{"id":15164,"date":"2026-08-12T19:07:43","date_gmt":"2026-08-12T13:37:43","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15164"},"modified":"2026-08-12T19:07:45","modified_gmt":"2026-08-12T13:37:45","slug":"sama-csf-cybersecurity-framework","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/","title":{"rendered":"SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Compliance with a cybersecurity framework is more than having policies and security tools in place. Financial institutions also need to know whether controls are applied consistently, monitored adequately, and effective against the risks they address.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#SAMA_CSF_at_a_Glance\" >SAMA CSF at a Glance<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#What_Is_SAMA_CSF\" >What Is SAMA CSF?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#Book_a_Free_Demo_Call_with_Our_Expert\" >Book a Free Demo Call with Our Expert<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#To_Whom_Does_the_SAMA_Framework_Apply\" >To Whom Does the SAMA Framework Apply?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#The_Four_Domains_of_SAMA_CSF\" >The Four Domains of SAMA CSF<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#SAMA_CSF_Maturity_Levels_Explained\" >SAMA CSF Maturity Levels Explained<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#Why_Level_3_Matters\" >Why Level 3 Matters<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#How_to_Prepare_for_SAMA_CSF_Compliance\" >How to Prepare for SAMA CSF Compliance<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#The_Human_Layer_of_Cybersecurity\" >The Human Layer of Cybersecurity<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#Where_Threatcop_Fits\" >Where Threatcop Fits<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#What_Should_a_Good_SAMA_CSF_Program_Achieve\" >What Should a Good SAMA CSF Program Achieve?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#Final_Thoughts\" >Final Thoughts<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#FAQs\" >FAQs<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<p class=\"wp-block-paragraph\">This is where the SAMA CSF comes in. The SAMA Cybersecurity Framework provides organizations regulated by the Saudi Central Bank with a structured approach to managing cyber risk, implementing controls, measuring maturity, and enhancing their security. Rather than simply asking whether a control exists, it considers how the control works in practice. Falling short isn&#8217;t just a failed assessment; it leaves the underlying risk unmanaged and brings regulatory scrutiny and remediation timelines with it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"SAMA_CSF_at_a_Glance\"><\/span><strong>SAMA CSF at a Glance<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Key Area<\/strong><\/td><td><strong>Details<\/strong><\/td><\/tr><tr><td>Framework<\/td><td>SAMA Cybersecurity Framework<\/td><\/tr><tr><td>Issued by<\/td><td>Saudi Central Bank (SAMA)<\/td><\/tr><tr><td>Applies to<\/td><td>SAMA-regulated Member Organizations<\/td><\/tr><tr><td>Core domains<\/td><td>Four<\/td><\/tr><tr><td>Maturity levels<\/td><td>Level 0 to Level 5<\/td><\/tr><tr><td>Expected maturity<\/td><td>Level 3 or higher<\/td><\/tr><tr><td>Approach<\/td><td>Principle-based and risk-based<\/td><\/tr><tr><td>Focus<\/td><td>Governance, risk, operations, technology, and third parties<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Is_SAMA_CSF\"><\/span><strong>What Is SAMA CSF?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The SAMA CSF, also known as the Saudi Central Bank Cyber Security Framework or SAMA Cyber Security Framework, is the cybersecurity framework established by the Saudi Central Bank for regulated Member Organizations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It aims to establish a common cybersecurity approach, enhance cybersecurity maturity, and ensure proper management of cybersecurity risks. It is a principle-based approach, allowing organizations to apply its requirements in line with their context and risk profile.<\/p>\n\n\n\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>Threatcop \u2013 Book a Free Demo<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Outfit:wght@300;400;500;600;700&#038;display=swap\" rel=\"stylesheet\">\n<style>\n  .tc-wrap , .tc-wrap ::before, .tc-wrap ::after { box-sizing: border-box; margin: 0; padding: 0; }\n  .tc-wrap { font-family: 'Outfit', sans-serif; width: 100%; display: flex; justify-content: center; padding: 20px 10px; }\n  .tc-card { width: 100%; max-width: 820px; background: #fff; border-radius: 20px; overflow: hidden; box-shadow: 0 20px 60px rgba(24,57,148,0.13), 0 4px 16px rgba(24,57,148,0.07); display: flex; flex-direction: row; }\n  .tc-left { background: linear-gradient(160deg, #1e44b0 0%, #183994 40%, #0e2570 100%); width: 320px; flex-shrink: 0; padding: 40px 32px; display: flex; flex-direction: column; justify-content: center; position: relative; overflow: hidden; }\n  .tc-left::before { content: ''; position: absolute; inset: 0; background-image: radial-gradient(rgba(255,255,255,0.08) 1.5px, transparent 1.5px); background-size: 22px 22px; }\n  .tc-left::after { content: ''; position: absolute; bottom: -60px; right: -60px; width: 220px; height: 220px; background: radial-gradient(circle, rgba(99,179,255,0.22) 0%, transparent 65%); border-radius: 50%; pointer-events: none; }\n  .tc-panel-inner { position: relative; z-index: 1; }\n  .tc-badge { display: inline-flex !important; align-items: center !important; gap: 6px; background: rgba(255,255,255,0.1) !important; border: 1px solid rgba(255,255,255,0.18) !important; border-radius: 20px !important; padding: 4px 14px 4px 10px !important; font-size: 12.5px !important; font-weight: 600 !important; letter-spacing: .09em !important; text-transform: uppercase !important; color: rgba(255,255,255,0.85) !important; margin-bottom: 18px !important; font-family: 'Outfit', sans-serif !important; line-height: 1.4 !important; }\n  .tc-badge-dot { width: 6px; height: 6px; background: #5cd9a0; border-radius: 50%; box-shadow: 0 0 6px #5cd9a0; flex-shrink: 0; display: inline-block; }\n  .tc-left h1, .tc-left h2, .tc-left h3, .tc-left h4, .tc-left h5, .tc-left h6 { color: #ffffff !important; font-family: 'Outfit', sans-serif !important; font-size: 28px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.3px !important; margin: 0 !important; padding: 0 !important; background: none !important; -webkit-text-fill-color: #ffffff !important; }\n  .tc-left h2 em { font-style: normal !important; color: #7ec8ff !important; -webkit-text-fill-color: #7ec8ff !important; }\n  .tc-left p, .tc-left .tc-sub { color: rgba(255,255,255,0.78) !important; -webkit-text-fill-color: rgba(255,255,255,0.78) !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 300 !important; line-height: 1.65 !important; margin-top: 12px !important; background: none !important; }\n  .tc-right { flex: 1; padding: 32px 32px 28px; display: flex; flex-direction: column; justify-content: center; }\n  .tc-form-title { font-size: 13px !important; font-weight: 600 !important; letter-spacing: .12em; text-transform: uppercase; color: #8fa4cc !important; margin-bottom: 20px !important; display: flex !important; align-items: center !important; gap: 10px; font-family: 'Outfit', sans-serif !important; }\n  .tc-form-title::after { content: ''; flex: 1; height: 1px; background: #eef1fa; }\n  .tc-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n  .tc-field { display: flex; flex-direction: column; gap: 5px; }\n  .tc-field.full { grid-column: 1 \/ -1; }\n  .tc-field label { font-size: 13px !important; font-weight: 600 !important; color: #3a4f7a !important; letter-spacing: .04em; text-transform: uppercase; font-family: 'Outfit', sans-serif !important; display: block !important; }\n  .tc-input-wrap { position: relative; display: flex; align-items: center; }\n  .tc-input-wrap .tc-fi { position: absolute; right: 12px; width: 15px; height: 15px; stroke: #c0ccdf; stroke-width: 1.8; pointer-events: none; fill: none; }\n  .tc-wrap input[type=\"text\"], .tc-wrap input[type=\"email\"], .tc-wrap input[type=\"number\"] { width: 100% !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 34px 9px 13px !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 400 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; transition: border-color .2s, background .2s, box-shadow .2s; -moz-appearance: textfield; box-shadow: none !important; -webkit-text-fill-color: #1e2d50 !important; }\n  .tc-wrap input[type=\"number\"]::-webkit-inner-spin-button, .tc-wrap input[type=\"number\"]::-webkit-outer-spin-button { -webkit-appearance: none; }\n  .tc-wrap input::placeholder { color: #c0ccdf !important; -webkit-text-fill-color: #c0ccdf !important; opacity: 1; }\n  .tc-wrap input:focus { border-color: #183994 !important; background: #fff !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-phone-row { display: flex; gap: 8px; }\n  .tc-flag-select { position: relative; flex-shrink: 0; }\n  .tc-flag-select select { appearance: none !important; -webkit-appearance: none !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 26px 9px 12px !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 500 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; cursor: pointer; width: 100px !important; transition: border-color .2s, box-shadow .2s; }\n  .tc-flag-select select:focus { border-color: #183994 !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-flag-select::after { content: ''; position: absolute; right: 10px; top: 50%; transform: translateY(-50%); width: 0; height: 0; border-left: 4px solid transparent; border-right: 4px solid transparent; border-top: 5px solid #a0b0cc; pointer-events: none; }\n  .tc-phone-row .tc-input-wrap { flex: 1; }\n  .tc-btn-submit { width: 100% !important; margin-top: 18px !important; padding: 11px !important; background: #183994 !important; border: none !important; border-radius: 10px !important; color: #fff !important; -webkit-text-fill-color: #fff !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 600 !important; letter-spacing: .05em; cursor: pointer; display: flex !important; align-items: center !important; justify-content: center !important; gap: 9px; transition: background .2s, transform .15s, box-shadow .2s; box-shadow: 0 6px 24px rgba(24,57,148,0.28) !important; text-decoration: none !important; }\n  .tc-btn-submit:hover { background: #1d46b5 !important; transform: translateY(-1px); box-shadow: 0 10px 32px rgba(24,57,148,0.35) !important; color: #fff !important; }\n  .tc-btn-submit:active { transform: translateY(0); }\n  .tc-btn-submit svg { width: 16px; height: 16px; stroke: #fff; stroke-width: 2.2; fill: none; flex-shrink: 0; }\n  .tc-trust { margin-top: 10px !important; display: flex !important; align-items: center !important; justify-content: center !important; gap: 5px; font-size: 13px !important; color: #a0b0cc !important; font-family: 'Outfit', sans-serif !important; }\n  .tc-trust svg { width: 12px; height: 12px; stroke: #a0b0cc; stroke-width: 2; fill: none; flex-shrink: 0; }\n  @media (max-width: 680px) {\n    .tc-card { flex-direction: column !important; }\n    .tc-left { width: 100% !important; padding: 28px 24px 24px !important; }\n    .tc-right { padding: 24px 20px !important; }\n    .tc-grid { grid-template-columns: 1fr !important; }\n    .tc-field.full { grid-column: 1 !important; }\n  }\n<\/style>\n\n<div class=\"tc-wrap\">\n  <div class=\"tc-card\">\n    <div class=\"tc-left\">\n      <div class=\"tc-panel-inner\">\n        <div class=\"tc-badge\">\n          <span class=\"tc-badge-dot\"><\/span>\n          People Security Management\n        <\/div>\n        <h2><span class=\"ez-toc-section\" id=\"Book_a_Free_Demo_Call_with_Our_Expert\"><\/span>Book a Free<br><em>Demo Call<\/em><br>with Our Expert<span class=\"ez-toc-section-end\"><\/span><\/h2>\n        <p class=\"tc-sub\">Discover how Threatcop protects your workforce from modern cyber threats.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"tc-right\">\n      <div class=\"tc-form-title\">Your Details<\/div>\n      <form action=\"https:\/\/threatcop.com\/thankyou-blog\" method=\"get\" target=\"_blank\">\n        <input type=\"hidden\" name=\"BlogForm\" value=\"BlogForm\">\n        <input type=\"hidden\" name=\"PageSource\" id=\"tc-page-source\" value=\"\">\n        <div class=\"tc-grid\">\n          <div class=\"tc-field\">\n            <label>Full Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"FullName\" placeholder=\"Jane Smith\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"><\/circle><path d=\"M4 20c0-4 3.58-7 8-7s8 3 8 7\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field\">\n            <label>Company Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"CompanyName\" placeholder=\"Acme Corp\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"3\" width=\"18\" height=\"18\" rx=\"2\"><\/rect><path d=\"M9 3v18M3 9h6M3 15h6\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Corporate Email<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"email\" name=\"email\" placeholder=\"jane@yourcompany.com\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"2\" y=\"4\" width=\"20\" height=\"16\" rx=\"2\"><\/rect><polyline points=\"2,4 12,13 22,4\"><\/polyline><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Phone Number<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"number\" name=\"Phone\" placeholder=\"98765 43210\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 16.92v3a2 2 0 01-2.18 2A19.79 19.79 0 013.09 4.18 2 2 0 015.07 2h3a2 2 0 012 1.72c.13.96.36 1.9.71 2.81a2 2 0 01-.45 2.11L9.09 9.91a16 16 0 006 6l1.27-1.27a2 2 0 012.11-.45c.91.35 1.85.58 2.81.71A2 2 0 0122 16.92z\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n        <\/div>\n        <button type=\"submit\" class=\"tc-btn-submit\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 2L11 13M22 2L15 22l-4-9-9-4 20-7z\"><\/path><\/svg>\n          Book My Free Demo\n        <\/button>\n        <div class=\"tc-trust\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"11\" width=\"18\" height=\"11\" rx=\"2\"><\/rect><path d=\"M7 11V7a5 5 0 0110 0v4\"><\/path><\/svg>\n          Your data is safe &amp; never shared with third parties\n        <\/div>\n      <\/form>\n    <\/div>\n  <\/div>\n<\/div>\n<script>document.getElementById('tc-page-source').value = window.location.href;<\/script>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"To_Whom_Does_the_SAMA_Framework_Apply\"><\/span><strong>To Whom Does the SAMA Framework Apply?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The framework applies to Member Organizations regulated by SAMA, including banking, insurance and reinsurance, financing, credit bureaus, financial market infrastructure, and others. Specific requirements may vary depending on the organization&#8217;s regulatory scope.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity is not only an IT responsibility. An organization&#8217;s security posture can be affected by leadership, employees, business functions, technology teams, and third parties.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Four_Domains_of_SAMA_CSF\"><\/span><strong>The Four Domains of SAMA CSF<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The framework consists of four domains covering leadership and governance, risk management and compliance, operations and technology, and third-party security. These four domains break down further into 32 subdomains, each with its own specific control objectives.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\"><strong>1. Cyber Security Leadership and Governance<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This domain relates to cybersecurity strategy, policy, responsibility, oversight, and accountability. Good governance ensures that cybersecurity risks are presented to the necessary decision-makers and that security priorities have clear ownership.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\"><strong>2. Cyber Security Risk Management and Compliance<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations need to identify, assess, manage, and monitor cybersecurity risks by understanding key assets, threats, existing controls, and gaps.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Particular attention is given to connecting documentation with implementation:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Policy: What should be done<\/li>\n\n\n\n<li>Procedure: How it should be done<\/li>\n\n\n\n<li>Monitoring: How the organization knows it is being done<\/li>\n\n\n\n<li>Evidence: What proves it is being done<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\"><strong>3. Cybersecurity Operations and Technology<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This area relates to the technical and operational capabilities used to protect information assets and services. Depending on the requirements, this can range from access management and vulnerability management to security monitoring, incident management, and security architecture.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\"><strong>4. Third-Party Cyber Security<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Vendors and service providers with access to business processes, systems, and data can pose risks. Organizations should understand these risks, set appropriate security requirements, and monitor third-party security throughout the relationship.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"SAMA_CSF_Maturity_Levels_Explained\"><\/span><strong>SAMA CSF Maturity Levels Explained<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The maturity model illustrates the evolution of cybersecurity practices, from informal to measurable, continuously improving controls. It comprises six levels, ranging from Level 0 to Level 5, with SAMA stating that Member Organizations should operate at Level 3 or higher. A small number of subdomains, such as security operations center capabilities and event management, are expected to reach<a href=\"https:\/\/rulebook.sama.gov.sa\/en\/cyber-security-framework-maturity-level-4-requirements\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> Level 4<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Maturity Level<\/strong><\/td><td><strong>What It Means<\/strong><\/td><\/tr><tr><td>Level 0: Non-Existent<\/td><td>Appropriate cybersecurity controls are not in place.<\/td><\/tr><tr><td>Level 1: Ad-Hoc<\/td><td>Some security practices exist but are not consistent.<\/td><\/tr><tr><td>Level 2: Repeatable but Informal<\/td><td>Practices are repeatable but remain mostly informal.<\/td><\/tr><tr><td>Level 3: Defined<\/td><td>Controls are defined, approved, implemented, and monitored.<\/td><\/tr><tr><td>Level 4: Managed and Measurable<\/td><td>Control effectiveness is measured and evaluated.<\/td><\/tr><tr><td>Level 5: Adaptive<\/td><td>Cybersecurity is continuously improved and integrated with enterprise risk management.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Level_3_Matters\"><\/span><strong>Why Level 3 Matters<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Level 3 is a level that organizations should understand clearly. Controls need to be defined, approved, and implemented through appropriate processes, with compliance monitored.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For instance, an access-control policy alone is not a strong indicator of effective access management. Defined procedures, ownership, access reviews, monitoring, and supporting evidence are also required.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_Prepare_for_SAMA_CSF_Compliance\"><\/span><strong>How to Prepare for SAMA CSF Compliance<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There are five practical steps organizations can follow:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Take stock: <\/strong>Identify applicable requirements and compare them with existing controls, policies, procedures, technologies, evidence, and responsibilities.<\/li>\n\n\n\n<li><strong>Prioritize gaps: <\/strong>Consider asset criticality, business impact, threat exposure, regulatory importance, and existing safeguards when deciding which gaps to address first.<\/li>\n\n\n\n<li><strong>Set ownership: <\/strong>Make sure major controls and remediation activities have clearly defined owners.<\/li>\n\n\n\n<li><strong>Keep evidence: <\/strong>Integrate approvals, testing results, monitoring information, access reviews, logs, and assessments into normal security operations.<\/li>\n\n\n\n<li><strong>Assess effectiveness:<\/strong> Evaluate whether controls are working as intended and use the results to improve the program.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Human_Layer_of_Cybersecurity\"><\/span><strong>The Human Layer of Cybersecurity<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">That same policy-procedure-monitoring-evidence chain applies to people, not just systems, and it is often hardest to hold together here. Strong technical controls still depend on people. Employees interact with email, credentials, applications, customer information, and business systems every day. These interactions can be targeted through phishing, impersonation, and social engineering attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Employee security is therefore critical to overall cybersecurity maturity. Training completion alone does not indicate whether employees can detect and respond to threats. Organizations also need to understand risky behavior and determine whether their awareness efforts are effective.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_Threatcop_Fits\"><\/span><strong>Where Threatcop Fits<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Threatcop&#8217;s<a href=\"https:\/\/threatcop.com\/people-security-management\"> People Security Management<\/a> approach focuses on this human layer through simulated attacks, employee risk assessment, training, security awareness, and reporting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The AAPE process, Assess, Aware, Protect, and Empower, supports an ongoing approach to security awareness. Organizations can assess employee risk, test responses to realistic scenarios, provide targeted awareness, and track progress.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Should_a_Good_SAMA_CSF_Program_Achieve\"><\/span><strong>What Should a Good SAMA CSF Program Achieve?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An established program should provide security leaders with a clear understanding of their cybersecurity environment. They should know the applicable requirements, their current maturity level, critical gaps, gap owners, evidence of implementation, and whether controls, including the people who operate them, are working effectively.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The best programs bring together governance, risk, technology, controls, evidence, people, and continuous improvement. This turns compliance into a long-term security practice instead of merely an annual evaluation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Final_Thoughts\"><\/span><strong>Final Thoughts<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The SAMA CSF provides regulated financial institutions with a framework for managing cyber risk, implementing controls, measuring maturity, and enhancing their security posture.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Passing an assessment should not be the only goal. The objective should be to develop a cybersecurity program that can demonstrate what it protects, how its controls operate, whether they are effective, and what it needs to improve next.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your program can show policies and tools but not evidence that they are working, particularly on the human side, that is the gap to prioritize. Talk to Threatcop about running an AAPE assessment against your current SAMA CSF maturity baseline.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"FAQs\"><\/span><strong>FAQs<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n<style>#sp-ea-15167 .spcollapsing { height: 0; overflow: hidden; transition-property: height;transition-duration: 300ms;}#sp-ea-15167.sp-easy-accordion>.sp-ea-single {margin-bottom: 10px; border: 1px solid #e2e2e2; }#sp-ea-15167.sp-easy-accordion>.sp-ea-single>.ea-header a {color: #444;}#sp-ea-15167.sp-easy-accordion>.sp-ea-single>.sp-collapse>.ea-body {background: #fff; color: #444;}#sp-ea-15167.sp-easy-accordion>.sp-ea-single {background: #eee;}#sp-ea-15167.sp-easy-accordion>.sp-ea-single>.ea-header a .ea-expand-icon { float: left; color: #444;font-size: 16px;}<\/style><div id=\"sp_easy_accordion-1786540990\"><div id=\"sp-ea-15167\" class=\"sp-ea-one sp-easy-accordion\" data-ea-active=\"ea-click\" data-ea-mode=\"vertical\" data-preloader=\"\" data-scroll-active-item=\"\" data-offset-to-scroll=\"0\"><div class=\"ea-card ea-expand sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-151670\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse151670\" aria-controls=\"collapse151670\" href=\"#\" aria-expanded=\"true\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-minus\"><\/i> What is SAMA CSF?<\/a><\/h3><div class=\"sp-collapse spcollapse collapsed show\" id=\"collapse151670\" data-parent=\"#sp-ea-15167\" role=\"region\" aria-labelledby=\"ea-header-151670\"> <div class=\"ea-body\"><p><span style=\"font-weight: 400\">SAMA CSF is the SAMA Cybersecurity Framework issued by the Saudi Central Bank for Member Organizations. It provides cybersecurity principles, objectives, control considerations, and a maturity model for managing cybersecurity risk.<\/span><\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-151671\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse151671\" aria-controls=\"collapse151671\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> How many SAMA CSF domains are there? <\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse151671\" data-parent=\"#sp-ea-15167\" role=\"region\" aria-labelledby=\"ea-header-151671\"> <div class=\"ea-body\"><p><span style=\"font-weight: 400\">There are four domains, broken into 32 subdomains: Cyber Security Leadership and Governance, Cyber Security Risk Management and Compliance, Cyber Security Operations and Technology, and Third-Party Cyber Security.<\/span><\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-151672\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse151672\" aria-controls=\"collapse151672\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> What can be done to prepare for the SAMA Framework? <\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse151672\" data-parent=\"#sp-ea-15167\" role=\"region\" aria-labelledby=\"ea-header-151672\"> <div class=\"ea-body\"><p><span style=\"font-weight: 400\">Organizations should evaluate their existing posture, identify and prioritize gaps, establish control ownership, implement remediation, maintain control evidence, and evaluate control effectiveness.<\/span><\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-151673\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse151673\" aria-controls=\"collapse151673\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Why are employees important to security? <\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse151673\" data-parent=\"#sp-ea-15167\" role=\"region\" aria-labelledby=\"ea-header-151673\"> <div class=\"ea-body\"><p><span style=\"font-weight: 400\">Every day, employees interact with systems, information, credentials, and security controls. Security awareness, simulations, risk assessments, and targeted training can help organizations identify and reduce human-related cybersecurity risks.<\/span><\/p><\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Compliance with a cybersecurity framework is more than having policies and security tools in place. Financial institutions also need to know whether controls are applied consistently, monitored adequately, and effective against the risks they address. This is where the SAMA CSF comes in. The SAMA Cybersecurity Framework provides organizations regulated by the Saudi Central Bank [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":15170,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[42],"tags":[],"class_list":["post-15164","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-awareness"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework<\/title>\n<meta name=\"description\" content=\"SAMA CSF Guide: Understand the Saudi Central Bank&#039;s cybersecurity framework, domains, maturity levels, compliance requirements, and steps to improve cybersecurity maturity.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework\" \/>\n<meta property=\"og:description\" content=\"SAMA CSF Guide: Understand the Saudi Central Bank&#039;s cybersecurity framework, domains, maturity levels, compliance requirements, and steps to improve cybersecurity maturity.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-12T13:37:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-12T13:37:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/Panel-Banner-5-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Threatcop\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Threatcop\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/\"},\"author\":{\"name\":\"Threatcop\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/e4db27ffd37219d73fc6b40cc9d45cfa\"},\"headline\":\"SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework\",\"datePublished\":\"2026-08-12T13:37:43+00:00\",\"dateModified\":\"2026-08-12T13:37:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/\"},\"wordCount\":1132,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Panel-Banner-5-1.jpg\",\"articleSection\":[\"Cybersecurity Awareness\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/\",\"name\":\"SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Panel-Banner-5-1.jpg\",\"datePublished\":\"2026-08-12T13:37:43+00:00\",\"dateModified\":\"2026-08-12T13:37:45+00:00\",\"description\":\"SAMA CSF Guide: Understand the Saudi Central Bank's cybersecurity framework, domains, maturity levels, compliance requirements, and steps to improve cybersecurity maturity.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Panel-Banner-5-1.jpg\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Panel-Banner-5-1.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"SAMA CSF\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/sama-csf-cybersecurity-framework\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/e4db27ffd37219d73fc6b40cc9d45cfa\",\"name\":\"Threatcop\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/avatar_user_1_1696398433.jpeg\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/avatar_user_1_1696398433.jpeg\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/avatar_user_1_1696398433.jpeg\",\"caption\":\"Threatcop\"},\"sameAs\":[\"https:\\\/\\\/threatcop.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework","description":"SAMA CSF Guide: Understand the Saudi Central Bank's cybersecurity framework, domains, maturity levels, compliance requirements, and steps to improve cybersecurity maturity.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/","og_locale":"en_US","og_type":"article","og_title":"SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework","og_description":"SAMA CSF Guide: Understand the Saudi Central Bank's cybersecurity framework, domains, maturity levels, compliance requirements, and steps to improve cybersecurity maturity.","og_url":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-08-12T13:37:43+00:00","article_modified_time":"2026-08-12T13:37:45+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/Panel-Banner-5-1.jpg","type":"image\/jpeg"}],"author":"Threatcop","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Threatcop","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/"},"author":{"name":"Threatcop","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/e4db27ffd37219d73fc6b40cc9d45cfa"},"headline":"SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework","datePublished":"2026-08-12T13:37:43+00:00","dateModified":"2026-08-12T13:37:45+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/"},"wordCount":1132,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/Panel-Banner-5-1.jpg","articleSection":["Cybersecurity Awareness"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/","url":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/","name":"SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/Panel-Banner-5-1.jpg","datePublished":"2026-08-12T13:37:43+00:00","dateModified":"2026-08-12T13:37:45+00:00","description":"SAMA CSF Guide: Understand the Saudi Central Bank's cybersecurity framework, domains, maturity levels, compliance requirements, and steps to improve cybersecurity maturity.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/Panel-Banner-5-1.jpg","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/Panel-Banner-5-1.jpg","width":1920,"height":1080,"caption":"SAMA CSF"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/sama-csf-cybersecurity-framework\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"SAMA CSF: Complete Guide to the SAMA Cybersecurity Framework"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/07\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/07\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/e4db27ffd37219d73fc6b40cc9d45cfa","name":"Threatcop","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2023\/10\/avatar_user_1_1696398433.jpeg","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2023\/10\/avatar_user_1_1696398433.jpeg","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2023\/10\/avatar_user_1_1696398433.jpeg","caption":"Threatcop"},"sameAs":["https:\/\/threatcop.com"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15164","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15164"}],"version-history":[{"count":4,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15164\/revisions"}],"predecessor-version":[{"id":15169,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15164\/revisions\/15169"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15170"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}