WaqiSecWaqiSec

SAMA Cyber Security Framework (CSF) for Fintechs: What You Need and a Compliance Checklist

WaqiSec Compliance Team · Last reviewed:

SHORT ANSWER

The SAMA Cyber Security Framework (CSF), issued in May 2017, is the cybersecurity baseline for organizations regulated by the Saudi Central Bank. It has 4 domains and 32 subdomains, and firms are expected to reach at least maturity Level 3. Payment service providers are bound to it through SAMA's PSP Regulations, and sandbox and licence applicants must meet SAMA's Cyber Resilience Fundamental Requirements. Compliance is shown through periodic self-assessment and documented evidence, not a certificate.

Issued bySaudi Central Bank (SAMA)
Version1.0, May 2017 (in force)
Structure4 domains · 32 subdomains
Maturity modelLevels 0–5; minimum expected: Level 3 (structured and formalized)
Applies toBanks, financing companies, credit bureaus, financial market infrastructure; payment service providers via the PSP Regulations
Sandbox / licence applicantsCyber Resilience Fundamental Requirements (CRFR), January 2022
AssessmentPeriodic self-assessment shared with SAMA; SAMA may review or audit at any time
CertificateNone

What is the SAMA Cyber Security Framework?

The Saudi Central Bank (SAMA) issued version 1.0 of its Cyber Security Framework on 24 May 2017. It gives regulated financial institutions a common way to identify and address cyber risk. It remains in force and is the reference that SAMA's other rulebooks, licensing guidelines and supervisors point to.

Saudi fintech has grown fast. According to the Financial Sector Development Program, 261 fintech companies were operating in the Kingdom at the end of 2024. For most of them, "show us your CSF compliance" is now a standard question from SAMA, partner banks and investors.

The 4 domains of the SAMA CSF

DomainWhat it covers
1. Cyber Security Leadership and Governance (7 subdomains)Cybersecurity governance, strategy, policy, roles and responsibilities, cybersecurity in the project lifecycle, awareness and training
2. Cyber Security Risk Management and Compliance (5 subdomains)Risk management, regulatory compliance, compliance with international standards, cybersecurity review and audit
3. Cyber Security Operations and Technology (17 subdomains)Asset management, architecture, identity and access, application and change security, infrastructure, cryptography, mobile and BYOD, data protection, secure disposal, payment systems, e-banking services, event, incident, threat and vulnerability management
4. Third Party Cyber Security (3 subdomains)Contract and vendor management, outsourcing, cloud computing

Maturity levels: why Level 3 matters

The CSF measures each control on a six-level maturity scale:

  1. Non-existent
  2. Ad-hoc
  3. Repeatable but informal
  4. Structured and formalized
  5. Managed and measurable
  6. Adaptive

The minimum expected level is Level 3: structured and formalized. At this level, controls are written down as approved policies and procedures, applied consistently and backed by evidence. This is where most young fintechs fall short: engineering teams often do good security work that is simply not documented.

Does the SAMA CSF apply to your fintech?

The CSF also requires that cyber incidents rated medium or above be reported to SAMA immediately.

Sandbox and licence applications

If you are entering SAMA's regulatory sandbox or applying for a licence, SAMA's Cyber Resilience Fundamental Requirements (CRFR), issued January 2022, apply to you. SAMA's sandbox guidance notes list the cyber and resilience areas that applicants must address:

Preparing this documentation early is one of the easiest ways to avoid delays in the operational readiness stage.

SAMA CSF, NCA controls and the PDPL

A SAMA-regulated fintech falls under NCA's ECC-2:2024 only if it owns, operates or hosts critical national infrastructure. Its SAMA obligations apply either way. Every fintech that handles customer data must also comply with the Saudi Personal Data Protection Law, including 72-hour breach notification to SDAIA. And NCA's new NCNICC-1:2025 private-sector controls set the baseline for non-CNI private companies generally. The frameworks overlap heavily, so a single well-structured policy set mapped to all of them saves significant effort.

SAMA CSF checklist for fintechs

Frequently Asked Questions

What is the SAMA Cyber Security Framework?

It is the cybersecurity framework issued by the Saudi Central Bank in May 2017 for the organizations it regulates. It has 4 domains and 32 subdomains, with a maturity model from Level 0 to Level 5.

What maturity level does SAMA expect?

The minimum expected maturity level is Level 3, meaning controls are structured and formalized: documented, approved and consistently applied.

Do payment companies have to comply with the SAMA CSF?

Yes. SAMA's Payment Service Provider Regulations require PSPs to put in place and maintain cybersecurity requirements in accordance with SAMA's Cyber Security Framework.

Is there a SAMA CSF certificate?

No. Compliance is demonstrated through periodic self-assessment shared with SAMA and documented evidence, and SAMA may review or audit at any time.

What do sandbox applicants need for cybersecurity?

Sandbox and licence applicants must meet SAMA's Cyber Resilience Fundamental Requirements and address areas such as cybersecurity policy, CSF compliance, penetration testing, data privacy, business continuity and incident management.

Does the NCA ECC apply to fintechs?

Only if the fintech owns, operates or hosts critical national infrastructure. SAMA requirements apply regardless, and the PDPL applies to all personal data processing.

Related guides

Sources

  1. SAMA Rulebook — Cyber Security Framework
  2. SAMA — Payment Service Provider Regulations (PDF)
  3. SAMA — Cyber Resilience Fundamental Requirements (PDF)
  4. SAMA — Regulatory Sandbox Application Guidance Notes (PDF)
  5. SAMA Rulebook — Business Continuity Management Framework
  6. SAMA Rulebook — IT Governance Framework
  7. Mubasher — 261 operating fintechs at end of 2024 (FSDP)
  8. Al Tamimi — Insurance Authority becomes sole insurance regulator

This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.

💬