NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
SAMA CSF compliance software

Bank in Saudi Arabia, aligned to the SAMA framework.

Venvera is SAMA CSF compliance software for the Saudi Central Bank’s Cyber Security Framework, keeping its domains, subdomains, controls and maturity levels audit-ready for your SAMA supervision, without rebuilding the evidence every review cycle.

GovernanceRisk and complianceOperationsThird-partyMaturity model

What is the SAMA CSF, and why can you not ignore it?

The SAMA Cyber Security Framework (v1.0, May 2017) is the Saudi Central Bank’s mandatory cyber security regime for every organisation it supervises - banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure. It is principle-based, structured around 4 domains, 32 subdomains and roughly 118 control considerations, and it is assessed against a 6-level maturity model from 0 Non-existent to 5 Adaptive. This is not a badge you choose to pursue: SAMA mandates it for its Member Organizations, your maturity is measured against a target of Level 3 or higher, and shortfalls surface in a supervisory review and draw supervisory action. Venvera keeps every subdomain scored, every control evidenced and the periodic self-assessment workbook ready to submit, so the next review is a report you export rather than a project you start.

 app.venvera.com
/ SAMA CSF · four domains, one audit-ready screen
/ SAMA CSF · four domains, one audit-ready screen
32
Subdomains across the four SAMA domains
~118
Control considerations tracked with evidence
Level 3
Minimum maturity SAMA expects you to hold
5 min
Gap assessment completion time
Maturity assessment

Know your SAMA maturity score before the reviewer does.

SAMA requires a periodic self-assessment scored on its 6-level maturity model, from 0 Non-existent to 5 Adaptive, with Member Organizations expected to hold Level 3 or higher. Venvera scores every subdomain against current versus target maturity, computes per-domain and overall scores in real time, and surfaces the gaps that pull you below target - so the annual spreadsheet sprint becomes a live dashboard.

  • 6-level maturity model scored per subdomain against your target
  • Per-subdomain current versus target tracking with auto-computed gap
  • Domain and overall maturity scores with trend over time
  • Evidence notes attached at the subdomain level
  • Sign-off workflow for the periodic self-assessment submission to SAMA
 app.venvera.com
/ MATURITY · every subdomain scored against Level 3
/ MATURITY · every subdomain scored against Level 3
Governance

Board governance evidenced the way SAMA expects.

Section 3.1 puts the board on the hook for cyber security and requires a committee chaired by an independent senior manager. Venvera tracks the committee charter, meeting cadence and agenda, the CISO appointment requirement including the Saudi-nationality consideration, and the full cyber security policy lifecycle with board endorsement - all evidenced for the SAMA reviewer.

  • Cyber security committee charter, members and meeting log
  • CISO role tracking: appointment, qualifications, no-objection from SAMA
  • Cyber security policy lifecycle with board endorsement workflow
  • Strategy alignment to the Banking Sector cyber security strategy
  • Awareness and role-specific training programmes tracked to completion
 app.venvera.com
/ GOVERNANCE · committee, CISO record and policy lifecycle
/ GOVERNANCE · committee, CISO record and policy lifecycle
Risk and compliance

Run risk, audit and regulatory change as one programme.

Section 3.2 asks for a structured risk process, ongoing monitoring of SAMA and Kingdom regulatory change, alignment to international standards, periodic effectiveness reviews and independent audits. Venvera couples its risk register, a regulatory updates feed and the audit log so the whole domain runs as a single programme instead of five disconnected efforts.

  • Cyber security risk register aligned to the SAMA risk methodology
  • Regulatory updates feed for SAMA circulars and Kingdom directives
  • Cross-mapping to ISO 27001:2022, NIST CSF 2.0 and PCI DSS v4
  • Periodic effectiveness reviews with KPI and KRI tracking
  • Internal and external audit scheduling, findings and remediation
 app.venvera.com
/ RISK · register, regulatory feed and audit trail in one
/ RISK · register, regulatory feed and audit trail in one
Operations and technology

Seventeen operations subdomains, one living control catalogue.

Section 3.3 is the operational heart of the framework - 17 subdomains from HR screening to vulnerability management, payment systems and electronic banking. Venvera renders each as a checklist of control considerations with status, owner and evidence link, and applies the bank versus non-bank exclusions for 3.3.12 and 3.3.13 automatically, so scope reflects your entity type without manual reasoning.

  • All 17 operations and technology subdomains tracked separately
  • Bank versus non-bank applicability applied automatically
  • Control owners with sign-off and evidence link per consideration
  • Native incident management wired to the incident subdomain
  • Vulnerability management cycle aligned to KRI-driven SLAs
 app.venvera.com
/ CONTROLS · 17 subdomains, owner and evidence on each
/ CONTROLS · 17 subdomains, owner and evidence on each
Third-party

Close the third-party gap SAMA reviewers cite most.

Section 3.4 - vendor contracts, outsourcing governance and cloud - is one of the most-cited gaps in SAMA assessments. Venvera wires its third-party module directly to the outsourcing subdomains: every supplier carries the SAMA-required clauses, questionnaire results and sub-outsourcing visibility, and cloud providers are tracked separately with data-localisation status and shared-responsibility evidence.

  • Vendor contract clauses tracked against 3.4.1 control considerations
  • Outsourcing governance with service criticality classification
  • Cloud provider register with a shared-responsibility matrix
  • Sub-outsourcing chain visibility with n-th party mapping
  • Data localisation evidence for KSA residency requirements
 app.venvera.com
/ THIRD-PARTY · clauses, questionnaires and cloud evidence
/ THIRD-PARTY · clauses, questionnaires and cloud evidence
Reporting

Generate the SAMA submission workbook from live data.

SAMA expects an actively engaged board and a clean self-assessment. Venvera produces the cyber security committee deck, the periodic self-assessment workbook for submission and the auditor evidence package, each pre-filled from your live data - no copy-paste between the GRC tool and Word the week before a review.

  • Cyber security committee board deck in PDF or DOCX
  • SAMA periodic self-assessment workbook export
  • Auditor evidence package per subdomain
  • KRI and KPI trend reports for the board
  • Risk-acceptance and waiver tracking aligned to SAMA Appendix D
 app.venvera.com
/ REPORTS · committee deck and submission workbook, ready
/ REPORTS · committee deck and submission workbook, ready
Why switch

The spreadsheet or Venvera.

Spreadsheets
Venvera
Maturity scoring
Excel spreadsheet, refreshed once a year
Live 6-level maturity per subdomain with trend
Control evidence
SharePoint folders by subdomain
Evidence linked at the control consideration
SAMA self-assessment
Manual workbook prep takes weeks
Workbook export from live data, one click
Bank vs non-bank scoping
Manual reasoning on 3.3.12 and 3.3.13
Applied automatically from your entity type
Audit trail
Email approvals, no version history
Append-only audit log per control
Board reporting
Slides assembled by hand each quarter
Board deck generated from live KPIs

SAMA CSF, answered.

Get SAMA-ready for supervision.

Start with a free gap report across the SAMA CSF domains - 10 minutes, no email to start.

Every paid plan: audit-ready in 90 days, or your money back

10 minutes · no email to start · no credit card · yours to keep