GCC compliance

SAMA CSF maturity levels: what level 3 means and how to reach it

The Saudi Central Bank's Cyber Security Framework rates every control area from 0 to 5 and expects at least level 3. Here is what each level means and how to prove it.

Short answer

SAMA CSF maturity levels rate each control area of the Saudi Central Bank's Cyber Security Framework from 0 to 5. SAMA expects member organisations to reach at least level 3, structured and formalised, where controls are documented, approved, communicated and consistently applied. Levels 4 and 5 add measurement and continuous improvement.

Key takeaways

  • The scale runs from 0 (non-existent) to 5 (adaptive).
  • Level 3, structured and formalised, is the minimum SAMA expects.
  • Evidence must show controls are applied consistently, not just written down.
  • Rate each control area separately; one weak area pulls the programme below level 3.

The six levels

LevelNameWhat it looks like
0Non-existentNo documented or applied control
1Ad hocApplied inconsistently and informally
2Repeatable but informalApplied repeatedly but not documented or approved
3Structured and formalisedDocumented, approved, communicated and consistently applied
4Managed and measurableEffectiveness measured and reviewed
5AdaptiveContinuously improved based on measurement and threats

Why level 3 is the line

SAMA expects member organisations to operate at maturity level 3 or higher. At level 3 a control is not only written into policy but approved by the right authority, communicated to the people who run it and applied the same way every time. Assessors look for that consistency in records, not in the policy text alone.

Evidence for each level

For level 3, keep the approved policy or procedure, proof it was communicated, and operating records over time, such as access reviews, change tickets or incident logs. For level 4, add metrics with targets and management review of those metrics. For level 5, show how measurements and threat intelligence changed the control.

Checklist

Reaching level 3 across the framework

0 of 5 done

SAMA CSF applies to SAMA-regulated institutions; NCA ECC can apply as well where an institution is in NCA's scope, and most evidence overlaps.

Put this into practice on QULDEX

Frequently asked questions

What maturity level does SAMA require?

SAMA expects member organisations to reach at least level 3, structured and formalised, across the framework.

What is the difference between SAMA maturity level 2 and level 3?

At level 2 a control is repeated but informal. At level 3 it is documented, approved, communicated and applied consistently, with records to prove it.

Does each control area need its own maturity rating?

Yes. Rate each control area separately; areas below level 3 are the gaps to close.

Sources

  1. Cyber Security Framework, version 1.0, Saudi Central Bank (SAMA)
  2. SAMA Rules on Outsourcing, Saudi Central Bank (SAMA)
  3. National Cybersecurity Authority: regulatory documents, NCA