Cyber Resilience Fundamental Requirements

SAMA CRFR

What it is

SAMA's fundamental requirements for cyber resilience: the baseline capabilities regulated institutions are expected to have in place to withstand, respond to and recover from cyber incidents.

What it covers

  1. 01Cyber resilience governance and oversight
  2. 02Identification of critical services and assets
  3. 03Protection and detection capabilities
  4. 04Incident response and recovery
  5. 05Testing, exercising and continuous improvement

How we help

  • Gap assessment against the requirements
  • Prioritized remediation roadmap
  • Resilience policies, plans and playbooks
  • Exercise program and evidence pack for SAMA

In depth

The Cyber Resilience Fundamental Requirements (CRFR) set out what SAMA expects of the institutions it regulates to remain resilient to cyber incidents: understanding which services and assets are critical, protecting and monitoring them, responding effectively when incidents happen, and recovering within tolerances.

CRFR works alongside the SAMA Cyber Security Framework and the SAMA Business Continuity Management framework. We assess your current capability against the requirements, help you close the gaps, and build the evidence that demonstrates resilience to SAMA.

Other frameworks we work with

Ready to meet SAMA CRFR?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Trust

Built around the regulators you answer to

SAMA
Saudi Central BankCSF · BCM
NCA
National Cybersecurity AuthorityECC · CCC · CRFR
SDAIA
Data & AI AuthorityPDPL
SWIFT
Customer Security ProgrammeCSCF
7regulatory frameworks

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment