SAMA CSF Compliance Platform

SAMA CSF, measured and managed

Operationalize the Saudi Central Bank Cyber Security Framework with domain coverage, maturity scoring, evidence, and SAMA-ready reporting for banks, insurers, and finance companies.

Compliance postureLive
Control coverage
94%
Open risks
7
Evidence items
1,284
Audit findings
2
Implemented94%
In progress58%
Evidence freshness82%
  • Maturity heatmap across SAMA CSF domains
  • Open risks and corrective actions by owner
  • Incident timelines with SAMA notification status
01The problem

The SAMA CSF challenge

SAMA expects financial institutions to demonstrate measurable cybersecurity maturity across domains spanning governance, defence, resilience, and third parties, with regular self-assessments and on-site audits.

  • Multiple domains and subdomains to assess and operate
  • Maturity scoring expected per subdomain
  • Annual self-assessments with SAMA submission
  • Onsite SAMA inspections and follow-up actions
  • Third-party and outsourcing cybersecurity scrutiny
  • Incident notification to SAMA within strict timelines
02The approach

A bank-grade SAMA CSF operating model

Waaqi gives Saudi financial institutions a structured, evidence-backed SAMA CSF program with built-in maturity scoring and SAMA-ready submissions.

01

SAMA-native library

All SAMA CSF domains and subdomains pre-loaded with maturity criteria and evidence prompts.

02

Continuous maturity

Maturity scores update as evidence is captured, not once a year.

03

SAMA-ready packages

Generate self-assessments, incident reports, and inspection responses on demand.

03Capabilities

What you get inside Waaqi

Every module works from one control library, one evidence store, and one risk register.

Full SAMA CSF Library

All domains and subdomains pre-loaded with maturity rubrics and guidance.

Maturity Scoring

Five-level maturity ratings per subdomain with current vs target views and roadmaps.

Risk Management

Financial-services risk register linked to SAMA domains and KRIs.

Internal Audit

Plan and run SAMA-aligned internal audits with findings, CAPA, and reviews.

Policy Automation

Auto-generate cybersecurity policies aligned to SAMA expectations and the framework.

Incident Management

Workflow for SAMA incident reporting with timelines and post-incident reviews.

Third-Party & Outsourcing

Vendor and outsourcing risk with SAMA-aligned controls and evidence.

Multi-Framework Mapping

Reuse SAMA CSF controls for ISO 27001, NIST CSF, and PCI DSS.

04Workflow

From control definition to audit-ready evidence

Each step is owned, dated, and traceable, so nothing depends on a spreadsheet or a single person.

  1. Step 1

    Set scope & profile

    Define institution scope and target maturity per domain.

  2. Step 2

    Assign owners

    Route subdomains to business, IT, and security owners with SLAs.

  3. Step 3

    Collect evidence

    Continuous evidence updates current maturity automatically.

  4. Step 4

    Submit to SAMA

    Generate self-assessment, incident, and inspection packages on demand.

05Audit readiness

SAMA inspections, no surprises

Hand SAMA inspectors a complete, structured package with maturity rationale and evidence for every subdomain.

  • Self-assessment exports with supporting evidence
  • Maturity rationale per subdomain and review history
  • Incident register with SAMA notifications
  • Third-party and outsourcing assurance records
  • Internal audit findings and CAPA progress
06For leadership

Board level answers without a fire drill

Boards, CISOs, and risk committees get the same numbers the compliance team works from.

Board confidence

Translate SAMA maturity into business risk and investment language for the board and audit committee.

Lower regulatory exposure

Provable compliance and faster incident response reduce enforcement risk.

Operational resilience

A live SAMA program strengthens resilience, not just compliance reporting.

07FAQ

Questions we get asked

What is the SAMA Cyber Security Framework?

The SAMA Cyber Security Framework (SAMA CSF) is the mandatory cybersecurity framework issued by the Saudi Central Bank (formerly SAMA) for all regulated financial institutions in the Kingdom of Saudi Arabia. It defines required cybersecurity controls across governance, risk, defence, and resilience domains, assessed against a five-level maturity model.

Who must comply with SAMA CSF?

Every entity regulated by the Saudi Central Bank must comply, including local and foreign banks, insurance and reinsurance companies, finance companies, payment service providers, money exchangers, and credit bureaus operating in Saudi Arabia.

How is maturity measured under SAMA CSF?

SAMA CSF uses a six-level maturity scale (0 Non-existent, 1 Ad hoc, 2 Repeatable, 3 Defined, 4 Managed, 5 Adaptive). Most member organizations are expected to operate at level 3 or above across all subdomains, with critical areas at level 4. Waaqi continuously scores maturity per subdomain based on live evidence.

How does SAMA CSF relate to NCA ECC and PCI DSS?

NCA ECC is the national cybersecurity baseline; SAMA CSF is the financial-sector overlay; PCI DSS applies to card data. Most Saudi financial institutions need all three. Waaqi maps controls across SAMA CSF, NCA ECC, PCI DSS, ISO 27001, and KSA PDPL so a single implementation satisfies overlapping requirements.

What is the SAMA cybersecurity self-assessment?

SAMA requires member organizations to conduct a periodic self-assessment of their cybersecurity maturity and submit the results. Waaqi automates the self-assessment, ties every subdomain score to underlying evidence, and produces the submission package on demand.

What does SAMA expect for incident reporting?

Member organizations must notify SAMA of cybersecurity incidents within prescribed timelines, with severity classification, impact analysis, and remediation status. Waaqi includes a SAMA-aligned incident workflow with notification templates, evidence capture, and post-incident review.

Does SAMA CSF cover third parties and cloud?

Yes. SAMA CSF includes a dedicated third-party cybersecurity domain and SAMA has issued additional cloud computing and outsourcing guidance. Waaqi tracks vendors, cloud providers, attestations, and outsourcing risk in the same control library.

How does Waaqi help with SAMA CSF compliance?

Waaqi pre-loads every SAMA CSF domain and subdomain, assigns owners, automates evidence collection and maturity scoring, manages the self-assessment lifecycle, runs incident reporting workflows, and produces SAMA-ready submission packages, turning CSF compliance into a continuous program.

SAMA CSF compliance: cybersecurity for Saudi financial institutions

The SAMA Cyber Security Framework is the binding cybersecurity standard for every financial institution regulated by the Saudi Central Bank. It applies to banks, insurance and reinsurance companies, finance companies, payment service providers, money exchangers, and credit bureaus operating in the Kingdom of Saudi Arabia.

The framework spans four primary domains, Cyber Security Leadership and Governance, Cyber Security Risk Management and Compliance, Cyber Security Operations and Technology, and Third Party Cyber Security, broken down into subdomains and individual controls. Each subdomain is assessed against a six-level maturity scale, with member organizations expected to operate at level 3 (Defined) or above across the board, and at level 4 (Managed) in critical areas.

SAMA reinforces the framework with periodic self-assessments, supervisory reviews, and strict incident notification requirements. Falling below expected maturity has supervisory and reputational consequences, and is frequently a blocker for new licenses, products, or cross-border activities.

Running SAMA CSF as a continuous program with Waaqi

SAMA CSF is too large and too dynamic to run as a once-a-year exercise. Waaqi consolidates the entire framework, all domains, subdomains, and controls, into a single operating model. Every control has a designated owner, an evidence requirement, a freshness rule, and a maturity scoring algorithm tied to the SAMA model.

Evidence is collected automatically through integrations with cloud, identity, endpoint, SIEM, ticketing, and HR systems, supplemented by recurring tasks for procedural evidence. Maturity scoring updates continuously, so the question "what is our SAMA CSF maturity today?" has a real answer rather than a stale dashboard.

Self-assessment cycles are managed end-to-end: scope confirmation, control walkthroughs, evidence review, exception handling, management sign-off, and submission package generation in the format SAMA expects.

SAMA CSF, NCA ECC, PCI DSS, and KSA PDPL in one program

Saudi financial institutions almost always face overlapping regimes: NCA ECC as the national baseline, SAMA CSF as the sector framework, PCI DSS for cardholder data, KSA PDPL for personal data, and frequently ISO 27001 for international partners. Running these as separate programs creates duplication, conflicting evidence, and audit fatigue.

Waaqi's cross-mapping engine ties every SAMA CSF control to its equivalents in NCA ECC, PCI DSS, ISO 27001 Annex A, NIST CSF, and KSA PDPL. A single control implementation and a single piece of evidence satisfy every overlapping requirement, and CISOs report posture across all frameworks from one source of truth.

SAMA reporting, incident notification, and supervisory readiness

SAMA expects timely, structured incident notifications with severity classification, business impact, customer impact, regulatory implications, and remediation status. Waaqi's incident workflow captures all of this with SAMA-aligned templates, countdown timers, evidence attachment, and post-incident learning records linked back to the affected controls.

For supervisory reviews, Waaqi's auditor workspace gives the assessor a read-only, CSF-scoped view of every control, its evidence, exception history, and risk treatment, making reviews shorter and dramatically more likely to confirm the maturity level the institution claims.

Operationalize SAMA CSF

See how Waaqi runs SAMA CSF as a continuous, measurable program.