SAMA Cybersecurity: Evidence, Identity and Access

TheSAMA Cyber Security Framework is the mandatory cybersecurity standard issued by the Saudi Central Bank for every bank, insurer, and financial market infrastructure provider it regulates. First published in 2017 and updated periodically since, it sets the baseline that SAMA-regulated entities must implement, measure, and continuously improve, not a one-time certification exercise.
A maturity model, not a checklist
The structural difference between SAMA's framework and control-based standards likeNCA's ECC is worth understanding on its own. Rather than a fixed list of pass or fail controls, SAMA measures organisations against a maturity scale across each domain of the framework. Every regulated entity must reach a minimum maturity level of three, described as "Defined," across all domains to be considered compliant. Reaching level three means governance, risk management, and operational controls are documented, consistently applied, and demonstrably owned at board level, not simply present in some form.
What Saudi financial institutions shouldprioritise
Financial institutions should treat identity evidence, third-party access and governance reporting as ongoing operational requirements. Policies are useful, but assessors and internal stakeholders also need reliable evidence that controls are applied consistently.
Weak access governance can create regulatory, operational and reputational exposure, particularly where privileged or third-party activity cannot be reconstructed clearly.
Why the third party assurance changematters most
Third-party assurance often creates substantial practical work for security teams.Financial institutions rely on contractors, outsourced IT support and vendor access to production systems, so they need to know who has privileged access, what those users do and how an auditable record can be produced when required.
The identity and access layer SAMA caresabout most
Acrossthe maturity domains, access control and privileged account management sit nearthe centre of what assessors examine. Credential-based attacks bypassingtraditional MFA, through phishing and MFA fatigue techniques now common acrossthe region, are exactly the kind of gap a maturity-based framework is designedto catch, because a "Defined" maturity level expects authenticationcontrols proven resistant to these methods, not simply present.
How The Kernel supports SAMA-regulatedorganisations
TheKernel supports Saudi financial institutions with identity, authentication and compliance expertise. CyberHeed includes SAMA among its supported frame works and helps teams keep evidence current, while Bitwarden strengthens enterprise password and secrets management. Together, these capabilities support a more consistent approach to access governance and audit readiness.
Thiswork sits within The Kernel's Strong Authentication capability, applied to the same financial services clients SAMA regulates directly.
Workingout where your current maturity level actually sits?
Talk to our team | Explore our vendor portfolio
Want these in your inbox?
We publish practical, vendor-neutral writing on identity, authentication, and security operations in the region. No spam, no hard sell.


