Saudi Central Bank Cyber Security Framework

SAMA CSF Compliance, Built for Continuous Audit Readiness

Waaqi maps your organization to every domain of the Saudi Central Bank's Cyber Security Framework: governance, risk management, cybersecurity controls, and third-party management, with deliberate, defensible records at every step.

Framework at a glancePre-loaded
Framework domains
4
Control requirements
100+
Maturity scale
0 to 4
Minimum target level
3

Control library, gap assessment, risk register, and audit packs ship ready on day one.

01Context

Why SAMA CSF Matters

Every SAMA-regulated bank, insurer, and fintech operating in Saudi Arabia must demonstrate compliance with the Cyber Security Framework's four domains and hit a minimum maturity level, validated through annual self-assessment and independent review. Falling short isn't just a technical gap: it's a regulatory exposure with direct consequences for licensing and operations.

Manual, spreadsheet-based tracking of SAMA CSF maturity scores across dozens of controls creates exactly the kind of audit fatigue and evidence gaps regulators flag first. Waaqi replaces that fragility with a governed workflow where every control, maturity score, and piece of evidence is deliberate, timestamped, and traceable to a named owner.

02Inside Waaqi

How Waaqi Supports SAMA CSF

01

Gap Assessment

Framework-aligned scoring across every SAMA CSF control, Compliant, Partial, Gap, or N/A, with prioritized recommendations and automated policy generation, so you know your current maturity level before the regulator asks.

02

Control Mapping and Maturity Scoring

Map controls to SAMA CSF's four domains (governance, risk management, cybersecurity controls, third-party management) with the six-level maturity model, tracked against your target maturity and current-state evidence.

03

Risk Register

A risk register populated only through deliberate, user-initiated action: every entry intentional, timestamped, and defensible in a SAMA examination.

04

Audit Centre

Centralize evidence, run control tests, and export regulator-ready audit packs mapped directly to SAMA CSF requirements, eliminating last-minute evidence scrambling.

05

Third-Party Risk Management

SAMA-regulated institutions carry heavy outsourcing risk obligations. Waaqi's TPRM module governs the full vendor lifecycle, onboarding through offboarding, with tier-based risk registers and evidence tracking.

06

Data Residency

Deploy on Regional Cloud (KSA) for in-Kingdom data residency, or on-premises within your own data centre, to align with SAMA's sovereignty expectations.

03Efficiency

Multi-Framework Efficiency

Many SAMA-regulated entities also carry ISO 27001, NCA ECC, or KSA PDPL obligations. Waaqi's configurable control library lets you assess once and satisfy overlapping requirements across frameworks, reusing evidence and control tests instead of duplicating work.

For a detailed comparison of the two national frameworks, read our analysis: NCA ECC vs SAMA CSF: Key Differences for Saudi Organizations.

05FAQ

Questions we get asked

All organizations regulated by the Saudi Central Bank: banks, insurance companies, financing companies, credit bureaus, and payment service providers operating in Saudi Arabia.

SAMA mandates a minimum maturity level of 3 across all domains, assessed annually through self-assessment and validated through independent review. Waaqi tracks current maturity scores against your target level continuously, so annual submissions reflect your actual posture.

Yes. Waaqi maps SAMA CSF controls to ISO 27001, NIST CSF, and NCA ECC equivalents, so a single implementation generates compliance evidence across multiple frameworks simultaneously.

Waaqi's Policy Generation Engine produces SAMA-aligned policy templates in both Arabic and English, formatted for regulatory submission and board approval.

See your SAMA CSF maturity scoring in a live walkthrough

Book a session with our team and we will show the SAMA CSF control library, gap assessment, and audit pack workflow running in a sandbox tenant.

Request a demo