menu
close_24px

SAMA

SAMA is the Saudi Central Bank, formerly the Saudi Arabian Monetary Authority. It's Saudi Arabia's financial regulator, and the body behind the SAMA Cybersecurity Framework (SAMA CSF), the mandatory baseline every bank, insurer, and payment provider it supervises has to meet.

This page covers that cybersecurity framework specifically, not the central bank's monetary policy or currency functions.

What does SAMA stand for?

SAMA originally stood for the Saudi Arabian Monetary Authority.

King Salman approved renaming the institution to the Saudi Central Bank on November 24, 2020, though the bank kept "SAMA" as its working acronym, citing the name's historic and international recognition. Both names still appear across compliance documentation.

The SAMA Cybersecurity Framework

Published in May 2017, the SAMA CSF is mandatory for every entity SAMA regulates: commercial and investment banks, insurers, finance companies, payment service providers, and financial market infrastructure operators.

The framework draws on internationally recognized standards, including NIST CSF, ISO 27001, PCI-DSS, and COBIT, adapted specifically to the Saudi financial sector. Rather than a pass/fail checklist, it uses a maturity model with defined levels, and regulated entities are expected to reach at least Level 3 (Defined) and continue improving from there.

Why it matters for mobile

Saudi Arabia's banking and payments sector has moved to mobile faster than most.

A large share of the institutions SAMA regulates now deliver core services, transfers, payments, and account access primarily through a mobile app rather than a branch or a desktop site. That makes a mobile app one of the concrete places SAMA CSF maturity actually gets tested: authentication strength, session handling, and data protection on a device the bank doesn't control.

Where Appknox fits

Appknox maps mobile application security findings to relevant SAMA CSF control areas automatically, giving a regulated institution's compliance team evidence tied to a specific finding rather than a generic pass/fail scan result. This runs alongside Appknox's other regional and framework mappings (DORA, PCI-DSS, NIST CSF, and more), so a bank operating under multiple regulatory regimes gets one evidence trail instead of several.

See Appknox's compliance frameworks: Compliance at Appknox

Check out the full testing methodology: Appknox Automated Vulnerability Assessment.

Frequently asked questions

What does SAMA stand for?

SAMA originally stood for the Saudi Arabian Monetary Authority. The institution was renamed the Saudi Central Bank in November 2020, but kept SAMA as its working acronym.

Who does the SAMA Cybersecurity Framework apply to?

The SAMA Cybersecurity Framework applies to every entity SAMA regulates: banks, insurers, finance companies, payment service providers, and financial market infrastructure operators in Saudi Arabia.

Is the SAMA Cybersecurity Framework a checklist?

No, the SAMA Cybersecurity Framework isn't just a checklist. It uses a maturity model with defined levels rather than a simple pass/fail list, and regulated entities are expected to reach and maintain a minimum maturity level.

How does SAMA CSF relate to other frameworks?

SAMA CSF draws on NIST CSF, ISO 27001, PCI-DSS, and COBIT, adapted specifically for Saudi Arabia's financial sector.

Does Appknox support SAMA compliance?

Yes. Appknox automatically maps mobile application security findings to relevant SAMA CSF control areas, alongside its other regional and framework mappings.

Related: What is NIST CSF? | What is DORA? | Appknox Automated Vulnerability Assessment

By Aadarsh Anand, Security Researcher, Appknox Security Research Team

Appknox is an enterprise mobile application security testing platform. This page was written by Appknox's security research team based on direct experience mapping automated and manual testing findings to SAMA and other regional regulatory frameworks across BFSI clients.

This page was drafted with AI assistance and reviewed and verified by the Appknox security research team.