Cyber Resilience Fundamental Requirements
SAMA CRFR
What it is
SAMA's fundamental requirements for cyber resilience: the baseline capabilities regulated institutions are expected to have in place to withstand, respond to and recover from cyber incidents.
What it covers
- 01Cyber resilience governance and oversight
- 02Identification of critical services and assets
- 03Protection and detection capabilities
- 04Incident response and recovery
- 05Testing, exercising and continuous improvement
How we help
- Gap assessment against the requirements
- Prioritized remediation roadmap
- Resilience policies, plans and playbooks
- Exercise program and evidence pack for SAMA
In depth
The Cyber Resilience Fundamental Requirements (CRFR) set out what SAMA expects of the institutions it regulates to remain resilient to cyber incidents: understanding which services and assets are critical, protecting and monitoring them, responding effectively when incidents happen, and recovering within tolerances.
CRFR works alongside the SAMA Cyber Security Framework and the SAMA Business Continuity Management framework. We assess your current capability against the requirements, help you close the gaps, and build the evidence that demonstrates resilience to SAMA.
Other frameworks we work with
Ready to meet SAMA CRFR?
Tell us where you stand. We will show you the shortest path to what your regulator expects.
Built around the regulators you answer to
Ready to talk about your compliance?
Tell us where you stand. We will show you the shortest path to what your regulator expects.