The SAMA Cyber Security Framework sets the cybersecurity expectations for banks, insurers, finance companies and other institutions under SAMA’s supervision, measured on a maturity scale. Institutions are expected to reach and sustain the required maturity across all domains — and to show the evidence.
We assess each control against its maturity criteria using documented evidence and interviews, not self-declaration. We then prioritize the gaps by risk and effort, help you close them, and assemble an evidence pack organized the way reviewers work through it.
Why it matters
How the engagement runs
- 1DiscoverScope, regulatory obligations and current posture.
- 2AssessEvidence-based gap and maturity assessment.
- 3PlanA prioritized, costed remediation roadmap.
- 4ImplementControls, policies and processes delivered.
- 5SustainMonitoring, reporting and re-assessment.
What you receive
- Maturity assessment report by domain and control
- Gap analysis and prioritized remediation roadmap
- Updated policies, standards and procedures
- Evidence pack and index
- Executive summary for the board
