Venvera is SAMA CSF compliance software for the Saudi Central Bank’s Cyber Security Framework, keeping its domains, subdomains, controls and maturity levels audit-ready for your SAMA supervision, without rebuilding the evidence every review cycle.
The SAMA Cyber Security Framework (v1.0, May 2017) is the Saudi Central Bank’s mandatory cyber security regime for every organisation it supervises - banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure. It is principle-based, structured around 4 domains, 32 subdomains and roughly 118 control considerations, and it is assessed against a 6-level maturity model from 0 Non-existent to 5 Adaptive. This is not a badge you choose to pursue: SAMA mandates it for its Member Organizations, your maturity is measured against a target of Level 3 or higher, and shortfalls surface in a supervisory review and draw supervisory action. Venvera keeps every subdomain scored, every control evidenced and the periodic self-assessment workbook ready to submit, so the next review is a report you export rather than a project you start.

SAMA requires a periodic self-assessment scored on its 6-level maturity model, from 0 Non-existent to 5 Adaptive, with Member Organizations expected to hold Level 3 or higher. Venvera scores every subdomain against current versus target maturity, computes per-domain and overall scores in real time, and surfaces the gaps that pull you below target - so the annual spreadsheet sprint becomes a live dashboard.

Section 3.1 puts the board on the hook for cyber security and requires a committee chaired by an independent senior manager. Venvera tracks the committee charter, meeting cadence and agenda, the CISO appointment requirement including the Saudi-nationality consideration, and the full cyber security policy lifecycle with board endorsement - all evidenced for the SAMA reviewer.

Section 3.2 asks for a structured risk process, ongoing monitoring of SAMA and Kingdom regulatory change, alignment to international standards, periodic effectiveness reviews and independent audits. Venvera couples its risk register, a regulatory updates feed and the audit log so the whole domain runs as a single programme instead of five disconnected efforts.

Section 3.3 is the operational heart of the framework - 17 subdomains from HR screening to vulnerability management, payment systems and electronic banking. Venvera renders each as a checklist of control considerations with status, owner and evidence link, and applies the bank versus non-bank exclusions for 3.3.12 and 3.3.13 automatically, so scope reflects your entity type without manual reasoning.

Section 3.4 - vendor contracts, outsourcing governance and cloud - is one of the most-cited gaps in SAMA assessments. Venvera wires its third-party module directly to the outsourcing subdomains: every supplier carries the SAMA-required clauses, questionnaire results and sub-outsourcing visibility, and cloud providers are tracked separately with data-localisation status and shared-responsibility evidence.

SAMA expects an actively engaged board and a clean self-assessment. Venvera produces the cyber security committee deck, the periodic self-assessment workbook for submission and the auditor evidence package, each pre-filled from your live data - no copy-paste between the GRC tool and Word the week before a review.

Start with a free gap report across the SAMA CSF domains - 10 minutes, no email to start.
✓ Every paid plan: audit-ready in 90 days, or your money back
10 minutes · no email to start · no credit card · yours to keep