Bridgewell Tek symbol
Free Assessment+966 54 859 1369
SAMA Framework

SAMA Cybersecurity Framework Compliance

Complete guidance for Saudi financial institutions to meet SAMA cybersecurity requirements in cloud environments.

Get SAMA Assessment

What is SAMA Cybersecurity Framework?

The Saudi Arabian Monetary Authority (SAMA) Cybersecurity Framework establishes mandatory security controls for all financial institutions operating in Saudi Arabia. It covers banks, insurance companies, financing companies, and other regulated entities.

Compliance Deadline

All SAMA-regulated entities must demonstrate compliance with the framework. Non-compliance can result in regulatory penalties and operational restrictions.

SAMA Framework Domains

Cybersecurity Governance

  • Cybersecurity Policy
  • Roles & Responsibilities
  • Risk Management Framework
  • Security Awareness

Cybersecurity Defense

  • Asset Management
  • Access Control
  • Cryptography
  • Network Security

Cybersecurity Resilience

  • Business Continuity
  • Disaster Recovery
  • Incident Response
  • Backup Management

Third-Party Security

  • Vendor Assessment
  • Contract Requirements
  • Ongoing Monitoring
  • Cloud Security

SAMA Cloud Security Requirements

When using cloud services, SAMA-regulated entities must implement additional controls to protect sensitive financial data and ensure regulatory compliance.

  • Data residency within Saudi Arabia
  • Encryption at rest and in transit
  • Multi-factor authentication
  • Security event logging and monitoring
  • Vulnerability management program
  • Penetration testing requirements
  • Incident response procedures
  • Business continuity planning

Our SAMA Services

  • Gap Assessment

    Identify compliance gaps in your current environment

  • Control Implementation

    Deploy required security controls on cloud infrastructure

  • Audit Preparation

    Documentation and evidence collection for regulators

What a SAMA CSF gap assessment looks like

A SAMA CSF assessment is not a checklist completed at the end of a cloud project. We review the control environment domain by domain, map each requirement to an owner and an evidence source, then record whether the control is designed, implemented, operating, or not applicable.

Cybersecurity governance

We inspect policy approval, accountability, risk acceptance, asset ownership, third-party oversight, and the cadence of management reporting. Evidence includes policies, committee minutes, risk registers, and supplier reviews.

Cybersecurity operations

We test identity lifecycle, privileged access, vulnerability management, logging, incident response, backup, disaster recovery, and secure configuration. Evidence includes access reviews, tickets, SIEM alerts, restore results, and incident exercises.

Cloud and data controls

For hosted workloads, we map tenancy, encryption, key custody, data residency, network segmentation, API security, and provider responsibilities to the SAMA CSF control intent and the bank’s internal risk appetite.

Remediation roadmap

Every gap receives a severity, accountable owner, target date, compensating control, and validation method. This turns the assessment into a sequenced remediation backlog rather than a report that becomes stale after the audit.

Achieve SAMA Compliance

Our experts will guide you through every step of SAMA compliance for your cloud environment.

Schedule Consultation