mapping artefacts render in both Arabic and English for KSA-domiciled institutions submitting evidence to SAMA.

SAMA CSF control mapping

SAMA CSF requirement ManySignal capability
3.3.5 Cyber Security Event Management — collect, correlate, and analyse Entity graph correlates identity, endpoint, network, and cloud events; every alert triaged by AI agent
3.3.6 Cyber Security Incident Management — detect, respond, recover Case timelines with agent-driven investigation, containment actions, and post-incident evidence
3.3.7 Threat Management — intelligence-driven detection TI feeds enrich the entity graph continuously; detections retro-hunt across historical telemetry
3.3.8 Vulnerability Management — identify, evaluate, remediate Vulnerability posture tracked as living data; risk-accepted items expire and re-surface for review
3.3.9 Cryptography — approved algorithms and key lifecycle Cryptographic usage inventoried across cloud and identity providers; deprecated ciphers flagged
3.3.10 Bring Your Own Device — controlled access and data protection Managed vs unmanaged device signals in the entity graph; anomalous BYOD access flagged
3.3.14 Physical Security — controlled access to information assets Physical access system logs correlate with digital identity events to catch tailgate + credential abuse
4.1 Third-Party Cyber Security — assess, monitor, respond Third-party identity, API, and service events monitored in-line with internal telemetry
3.1 Cyber Security Governance — policies, structure, oversight Policy attestation, access reviews, and board reporting evidence generated as by-product of platform use
2.3 Cyber Security Awareness — training and phishing simulation signal Awareness event outcomes tie back to identity risk scores in the entity graph

The SAMA CSF maturity ladder

  • Level 1 — Not Existent: no defined control or process
  • Level 2 — Ad-hoc: control exists informally, applied inconsistently
  • Level 3 — Structured and Formalised: documented, approved, and applied
  • Level 4 — Managed and Measurable: metrics collected, reviewed, and acted on
  • Level 5 — Adaptive: continuously improved based on measured outcomes
  • SAMA supervisory expectation: Level 3 minimum for critical controls
  • Operational core (Domain 3) typically expected at Level 4 or higher
  • Independent assessment cycle drives the annual maturity submission

SAMA CSF — buyer questions

What is the SAMA Cyber Security Framework?

The SAMA Cyber Security Framework is a mandatory cybersecurity control framework issued by SAMA — the Saudi Central Bank (formerly Saudi Arabian Monetary Authority) — for all regulated financial institutions operating in the Kingdom of Saudi Arabia. It defines four control domains and a five-level maturity model against which member organisations self-assess and are independently assessed. It has been in force since 2017 and is enforced through supervisory review.

Which entities must comply with the SAMA CSF?

All financial institutions regulated by SAMA — commercial banks, insurance and reinsurance companies, finance companies, credit bureaus, payment services providers, and money exchangers licensed to operate in KSA. Subsidiaries of foreign banks operating branches in Saudi Arabia are also in scope. Non-financial entities in KSA typically follow NCA ECC instead.

What are the four SAMA CSF domains?

Domain 1 — Cyber Security Leadership and Governance (strategy, structure, roles, budget, awareness). Domain 2 — Cyber Security Risk Management and Compliance (risk assessment, compliance monitoring, audit). Domain 3 — Cyber Security Operations and Technology (SOC, incident management, threat management, vulnerability management, cryptography, human resources, physical security, and more). Domain 4 — Third-Party Cyber Security (outsourcing, cloud, and vendor management).

How does the SAMA CSF maturity model work?

Each sub-control is scored on a five-level scale: Level 1 (Not Existent), Level 2 (Ad-hoc), Level 3 (Structured and Formalised), Level 4 (Managed and Measurable), and Level 5 (Adaptive). SAMA typically expects member organisations to operate at Level 3 or higher for critical controls, with Level 4-5 for the operational core. The maturity score is aggregated by domain and reported to SAMA.

How does ManySignal accelerate SAMA CSF maturity?

ManySignal directly delivers the operational evidence for Domain 3 (Operations and Technology) — SOC, incident management, threat management, vulnerability posture, cryptographic monitoring — as continuous data rather than attested policy. This raises baseline maturity from Ad-hoc / Structured (Level 2-3) toward Managed and Measurable (Level 4) because the platform produces quantified metrics on every control it covers, and the evidence is inspectable by assessors on demand.

Prepare your SAMA CSF submission with continuous evidence

Book a working session with our KSA compliance team to walk through your current maturity, gap areas, and the ManySignal evidence package that supports your next SAMA submission.