SAMA CSF compliance: cybersecurity for Saudi financial institutions
The SAMA Cyber Security Framework is the binding cybersecurity standard for every financial institution regulated by the Saudi Central Bank. It applies to banks, insurance and reinsurance companies, finance companies, payment service providers, money exchangers, and credit bureaus operating in the Kingdom of Saudi Arabia.
The framework spans four primary domains, Cyber Security Leadership and Governance, Cyber Security Risk Management and Compliance, Cyber Security Operations and Technology, and Third Party Cyber Security, broken down into subdomains and individual controls. Each subdomain is assessed against a six-level maturity scale, with member organizations expected to operate at level 3 (Defined) or above across the board, and at level 4 (Managed) in critical areas.
SAMA reinforces the framework with periodic self-assessments, supervisory reviews, and strict incident notification requirements. Falling below expected maturity has supervisory and reputational consequences, and is frequently a blocker for new licenses, products, or cross-border activities.
Running SAMA CSF as a continuous program with Waaqi
SAMA CSF is too large and too dynamic to run as a once-a-year exercise. Waaqi consolidates the entire framework, all domains, subdomains, and controls, into a single operating model. Every control has a designated owner, an evidence requirement, a freshness rule, and a maturity scoring algorithm tied to the SAMA model.
Evidence is collected automatically through integrations with cloud, identity, endpoint, SIEM, ticketing, and HR systems, supplemented by recurring tasks for procedural evidence. Maturity scoring updates continuously, so the question "what is our SAMA CSF maturity today?" has a real answer rather than a stale dashboard.
Self-assessment cycles are managed end-to-end: scope confirmation, control walkthroughs, evidence review, exception handling, management sign-off, and submission package generation in the format SAMA expects.
SAMA CSF, NCA ECC, PCI DSS, and KSA PDPL in one program
Saudi financial institutions almost always face overlapping regimes: NCA ECC as the national baseline, SAMA CSF as the sector framework, PCI DSS for cardholder data, KSA PDPL for personal data, and frequently ISO 27001 for international partners. Running these as separate programs creates duplication, conflicting evidence, and audit fatigue.
Waaqi's cross-mapping engine ties every SAMA CSF control to its equivalents in NCA ECC, PCI DSS, ISO 27001 Annex A, NIST CSF, and KSA PDPL. A single control implementation and a single piece of evidence satisfy every overlapping requirement, and CISOs report posture across all frameworks from one source of truth.
SAMA reporting, incident notification, and supervisory readiness
SAMA expects timely, structured incident notifications with severity classification, business impact, customer impact, regulatory implications, and remediation status. Waaqi's incident workflow captures all of this with SAMA-aligned templates, countdown timers, evidence attachment, and post-incident learning records linked back to the affected controls.
For supervisory reviews, Waaqi's auditor workspace gives the assessor a read-only, CSF-scoped view of every control, its evidence, exception history, and risk treatment, making reviews shorter and dramatically more likely to confirm the maturity level the institution claims.
