Zecurit
Compliance Guide

SAMA Cyber Security Framework Compliance

A Practical Guide for Banks, Fintechs, and Financial Institutions in Saudi Arabia

The Saudi Arabian Monetary Authority's Cyber Security Framework is mandatory for every SAMA-regulated entity, with a minimum maturity level of 3 required across all five domains. This guide maps the framework's endpoint-relevant controls to specific Zecurit Endpoint Manager capabilities, so IT and compliance teams can turn SAMA's requirements into day-to-day operational practice.

Published byZecurit
CategoryCompliance & Regulation
AudienceBank IT Teams, CISOs, Fintech Compliance Officers

Why SAMA's Framework Puts the Endpoint at the Centre of Compliance

At a Glance
  • Who is impacted: All SAMA-regulated entities including commercial banks, investment banks, insurance companies, finance companies, payment service providers, fintech startups, credit bureaus, and financial market infrastructure operators.
  • What the framework requires: A mandatory cybersecurity governance and control framework across five domains with over 100 controls, with a minimum Maturity Level 3 required across all domains for regulatory compliance.
  • Why endpoints matter: Domain 3 (Cyber Security Operations) explicitly mandates vulnerability management, patch management, endpoint protection, device control, configuration hardening, and access management as named controls.
  • How Zecurit helps: Patch management, vulnerability management, BitLocker encryption, device control, configuration management, access control, and audit-ready compliance reporting from a single agent and console.

The Saudi Arabian Monetary Authority, now operating as the Saudi Central Bank, issued its Cyber Security Framework in May 2017 under its mandate to enhance cybersecurity standards across Saudi Arabia's financial sector. The framework draws from internationally recognised standards including ISO/IEC 27001, NIST CSF, PCI-DSS, COBIT 5, and Basel III, adapting them specifically to the risk landscape of Saudi financial institutions operating within the Vision 2030 digital transformation context.

Unlike guidance frameworks that leave implementation to individual interpretation, SAMA's CSF is explicitly mandatory. Every SAMA-regulated entity must conduct an annual self-assessment against all five domains, submit results through SAMA's regulatory portal, and maintain evidence for independent validation during SAMA examinations. The minimum required maturity level is 3 (Defined) across every control, and SAMA conducts periodic inspection visits to verify the accuracy of self-assessments.

The Enforcement Reality: In 2023, a fintech application in Riyadh was fined and barred from onboarding new customers after failing to demonstrate an effective incident response system during a SAMA examination. IBM's 2024 Cost of a Data Breach Report identified the financial sector as one of the three most targeted industries globally, with the average breach cost exceeding USD 4.88 million. Saudi Arabia's rapid digital banking expansion makes these risks particularly acute, and SAMA's inspections are becoming increasingly stringent.

This guide maps the CSF's endpoint-relevant controls across all five domains to specific capabilities in Zecurit Endpoint Manager, helping IT and compliance teams build the evidence trail SAMA inspectors expect to see.

Key Terminology Under the SAMA CSF

Several terms recur across SAMA's framework and its assessment process:

  • Member Organisation (MO)

    Any financial institution regulated and supervised by SAMA, including banks, insurance companies, finance companies, payment service providers, and credit bureaus.

  • Maturity Level

    A six-level scale (0 to 5) measuring how effectively each control is implemented. Level 3 (Defined) is the regulatory minimum. Levels 4 and 5 reflect best-practice maturity.

  • Control Consideration

    A specific, testable security measure within a sub-domain. The framework contains over 100 control considerations across its five domains, each assessed against the maturity scale.

  • CISO

    Chief Information Security Officer: a mandatory appointment for most SAMA-regulated entities, with authority independent from IT operations and direct board reporting access.

  • Gap Assessment

    The initial comparison of an organisation's current cybersecurity posture against all CSF requirements, used to identify weaknesses and develop the compliance roadmap.

  • Annual Self-Assessment

    The mandatory yearly evaluation of cybersecurity maturity across all five domains, submitted to SAMA's regulatory portal and formally approved by the board or equivalent governance body.

Who Must Comply With the SAMA CSF?

The framework applies to every entity regulated and supervised by SAMA, regardless of size. This includes:

  • Commercial banks and investment banks licensed in Saudi Arabia
  • Insurance and reinsurance companies regulated by SAMA
  • Finance companies and microfinance institutions
  • Payment service providers and payment aggregators
  • Fintech startups licensed through the SAMA regulatory sandbox
  • Credit bureaus operating in the Kingdom
  • Exchange companies handling currency conversion
  • Financial market infrastructure operators
No Exemption for Size: The CSF applies to all SAMA-regulated entities regardless of their size, transaction volume, or technical maturity. A fintech startup with 20 employees is subject to the same framework obligations as a multinational commercial bank. Entities that process or transmit cardholder data must additionally implement PCI-DSS, and those using SWIFT services must implement the SWIFT Customer Security Controls Framework alongside the CSF.

The Six Maturity Levels

Unlike many frameworks with three or four maturity tiers, SAMA's CSF uses a six-level model (0 to 5) derived from the Capability Maturity Model Integration (CMMI). Every control consideration is independently assessed against this scale. The regulatory minimum is Level 3 across all controls.

Level 0

Non-Existent

No process exists. Complete lack of any recognisable approach.

Level 1

Ad Hoc

Processes exist but are informal, reactive, and undocumented.

Level 2

Repeatable

Basic processes exist but are applied inconsistently without formal standards.

Level 3

Defined

Standardised, documented, and approved. The regulatory minimum for all controls.

Required Minimum
Level 4

Managed

Processes are measured and controlled with quantitative targets.

Level 5

Optimising

Continuous improvement through innovation and proactive adaptation.

The Five Core Domains

The SAMA CSF organises all its control considerations across five core domains. All five domains are applicable to banks, while other financial institutions may have limited exclusions depending on their operational scope.

Domain 1 — 28 Controls

Cyber Security Leadership and Governance

Board oversight, CISO appointment, cybersecurity strategy, risk appetite framework, policy framework, and alignment with business objectives. Requires board-level accountability for all cybersecurity decisions.

Domain 2 — 38 Controls

Cyber Security Risk Management and Compliance

Cyber risk identification, assessment, treatment, and monitoring. Regulatory compliance tracking, third-party risk management, audit programme management, and information asset classification.

Domain 3 — Largest Domain

Cyber Security Operations and Technology

The most technically intensive domain: network security, endpoint protection, patch management, vulnerability management, access management, encryption, device control, and identity management. This is where most endpoint controls sit.

Domain 4 — 20 Controls

Third-Party Cyber Security

Vendor risk assessment, cloud computing security, outsourcing controls, SWIFT and payment system security, supply chain cybersecurity management, and contractual security obligations.

Domain 5 — 14 Controls

Cyber Security Resilience

Business continuity planning, disaster recovery, cyber incident response, threat intelligence sharing, forensics capability, and lessons-learned programme to improve resilience after incidents.

SAMA CSF Controls Mapped to Zecurit Endpoint Manager

The following sections translate the SAMA CSF's endpoint-relevant control considerations into the specific Zecurit Endpoint Manager capabilities that support Level 3 compliance and beyond.

Domain 2 — Risk Management

Information Asset Inventory and Classification

Sub-domain 3.2 — Information Asset Management

SAMA requires organisations to maintain a comprehensive, up-to-date inventory of all information assets, with each asset assigned an owner and classified by sensitivity and criticality. This inventory must feed directly into the annual risk assessment and SAMA self-assessment process.

Zecurit Endpoint Manager

Hardware Inventory automatically collects CPU, RAM, storage, peripheral, and system specification data from every enrolled device. Software Inventory discovers and tracks every installed application with real-time version data, and Asset Discovery auto-onboards new devices the moment they connect to the network. Geo-location tracking maintains physical accountability for assets across branches and remote locations.

Hardware Inventory Software Inventory Asset Discovery Geo Location Tracking
Domain 3 — Operations and Technology

Vulnerability Management

Sub-domain 3.3.9 — Vulnerability Management

SAMA explicitly mandates a formal vulnerability management process covering regular vulnerability assessments, risk-based prioritisation of identified vulnerabilities, timely remediation, and re-testing to confirm resolution. Vulnerability scan results must feed into the risk register and SAMA self-assessment evidence.

Zecurit Endpoint Manager

Vulnerability Management continuously maps installed software across every managed endpoint against the current CVE database, giving security teams a real-time, severity-ranked view of the organisation's vulnerability exposure. CVSS-based prioritisation surfaces critical vulnerabilities first, directly supporting SAMA's requirement for risk-based remediation. Vulnerability data integrates with the patch deployment workflow, enabling closed-loop tracking from detection through remediation.

Vulnerability Management CVSS Prioritisation Software Inventory
Domain 3 — Operations and Technology

Patch Management

Sub-domain 3.3.9 — Patch Management

SAMA requires a documented patch management process with defined SLAs for different patch criticalities, covering operating systems, applications, and firmware. Patch compliance evidence must be maintained and available for SAMA inspection, with quarterly reporting to the IT risk committee as a minimum expectation.

Zecurit Endpoint Manager

Patch Management automates the full patch lifecycle from detection through deployment to compliance verification. Critical patches are ranked by CVSS score and active exploit intelligence, with automated deployment during configured maintenance windows eliminating the manual coordination that creates SLA breaches. Real-Time Patch Status Monitoring gives IT risk committees a live compliance view, and Patch Compliance Reports produce the dated, per-device evidence SAMA inspectors expect to see.

Patch Management CVSS Prioritisation Patch Status Monitoring Patch Compliance Reports
Domain 3 — Operations and Technology

Data Protection and Encryption

Sub-domain 3.3.4 — Data and Information Protection

SAMA requires encryption of sensitive data at rest and in transit across all systems handling customer or financial data. Encryption coverage must be demonstrable, with encryption status verifiable for all assets in the information asset inventory.

Zecurit Endpoint Manager

BitLocker Management enforces drive encryption across every managed Windows endpoint from a central console, supporting TPM-only, TPM+PIN, and passphrase authentication modes. Recovery keys are backed up automatically, and BitLocker Compliance Reports identify any unprotected device across the fleet. This gives your CISO fleet-wide, examiner-ready evidence of encryption at rest, directly supporting SAMA's data protection control considerations.

BitLocker Management TPM Policy Management Recovery Key Backup BitLocker Compliance Reports
Domain 3 — Operations and Technology

Identity and Access Management

Sub-domain 3.3.2 — Identity and Access Management

SAMA mandates centralised identity and access management covering unique user identification, least-privilege access, privileged access management, separation of duties, regular access reviews, and comprehensive logging of all access events across critical systems.

Zecurit Endpoint Manager

Configuration Management's User and Group Management lets IT teams create, modify, and disable local user accounts remotely, enforce password policy, and audit all account changes from a central console. Remote Access sessions require explicit session confirmation from the end user and are governed by role-based access controls with full session logging. User Logon Reports record access patterns by account across the endpoint fleet, supporting regular access reviews and privileged access governance at SAMA's required maturity level.

User and Group Management Role-Based Access Session Confirmation and Audit User Logon Reports
Domain 3 — Operations and Technology

Endpoint Protection and Device Control

Sub-domain 3.3.3 — Endpoint Security

SAMA requires endpoint security solutions on all devices, with controls to prevent unauthorised connection of removable storage, restrict data exfiltration channels, and ensure antivirus and antimalware protection is operational and continuously monitored. SAMA's inspectors test these controls device by device.

Zecurit Endpoint Manager

Security Alerts notify IT teams instantly when antivirus or antimalware protection is disabled on any endpoint. Device Control enforces allow, block, or trusted-only policies for removable storage, Bluetooth, wireless adapters, and Windows Portable Devices, with BadUSB keystroke injection prevention. Policies are enforced even when endpoints are offline, and every connection attempt and blocked event is logged with a timestamp and user account for SAMA evidence.

Security Alerts Device Control USB/Removable Storage Policies Offline Policy Enforcement
Domain 3 — Operations and Technology

Secure Configuration and Hardening

Sub-domain 3.3.1 — Network Security; Sub-domain 3.3.3

SAMA requires security hardening of all system components based on industry best practices, with deviations from hardening standards documented and approved. Configuration baselines must be enforced and monitored for drift, with any unauthorised configuration changes detected and remediated promptly.

Zecurit Endpoint Manager

Configuration Management lets IT teams define named profiles bundling firewall rules, Windows Update policy, security hardening settings, and user and group configurations, then deploy them consistently across device groups. Hardware and software change alerts detect the moment any endpoint deviates from its approved baseline, enabling rapid remediation and maintaining the documented, consistently applied configuration standard SAMA's Level 3 maturity requires.

Configuration Management Centralised Profile Management Hardware/Software Change Alerts Firewall Configuration
Domain 3 — Operations and Technology

Cyber Security Event and Incident Management

Sub-domain 3.3.7 — Cyber Security Event Management

SAMA requires real-time monitoring and logging of all security-relevant events across the organisation's technology environment, with alerts reviewed and acted upon in a timely manner. Logs must be retained, protected from tampering, and available for SAMA examination and forensic investigation.

Zecurit Endpoint Manager

The Monitoring and Alerts module provides real-time notifications across security, hardware, software, disk, licence, and certificate events. Security Alerts flag disabled antivirus, disabled firewall, and BitLocker protection turning off the moment they happen. Device Control logs and User Logon Reports give incident response teams the forensic detail needed to scope and investigate security events promptly, directly supporting SAMA's event management maturity requirements.

Real-Time Monitoring and Alerts Security Alerts Certificate Alerts Audit Device Logs
Domain 3 — Operations and Technology

Software Control and Licence Management

Sub-domain 3.3.3 — Endpoint and Software Security

SAMA requires controls to prevent the installation and use of unauthorised software on organisation-owned devices, and to ensure software licence compliance. Unapproved or unlicensed software introduces security risk and creates regulatory exposure during SAMA examination.

Zecurit Endpoint Manager

Software Alerts notify IT teams instantly when prohibited or unauthorised software is installed on any managed endpoint. Software Licence Management monitors entitlements against actual installations to detect both over-installation and licence non-compliance. Software Deployment ensures approved applications are pushed through a controlled, auditable process, replacing ad-hoc installations that undermine software control posture.

Software Alerts Software Licence Management Software Deployment Prohibited Software Detection
Annual Self-Assessment Support

Audit-Ready Compliance Reporting for SAMA Examinations

Annual self-assessment; SAMA examination evidence

SAMA requires member organisations to conduct an annual self-assessment across all five domains, submit results through the SAMA regulatory portal, and maintain evidence for independent validation during examinations. The gap between an examiner's request and producing that evidence is exactly where Level 3 maturity is most frequently undermined.

Zecurit Endpoint Manager

Compliance and Reporting provides 100+ built-in report templates including pre-mapped templates for ISO 27001, PCI-DSS, HIPAA, GDPR, CIS, and NIST. Security Reports surface BitLocker gaps, firewall status, and antivirus health across all endpoints, and Scheduled Report Delivery emails these reports to stakeholders automatically, building the continuous compliance record SAMA's annual self-assessment process depends on.

100+ Compliance Reports Security Reports Patch Compliance Reports Scheduled Report Delivery

SAMA CSF Controls and Zecurit Endpoint Manager Capabilities

A consolidated reference mapping each SAMA CSF endpoint-relevant control to the relevant Zecurit features, useful for annual self-assessment preparation and SAMA examination evidence.

SAMA CSF Control Domain Zecurit Endpoint Manager Capability
Information Asset Inventory Domain 2 Hardware InventorySoftware InventoryAsset Discovery
Vulnerability Management Domain 3 Vulnerability ManagementCVSS Prioritisation
Patch Management Domain 3 Patch ManagementPatch Status MonitoringPatch Compliance Reports
Data Protection and Encryption Domain 3 BitLocker ManagementTPM Policy ManagementBitLocker Compliance Reports
Identity and Access Management Domain 3 User and Group ManagementRole-Based AccessUser Logon Reports
Endpoint Protection and Device Control Domain 3 Security AlertsDevice ControlUSB/Removable Storage Policies
Secure Configuration and Hardening Domain 3 Configuration ManagementCentralised Profile ManagementChange Alerts
Security Event and Incident Management Domain 3 Real-Time Monitoring and AlertsSecurity AlertsAudit Device Logs
Software Control and Licence Management Domain 3 Software AlertsSoftware Licence ManagementSoftware Deployment
Audit-Ready Annual Self-Assessment All Domains 100+ Compliance ReportsSecurity ReportsScheduled Report Delivery

SAMA Inspectors Test Maturity, Not Just Policy Documentation

The SAMA CSF's Level 3 maturity requirement means standardised, documented, and approved processes across all controls, not just a written policy sitting in a document management system. SAMA's examination visits verify that controls are actually operational, that logs exist and are reviewed, that patches are applied within defined SLAs, and that encryption coverage can be demonstrated device by device.

With Saudi Arabia's financial sector expanding rapidly through digital banking, fintech licensing, and Vision 2030 technology adoption, the attack surface is growing at the same pace as regulatory expectations. SAMA's inspections have become progressively more rigorous, and the enforcement actions following failed examinations are increasingly consequential.

Zecurit Endpoint Manager addresses the SAMA CSF's core endpoint-level control considerations from a single lightweight agent and unified console, giving bank and fintech IT teams the vulnerability management, patch management, encryption, device control, access governance, and compliance reporting that SAMA examiners expect to see, without assembling evidence from disconnected tools when an inspection arrives.

Zecurit

About Zecurit

Zecurit develops cloud-based IT management solutions designed for modern IT teams. The Zecurit platform helps organisations manage endpoints, track assets, enforce security policies, and securely support distributed workforces through centralised, easy-to-use tools.

To learn more about Zecurit Endpoint Manager and how it supports your SAMA Cyber Security Framework compliance programme, start a free 14-day trial or contact the Zecurit team.

Contact Zecurit