Short answer
SAMA CSF maturity levels rate each control area of the Saudi Central Bank's Cyber Security Framework from 0 to 5. SAMA expects member organisations to reach at least level 3, structured and formalised, where controls are documented, approved, communicated and consistently applied. Levels 4 and 5 add measurement and continuous improvement.
Key takeaways
- The scale runs from 0 (non-existent) to 5 (adaptive).
- Level 3, structured and formalised, is the minimum SAMA expects.
- Evidence must show controls are applied consistently, not just written down.
- Rate each control area separately; one weak area pulls the programme below level 3.
The six levels
| Level | Name | What it looks like |
|---|---|---|
| 0 | Non-existent | No documented or applied control |
| 1 | Ad hoc | Applied inconsistently and informally |
| 2 | Repeatable but informal | Applied repeatedly but not documented or approved |
| 3 | Structured and formalised | Documented, approved, communicated and consistently applied |
| 4 | Managed and measurable | Effectiveness measured and reviewed |
| 5 | Adaptive | Continuously improved based on measurement and threats |
Why level 3 is the line
SAMA expects member organisations to operate at maturity level 3 or higher. At level 3 a control is not only written into policy but approved by the right authority, communicated to the people who run it and applied the same way every time. Assessors look for that consistency in records, not in the policy text alone.
Evidence for each level
For level 3, keep the approved policy or procedure, proof it was communicated, and operating records over time, such as access reviews, change tickets or incident logs. For level 4, add metrics with targets and management review of those metrics. For level 5, show how measurements and threat intelligence changed the control.
Checklist
Reaching level 3 across the framework
0 of 5 done
SAMA CSF applies to SAMA-regulated institutions; NCA ECC can apply as well where an institution is in NCA's scope, and most evidence overlaps.
Put this into practice on QULDEX
Frequently asked questions
What maturity level does SAMA require?
SAMA expects member organisations to reach at least level 3, structured and formalised, across the framework.
What is the difference between SAMA maturity level 2 and level 3?
At level 2 a control is repeated but informal. At level 3 it is documented, approved, communicated and applied consistently, with records to prove it.
Does each control area need its own maturity rating?
Yes. Rate each control area separately; areas below level 3 are the gaps to close.
Sources
- Cyber Security Framework, version 1.0, Saudi Central Bank (SAMA)
- SAMA Rules on Outsourcing, Saudi Central Bank (SAMA)
- National Cybersecurity Authority: regulatory documents, NCA