> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SAMA Cyber Security Framework

> Comply with the Saudi Central Bank's cybersecurity framework for financial institutions.

> Comply with the Saudi Central Bank's cybersecurity framework for financial institutions.

The Saudi Arabian Monetary Authority (now Saudi Central Bank, SAMA) Cyber Security Framework is a mandatory framework for financial institutions regulated by SAMA. It defines cybersecurity requirements across governance, risk management, operations, and third-party security to protect the Kingdom's financial sector.

<Note>
  The SAMA CSF is mandatory for banks, insurance companies, and other financial institutions regulated by the Saudi Central Bank.
</Note>

## Who needs SAMA Cyber Security Framework?

<CardGroup cols={2}>
  <Card title="Saudi financial institutions" icon="landmark">
    Banks, insurers, and finance companies regulated by SAMA.
  </Card>

  <Card title="Fintech and payment firms" icon="credit-card">
    Payment service providers and fintechs operating in Saudi Arabia.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="Cyber security governance" icon="gavel">
    Leadership oversight, strategy, and a defined cybersecurity organization.
  </Card>

  <Card title="Risk management" icon="triangle-exclamation">
    Identification and treatment of cybersecurity risks.
  </Card>

  <Card title="Operations & technology" icon="gears">
    Security operations, identity management, and infrastructure protection.
  </Card>

  <Card title="Third-party security" icon="handshake">
    Management of cybersecurity risk from vendors and partners.
  </Card>
</CardGroup>

## How DSALTA helps with SAMA Cyber Security Framework

<Steps>
  <Step title="Activate SAMA CSF">
    Select the SAMA framework from the Frameworks page. DSALTA maps its domains to controls.
  </Step>

  <Step title="Review mapped controls">
    Review governance, risk, and operations controls and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations to gather technical evidence.
  </Step>

  <Step title="Approve policies">
    Review and approve policies aligned with SAMA requirements.
  </Step>

  <Step title="Track maturity">
    Monitor your maturity level against the framework's expectations.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Who must comply with the SAMA CSF?" icon="circle-question">
    All financial institutions regulated by the Saudi Central Bank, including banks, insurers, and finance companies.
  </Accordion>

  <Accordion title="Is the framework maturity-based?" icon="chart-line">
    Yes. SAMA assesses institutions against maturity levels, expecting continuous improvement over time.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
