Parameter

What is SAMA CSF?

SAMA Cyber Security Framework

What the Saudi Central Bank's Cyber Security Framework requires of financial institutions, its maturity levels, and where testing fits.

01Introduction

Banks, insurers and finance companies regulated in Saudi Arabia must meet the central bank's cybersecurity framework, and they're assessed on how mature their controls are, not just whether they exist. See fintech.

02What is SAMA CSF?

The SAMA Cyber Security Framework is issued by the Saudi Central Bank (SAMA) for its regulated financial institutions. It is organized into four domains: leadership and governance, risk management and compliance, operations and technology, and third-party security.

Institutions are rated on a maturity scale from 0 to 5, with level 3 the expected minimum. The operations and technology domain includes vulnerability management and penetration testing. SAMA also publishes a separate framework for threat-led ethical red teaming of financial entities.

03How SAMA CSF works

Institutions work toward a target maturity level.

  1. 1.

    Self-assess

    Rate current maturity for each control against SAMA's scale.

  2. 2.

    Close gaps

    Formalize, implement and measure controls to reach at least level 3.

  3. 3.

    Test

    Run periodic penetration tests and vulnerability scans on critical systems.

  4. 4.

    Supervisory review

    SAMA reviews self-assessments and conducts its own examinations.

04Threats and risks

Financial institutions face a concentrated set of threats.

  • Fraud and account takeover

    Attacks on digital banking and payment flows.

  • API exposure

    Open banking and fintech APIs with access control flaws.

  • Third-party risk

    Outsourced and cloud providers holding customer data.

  • Supervisory findings

    Maturity below level 3 triggers regulatory attention.

05How Parameter helps

Parameter helps show that testing is defined, repeatable and measured, which is what maturity levels reward.

  • Continuous testing

    The pentesting agents test digital banking apps and APIs on every release.

  • Red team preparation

    Red team as a service surfaces attack paths before a formal exercise.

  • Measured remediation

    Findings, fixes and retests give the metrics a higher maturity level needs.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your SAMA CSF program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.