Get Demo
↑

SAMA CSF Domains and Maturity Levels (0–5) Explained

SAMA CSF v1.0 — 4 domains, 32 subdomains (3.1.1–3.4.3), maturity levels 0–5, and Level 3 minimum for Member Organizations.

Published: September 2026 Compliance · SAMA CSF 8–12 min read

The Saudi Central Bank Cyber Security Framework (SAMA CSF) v1.0 — as published in the official Rulebook — structures expectations across 4 domains and 32 subdomains. Each subdomain states a principle, objective, and control considerations. Member Organizations should operate at maturity Level 3 or higher on the 0–5 scale.

Related: SAMA hub · CSF compliance services · SAMA automation · ECC vs SAMA.

Structure: CLG 7 + CRMC 5 + COT 17 + TPC 3 = 32 subdomains. Maturity levels 0–5; target Level 3+. Per subdomain, SAMA states control considerations rather than a single invented “total controls” headline.

Maturity Levels 0–5

3.1 Cyber Security Leadership and Governance (7)

3.2 Cyber Security Risk Management and Compliance (5)

3.3 Cyber Security Operations and Technology (17)

3.4 Third Party Cyber Security (3)

How CyberSilo Helps

Raise Subdomain Maturity to Level 3+

Walk 32 subdomains with owners, control considerations, and SIEM proof where operations demand it.

CSF services · Automation guide · SIEM for SAMA

Frequently Asked Questions

How is SAMA CSF structured?

Four domains and 32 subdomains: Cyber Security Leadership and Governance (7), Cyber Security Risk Management and Compliance (5), Cyber Security Operations and Technology (17), and Third Party Cyber Security (3).

What maturity level is required?

Member Organizations should operate at maturity Level 3 or higher on the 0–5 scale.

Where is the official TOC?

SAMA Rulebook Cyber Security Framework v1.0 — subdomain sections 3.1.1 through 3.4.3.

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!