How to comply with the SAMA Cyber Security Framework: a practical guide

Anastasia Malysheva

Product Marketing Manager at Axidian

The SAMA Cyber Security Framework includes 249 controls, so it may seem complex at first.

Axidian analyzed the SAMA Framework and translated its requirements into a practical working model. In this guide, we explain how to approach SAMA cybersecurity compliance step by step, build a cybersecurity calendar, organize required documentation, and identify the technology needed to support compliance.

What is the SAMA Cyber Security Framework?

Over the years, the Saudi Arabian Monetary Authority (SAMA) has introduced regulations addressing cyber resilience, information technology governance, counter-fraud, data privacy, and other security areas. The main collection of cybersecurity controls used as a reference for audits is the SAMA Cyber Security Framework, also commonly referred to as the SAMA CSF.

The SAMA CSF contains 4 main domains, 32 subdomains, and 249 controls. Following the SAMA Framework goes beyond preparing for an audit. Its controls provide organizations with a structured approach to cybersecurity governance, risk management, operational security, technology, and third-party relationships. As a result, compliance work can also help organizations establish more consistent security practices across these areas.

Why SAMA cybersecurity compliance matters

Non-compliance can create consequences beyond additional cybersecurity risks. Depending on its severity, an organization may need to remediate missing controls, implement additional processes or technology, and demonstrate compliance again. That remediation can quickly become a major priority for cybersecurity and IT teams.

Non-compliance can also damage trust among customers and partners, particularly if weaknesses become public following an incident. More serious cases may affect operating licenses or authorizations and can lead to financial penalties or restrictions on certain activities.

consequences of non-compliance

This is why SAMA cybersecurity compliance should be treated as an ongoing process rather than a project that starts shortly before an audit. Organizations need controls that are implemented, documented, monitored, and regularly reviewed.

What does the SAMA cybersecurity maturity assessment expect?

The SAMA Cyber Security Framework also defines expectations around cybersecurity maturity. Member Organizations should operate at Cyber Security Maturity Level 3 or higher.

At Level 3, cybersecurity controls should already be defined, approved, and implemented. Organizations should also monitor compliance with their cybersecurity documentation and demonstrate that established processes are consistently followed.

SAMA cybersecurity maturity assessment

This is an important distinction when approaching a SAMA cybersecurity maturity assessment. Policies alone are not enough, and neither is purchasing a set of security tools. Processes, documentation, technology, and evidence need to work together as part of the same cybersecurity program.

How to approach SAMA compliance step by step

A practical cybersecurity strategy usually involves three components: people, processes, and technology. Every organization needs to build the right team and define internal responsibilities. Axidian therefore focused its SAMA compliance methodology primarily on the processes and technology that support those teams.

How to approach SAMA CSF

Based on our analysis of all 249 controls in the SAMA CSF, we recommend organizing the preparation process into five stages.

1. Assign responsibility for SAMA compliance

Start by assembling a compliance team or appointing a person responsible for coordinating the project. Someone needs to own the process, monitor progress, communicate with different teams, and make sure identified gaps are actually addressed.

Clear ownership also makes individual controls easier to manage. When every requirement has a responsible person or team, it becomes much easier to track implementation status, collect evidence, and understand where additional work is required.

2. Conduct a SAMA Framework gap analysis

Next, compare your current cybersecurity environment against the SAMA Framework. Identify which policies, processes, controls, and technologies are already in place and where gaps remain.

You can conduct this analysis directly against the SAMA CSF or use Axidian’s structured SAMA cybersecurity framework checklist. The important part is to turn 249 individual controls into a manageable view of your current state, priorities, and missing requirements.

3. Close the identified compliance gaps

Once the gaps are visible, prioritize remediation. Some controls may require a new policy, review process, or governance procedure, while others depend on specific technology.

Controls tied to mandatory security capabilities deserve particular attention. If a requirement depends on functions such as multi-factor authentication, privileged access management, or cryptographic key lifecycle management, documentation alone cannot demonstrate that the control is operating effectively.

4. Document controls and collect evidence

SAMA auditors expect evidence that controls are implemented and operating. Explaining that a process exists is different from demonstrating how it works, when it was last performed, who is responsible, and what evidence was produced.

Organizations should therefore maintain policies, logs, reports, review records, configuration evidence, and other relevant documentation. Keeping this information organized also reduces the amount of work required during subsequent audits.

5. Build a cybersecurity calendar

Finally, identify every requirement that needs recurring action and put it on a schedule. Reviews, assessments, penetration tests, reporting activities, board meetings, and other repeating tasks should have an owner, frequency, and next due date.

Once an activity is completed and documented, the next one can immediately be scheduled. This creates a cybersecurity calendar that supports continuous compliance instead of repeated last-minute audit preparation.

Inside the SAMA cybersecurity framework checklist

Working directly with all 249 controls can become difficult even for experienced teams. To make the Framework easier to use in day-to-day compliance work, Axidian developed a practical SAMA cybersecurity framework checklist based on three areas: recurring activities, documentation, and technology.

Organizations can use the checklists as a working foundation and adapt them to their own environment. Alternatively, teams can take the methodology and build their own compliance structure around the same three areas.

Cybersecurity calendar: 43 recurring controls

SAMA calendar checklist

43 controls in the SAMA CSF require periodic reviews, assessments, reporting, or other recurring activities. Axidian collected them in a single calendar-oriented checklist.

For each activity, teams can define its frequency, appoint a responsible person, record when the previous activity was completed, and plan the next one. Instead of searching through the full SAMA Framework every time, the team gets a working cybersecurity calendar that can be maintained throughout the year.

Documentation checklist: 36 controls

SAMA documentation checklist

The SAMA Cyber Security Framework contains 36 controls that require specific documentation. These include policies, procedures, assessments, governance records, and other evidence needed to demonstrate how security processes operate.

The documentation checklist allows teams to record the status of each document, add links, track the latest update, and assign ownership. This creates one place where the compliance team can quickly see what is complete, outdated, or still missing.

Technology checklist: 33 solution categories

SAMA software checklist

Axidian also analyzed which technology categories can support SAMA cybersecurity compliance. The resulting vendor-agnostic checklist contains 33 categories of cybersecurity solutions, divided into three tiers according to how important technology is for meeting the related controls.

The first tier consists of 16 must-have solutions. These relate to controls where auditors typically expect evidence produced directly by security technology rather than policies or manual procedures alone.

The second tier contains 12 recommended solutions. Some of these controls can be handled partly through manual processes, particularly in smaller organizations, but dedicated technology can make implementation and evidence collection considerably easier.

The remaining 5 categories are optional solutions. These support controls are driven mainly by governance and processes, where software can improve efficiency but is generally not the primary compliance mechanism.

This does not mean every organization needs to purchase all 33 categories. The final technology stack depends on existing infrastructure, risk, internal resources, and which processes the cybersecurity team wants to automate.

Which technologies are required for SAMA cybersecurity compliance?

Several categories in the technology checklist support controls that cannot realistically be addressed through policies alone. Axidian provides solutions for three of these areas: multi-factor authentication, privileged access management, and cryptographic key lifecycle management.

These tools can also support other SAMA controls beyond their primary compliance function. For organizations already investing in mandatory technologies, using their broader capabilities can reduce manual work and improve control visibility.

Multi-factor authentication (MFA) for sensitive, critical, privileged, and remote access

Domain 3, Subdomain 5, Control 4 of the SAMA Framework mandates multi-factor authentication for sensitive and critical systems and profiles, as well as privileged and remote access.

Axidian Access provides centralized access to corporate resources with MFA and single sign-on. Organizations can configure granular access policies according to user permissions, location, target resources, and required authentication methods.

The platform supports multiple authentication technologies and allows different methods to be combined for specific access scenarios. Centralized management also gives security teams a consistent way to control authentication across different corporate systems.

Axidian Privilege provides MFA specifically for privileged sessions, including local and remote access. MFA is built-in as a core capability, so organizations can combine privileged access control and additional authentication within the same solution.

Privileged access management

The SAMA Framework also requires organizations to maintain strong oversight of privileged access. This involves controlling administrative activity, managing privileged credentials, monitoring sessions, and retaining evidence that can be used during reviews and investigations.

Axidian Privilege centralizes privileged access management and defines who can connect to what resources, using which accounts and under which conditions. Privileged credentials can be stored and managed by PAM instead of being disclosed directly to administrators.

Privileged sessions can also be recorded and reviewed. These capabilities provide security teams with evidence of user activity and help demonstrate that privileged access is actively controlled throughout its lifecycle.

Cryptographic key lifecycle management

Another area covered by SAMA requirements is the secure management of cryptographic keys throughout their lifecycle. Organizations using personal digital certificates, smart cards, or cryptographic USB tokens need processes for issuing, tracking, renewing, and revoking these assets.

Axidian CertiFlow provides centralized management of Public Key Infrastructure, digital certificates, smart cards, and USB tokens. Teams can automate certificate issuance, track expiration dates, and revoke certificates when access should no longer be available.

Cryptographic operations are logged, which also supports compliance reviews and incident investigation. Reports can be filtered using information such as users, events, card types, dates, and services.

How Axidian solutions support additional SAMA Framework controls

Mandatory controls are only one part of the SAMA CSF. Once Identity and Access Management(IAM) and PAM technologies are already deployed, organizations can use their additional capabilities to support other controls and reduce the number of manual security operations.

The principle is simple: if an organization already needs a particular security technology for compliance, it makes sense to use its broader functionality wherever it supports the SAMA Framework.

Automating access provisioning with Axidian Access

Axidian Access can integrate with Identity Management systems to automate credential and access lifecycle processes. This helps organizations maintain more consistent access provisioning and reduces the number of manual steps involved when users join, move between roles, or require access to new applications.

For example, once a new employee is added to a source system such as HR and synchronization takes place, required access profiles can be provisioned according to the employee’s role. Password lifecycle processes can also be automated, reducing situations where credentials need to be created, changed, or entered manually.

Detecting unmanaged accounts with Axidian Privilege

Axidian Privilege includes Account Discovery, which performs recurring searches for accounts across connected resources and domains. Organizations can configure search frequency and apply different schedules to specific resource groups.

When the system discovers a new account, the event is recorded in the log and administrators can receive a notification. They can then investigate the account and decide whether it needs to be managed through PAM.

This supports continuous access governance. Instead of discovering forgotten or unmanaged accounts only during a SAMA audit, security teams can monitor changes throughout the year.

Get the SAMA compliance checklist and webinar

The SAMA Cyber Security Framework contains 249 controls, but teams do not need to treat them as one enormous compliance project. Breaking the Framework into documentation, recurring activities, and technology provides a clearer way to identify priorities and track progress.

The Axidian guide turns the SAMA CSF into three practical working checklists: 43 recurring cybersecurity activities, 36 documentation controls, and 33 technology categories, including 16 must-have, 12 recommended, and 5 optional solutions.

Watch the webinar and download the SAMA cybersecurity framework checklist using the button below.

About the Author

Anastasia Malysheva

Product Marketing Manager at Axidian

Anastasia translates complex cybersecurity solutions into actionable insights, drawing from her 8+ years of B2B marketing experience in international markets.