Waaqi maps your organization to every domain of the Saudi Central Bank's Cyber Security Framework: governance, risk management, cybersecurity controls, and third-party management, with deliberate, defensible records at every step.
Control library, gap assessment, risk register, and audit packs ship ready on day one.
Every SAMA-regulated bank, insurer, and fintech operating in Saudi Arabia must demonstrate compliance with the Cyber Security Framework's four domains and hit a minimum maturity level, validated through annual self-assessment and independent review. Falling short isn't just a technical gap: it's a regulatory exposure with direct consequences for licensing and operations.
Manual, spreadsheet-based tracking of SAMA CSF maturity scores across dozens of controls creates exactly the kind of audit fatigue and evidence gaps regulators flag first. Waaqi replaces that fragility with a governed workflow where every control, maturity score, and piece of evidence is deliberate, timestamped, and traceable to a named owner.
Framework-aligned scoring across every SAMA CSF control, Compliant, Partial, Gap, or N/A, with prioritized recommendations and automated policy generation, so you know your current maturity level before the regulator asks.
Map controls to SAMA CSF's four domains (governance, risk management, cybersecurity controls, third-party management) with the six-level maturity model, tracked against your target maturity and current-state evidence.
A risk register populated only through deliberate, user-initiated action: every entry intentional, timestamped, and defensible in a SAMA examination.
Centralize evidence, run control tests, and export regulator-ready audit packs mapped directly to SAMA CSF requirements, eliminating last-minute evidence scrambling.
SAMA-regulated institutions carry heavy outsourcing risk obligations. Waaqi's TPRM module governs the full vendor lifecycle, onboarding through offboarding, with tier-based risk registers and evidence tracking.
Deploy on Regional Cloud (KSA) for in-Kingdom data residency, or on-premises within your own data centre, to align with SAMA's sovereignty expectations.
Many SAMA-regulated entities also carry ISO 27001, NCA ECC, or KSA PDPL obligations. Waaqi's configurable control library lets you assess once and satisfy overlapping requirements across frameworks, reusing evidence and control tests instead of duplicating work.
For a detailed comparison of the two national frameworks, read our analysis: NCA ECC vs SAMA CSF: Key Differences for Saudi Organizations.
Start from a pre-configured regional workspace instead of building from scratch.
Full SAMA CSF control library, five-level maturity scoring, financial-services risk taxonomy, and steering committee reporting packs.
Open workspaceAll 114 ECC controls across 5 domains with Arabic-ready policy templates and NCA-ready dashboards.
Open workspacePre-mapped PDPL articles, ROPA and DPIA templates, DSR tracking, and breach notification playbooks.
Open workspaceBook a session with our team and we will show the SAMA CSF control library, gap assessment, and audit pack workflow running in a sandbox tenant.