An annual compliance sprint struggles to evidence a framework that assumes continuous operation. EIE’s operating recommendation is a sustainable quarterly cadence — here is the working calendar and checklist.
The Saudi Central Bank’s Cybersecurity Framework (SAMA CSF) is the regulatory baseline for banks, finance companies, insurers, payment service providers and other SAMA-regulated entities, according to the SAMA instrument and notification that apply to each institution. It is mandatory for the institutions SAMA applies it to, and compliance is assessed by the regulator. It is also — unlike much regulation — a genuinely well-structured framework: four domains, sub-domains beneath them, and a maturity model that scores how embedded each control is, not merely whether a document exists.
The institutions that struggle with SAMA CSF are rarely short of policies. They are short of cadence: the framework assumes continuous operation, and an annual scramble cannot fake twelve months of evidence. This article lays out the quarterly self-assessment rhythm we recommend, with the checklist itself.
Scope note: practical guidance, not legal or regulatory advice. Your SAMA classification, licence category and supervisory correspondence govern; verify current framework requirements with SAMA directly (sama.gov.sa).
The four domains, briefly
1. Cybersecurity Leadership and Governance — strategy, board oversight, policy framework, organisational structure, asset management. 2. Cybersecurity Risk Management and Compliance — risk assessment methodology, treatment, regulatory compliance, internal audit. 3. Cybersecurity Operations and Technology — the deep domain: identity and access, application and infrastructure security, network security, monitoring, incident management, business continuity. 4. Third-Party Cybersecurity — the domain that surprises institutions: evidenced due diligence on every vendor, contractor and supplier with access, including their sub-contractors.
Maturity is self-scored and then challenged by auditors. The honest institution scores conservatively: a control is not “defined” because a policy exists; it is defined when the policy describes what your teams actually do, and evidence proves it.
The quarterly cadence
Every quarter carries the same three monthly disciplines, plus one rotating deep-dive so that all four domains get a full review across the year:
| Month | Standing discipline | What it produces |
|---|---|---|
| Month 1 | Identity & access review — joiner/mover/leaver reconciliation, privileged-account inventory, dormant-account cleanup, MFA coverage check | Signed access-review record; PAM exceptions log |
| Month 2 | Vulnerability & patch posture — scan results triaged, patching performance vs SLA, exceptions risk-accepted in writing | Patch report vs SLA; risk-acceptance register |
| Month 3 | Incident readiness — one tabletop or technical exercise, call-tree verification, backup restore test | Exercise report with lessons; restore-test log |
| Rotating | Q1 Governance · Q2 Risk & Compliance · Q3 Operations & Technology · Q4 Third-Party | Full domain self-assessment with maturity scores refreshed |
The rhythm is deliberately light — each standing discipline is a working session, not a project — because the cadence that survives busy quarters is the one that fits inside them.
The self-assessment checklist
Grouped by domain. Every “yes” needs a dated artifact; a yes without evidence is a no.
Leadership & Governance
- Cybersecurity strategy current and board-approved within the last 12 months
- Policy set reviewed on schedule; ownership assigned by name, not by department
- Asset inventory reconciled this quarter (IT, OT, cloud, data assets)
- Cybersecurity roles staffed; Saudization and segregation-of-duties requirements met
- Board received a cybersecurity report this quarter
Risk Management & Compliance
- Risk register reviewed; new systems and projects risk-assessed before go-live
- Treatment plans on schedule; overdue items escalated
- Regulatory correspondence log current; prior audit findings tracked to closure
- Internal audit’s cybersecurity coverage plan on track
Operations & Technology
- Access reviews completed (Month 1 discipline) including privileged and remote access
- Patch SLAs met or exceptions risk-accepted (Month 2 discipline)
- Monitoring use-cases reviewed; alert-handling metrics within tolerance
- Incident-response exercise held (Month 3 discipline); lessons assigned owners
- Backup restore test passed; DR plan components validated this quarter
- Change management operating: emergency changes reviewed after the fact
Third-Party Cybersecurity
- Vendor register current, tiered by access and criticality
- Due-diligence assessments in date for all high-tier vendors
- Contracts carry cybersecurity clauses (right to audit, breach notification, data handling)
- Third-party access reviewed and time-bounded; standing vendor accounts justified
- Sub-contractor visibility confirmed for critical suppliers
Scoring honestly
For each sub-domain, score maturity on the framework’s scale and record the evidence reference beside the score. Two habits keep scores defensible under audit: never raise a score in the same quarter the evidence was created (embedding takes a cycle to prove), and record the delta story — auditors respond far better to “2 → 3 with these artifacts” than to a static wall of 4s that the first interview punctures.
The board one-pager
Quarterly reporting to the board works best as one page: overall maturity trend line; the three weakest sub-domains with owners and dates; incidents and near-misses this quarter with response performance; third-party risk movements; and one decision the board is actually being asked to make (budget, risk acceptance, or priority). Boards fund programmes they can follow.
The third-party domain — if you are the vendor
The framework’s third-party requirements flow down: SAMA-regulated institutions must evidence the cybersecurity of their suppliers, which means every IT integrator, contractor and service provider to a Saudi bank now needs its own audit pack — security policies, training records, incident-response capability, sub-contractor management, and in-Kingdom operational evidence. Elite Ideas Establishment maintains this evidence pack as a standing deliverable for regulated procurements, and builds the same discipline for organisations that supply the financial sector: for a vendor to a bank, the audit pack has become as decisive as the technical proposal.
Where EIE fits
EIE delivers the operational side of SAMA CSF for Saudi institutions and their suppliers: instrumenting the quarterly cadence, engineering the Operations & Technology controls (identity, segmentation, monitoring, backup and recovery), preparing the third-party audit pack, and running the exercises that turn written plans into scored maturity — from our Jeddah headquarters, with Kingdom-wide service coverage. Talk to our team →
Frequently asked questions
Who does the SAMA Cybersecurity Framework apply to?
SAMA-regulated member organisations — banks, finance companies, insurance companies, payment service providers and other licensed entities — as notified by SAMA. Applicability and control depth depend on the SAMA instrument and classification that apply to the institution.
How is SAMA CSF different from NCA’s controls?
SAMA CSF governs financial institutions under the central bank’s supervision; NCA’s ECC/CSCC cover the broader critical-sector landscape. Many financial-sector organisations must satisfy both, and the frameworks overlap enough that one well-run control programme can evidence the two.
Is a quarterly self-assessment actually required?
The framework requires periodic self-assessment and continuous operation of controls; the quarterly cadence in this article is the operating rhythm we recommend because it produces the year of evidence an audit expects — an annual exercise cannot.
What should a supplier to a Saudi bank prepare for?
An evidenced cybersecurity pack: policies, training records, access management for your own staff, incident-response capability, sub-contractor controls and breach-notification commitments — requested during onboarding and renewals under the Third-Party domain.
Sources and further reading: Saudi Central Bank — Cyber Security Framework (SAMA Rulebook); your institution’s SAMA supervisory correspondence governs specifics. The quarterly cadence in this article is EIE’s operating recommendation, not a SAMA-mandated frequency or a guaranteed audit result.
Related: Cybersecurity & Compliance services · NCA implementation guide · PDPL DSAR playbook