The Saudi Central Bank's Cyber Security Framework places penetration testing in control 3.2.4 "Cyber Security Review," which states that customer and internet-facing services should be subject to annual review and penetration tests — not, as is often assumed, in the Vulnerability Management control (3.3.17). Red teaming is governed by a separate SAMA document, the Financial Entities Ethical Red-Teaming (FEER) Framework, which requires intelligence-led adversarial testing of every SAMA-regulated member organization at least once every three years. The CSF is measured on a six-level maturity model (0–5), and member organizations must reach level 3 or higher. Scope covers banks, insurers and reinsurers, financing companies, credit bureaus and the financial market infrastructure. SAMA operates in parallel with the NCA ECC, and most banks map controls once to satisfy both.
// 01 Which SAMA CSF control requires penetration testing?
Penetration testing sits in control 3.2.4 "Cyber Security Review," within Domain 3.2, "Cyber Security Risk Management and Compliance." This placement surprises people who expect to find it under vulnerability management — but in the SAMA framework, penetration testing is framed as an assurance activity that validates whether controls actually work, which is why it lives in the review domain rather than in operations.
The control's principle is that "the cyber security status of the Member Organization's information assets should be subject to periodic cyber security review," with the objective of ascertaining "whether the cyber security controls are securely designed and implemented, and the effectiveness of these controls is being monitored." The specific penetration testing consideration is explicit: "Customer and internet facing services should be subject to annual review and penetration tests." Results are recorded, reported to the business owner, and subject to follow-up reviews confirming that issues have been addressed and critical risks treated.
Note the frequency wording. Where the NCA ECC uses the deliberately open word "periodically," SAMA is specific: annual, for customer and internet-facing services. If you operate under both regimes, the SAMA annual cadence is the stricter, controlling number for your public-facing estate.
// 02 How is penetration testing different from vulnerability and threat management?
The SAMA CSF keeps three related activities in three distinct controls, and assessors expect you to run all three — not to treat a vulnerability scan as if it satisfied the penetration testing obligation. Conflating them is the most common SAMA cyber-review finding we see.
| Activity | Control | What it requires | Cadence |
|---|---|---|---|
| Penetration testing | 3.2.4 Cyber Security Review | Adversarial validation of customer/internet-facing services | Annual |
| Vulnerability management | 3.3.17 Vulnerability Management | Process to identify and mitigate application & infrastructure vulnerabilities; classification and mitigation timelines; patch management | Risk-based scanning |
| Threat management | 3.3.16 Threat Management | Threat-intelligence process to identify, assess and understand cyber threats | Continuous |
| Ethical red teaming | FEER (separate framework) | Intelligence-led simulation of real, advanced attacks against live systems | At least every 3 years |
The Vulnerability Management control (3.3.17) requires the organization to "define, approve and implement a vulnerability management process for the identification and mitigation of application and infrastructural vulnerabilities," with a risk-based scan frequency — it says nothing about penetration testing, and its cadence is not annual. So the honest reading is: continuous, risk-based scanning under 3.3.17; annual adversarial penetration testing under 3.2.4; threat intelligence under 3.3.16; and periodic red teaming under FEER. Four activities, four homes.
// 03 Does SAMA require red teaming?
Yes — under a dedicated framework separate from the CSF. In 2019 SAMA issued the Financial Entities Ethical Red-Teaming Framework, commonly abbreviated FEER, its intelligence-led adversarial-simulation regime in the same family as the Bank of England's CBEST and the European TIBER-EU. Where the CSF's 3.2.4 penetration testing validates whether controls are correctly built, FEER tests something harder: whether the organization can actually detect and respond to a sophisticated attacker operating against its live production systems.
The framework's stated objective is to "test the detection and response capabilities of the Member Organization against real sophisticated and advanced attacks." Its applicability is broad and explicit: "the Framework applies to all Member Organizations in the Financial Sector, which are regulated by SAMA" — it is not limited to a maturity tier or to the largest banks. SAMA also reserves the authority to select any member organization and require a red teaming test. On frequency, Section 1.6 is precise: each SAMA-regulated member organization "should be tested, as a minimum once every three (3) years."
CSF penetration testing
Annual. Validates that controls on customer and internet-facing services are securely designed and implemented. Scope-defined, assurance-oriented.
Ethical red teaming
At least every three years. Intelligence-led, objective-based simulation of an advanced adversary against live systems. Tests detection and response, not just control design.
// 04 What maturity level must a SAMA member organization reach?
The CSF is assessed on a six-level maturity model, and the target is level 3 or higher. The framework states plainly that "Member Organizations should at least operate at maturity level 3 or higher." Understanding the ladder matters because it tells you not just whether you do penetration testing, but whether you can prove it is working — the difference between a level 3 and a level 4 programme.
| Level | Name | What it means |
|---|---|---|
| 0 | Non-existent | No documentation, awareness or attention for the control |
| 1 | Ad-hoc | Control undefined or partially defined; performed inconsistently |
| 2 | Repeatable but informal | Executed on an informal, unwritten but standardized practice |
| 3 | Structured and formalized | Controls defined, approved and implemented in a structured way — the minimum target |
| 4 | Managed and measurable | Control effectiveness periodically assessed and improved |
| 5 | Adaptive | Controls under a continuous improvement plan |
Penetration testing under 3.2.4 is an ordinary control consideration, so it is expected from the level 3 baseline — a defined, approved, implemented, structured practice, with the "annual … penetration tests" wording as its concrete expression. Reaching levels 4 and 5 is about demonstrating measured effectiveness and continuous improvement: trending your findings year over year, evidencing that remediation actually reduced risk, and feeding results back into the control set. Red teaming under FEER, by contrast, is not tied to a maturity tier at all — it applies to every SAMA-regulated member organization regardless of where it sits on the ladder.
// 05 Who must comply with the SAMA CSF?
The framework applies to all SAMA "member organizations" — the institutions the Saudi Central Bank regulates. The core enumerated population is banks operating in Saudi Arabia, insurance and reinsurance companies, financing companies, credit bureaus, and the financial market infrastructure. In practice, money exchangers and fintechs operating under SAMA's regulatory sandbox are also treated as in scope, though the sandbox and exchanger inclusion rests on how SAMA has applied the framework rather than on a single verbatim line in the 2017 document.
The practical test is simple: if the Saudi Central Bank licenses or regulates your entity, assume the CSF applies and that you are expected to operate at maturity level 3 or higher across its controls. New entrants — particularly sandbox fintechs — are wise to build the 3.2.4 annual testing cadence into their operating model from launch, because retrofitting an assurance programme under supervisory pressure is far more expensive than designing it in.
// 06 How does the SAMA CSF relate to the NCA ECC?
They are separate frameworks that operate in parallel, and most Saudi banks comply with both. SAMA is the sector regulator for financial institutions; the National Cybersecurity Authority's Essential Cybersecurity Controls apply where an institution's systems are classified as Critical National Infrastructure or otherwise fall within ECC scope. Neither replaces the other.
The efficient approach is to treat the SAMA CSF as the more prescriptive, financial-sector-specific regime and map its controls to the ECC domains, so a single evidence set serves both regulators. A SAMA 3.2.4 annual penetration test of customer and internet-facing services, for example, also speaks directly to ECC control 2-11, whose scope is externally provided Internet services. Scoping the test once against both control references — and structuring the report so it can be filed with either — avoids paying twice for overlapping assurance. Where systems are additionally classified as critical, the ECC's companion CSCC brings a six-month testing interval into the picture, which becomes the binding cadence for those specific assets.
// 07 What does a SAMA-aligned testing programme look like in practice?
Putting the pieces together, a compliant programme is not a single annual event but a layered cadence. The most common failure is running one annual penetration test and assuming it satisfies everything; it does not, because vulnerability management, threat intelligence and FEER red teaming are separate obligations with their own rhythms.
Vulnerability management (3.3.17)
Risk-based scanning of applications and infrastructure, with classified findings, defined mitigation timelines and patch management. Feeds the annual test with a clean baseline.
Threat management (3.3.16)
Threat-intelligence process that identifies and assesses relevant adversaries — and, done well, shapes the scenarios for both the annual test and the FEER exercise.
Penetration testing (3.2.4)
Adversarial validation of customer and internet-facing services, reported to the business owner, with follow-up review confirming remediation.
Ethical red teaming (FEER)
Intelligence-led simulation of an advanced attacker against live systems, testing detection and response, executed by certified ethical hackers with structured reporting to SAMA.
A well-run institution sequences these so each informs the next: threat intelligence defines the scenarios, vulnerability management clears the noise, the annual penetration test validates controls, and the tri-ennial red team stress-tests the whole detection-and-response chain. That is also the programme that moves you from maturity level 3 toward levels 4 and 5, because it produces the measured, improving evidence those levels require.
// 08 Frequently asked questions
Which SAMA CSF control requires penetration testing?
Control 3.2.4 "Cyber Security Review." Its consideration states that customer and internet-facing services should be subject to annual review and penetration tests. It is not in the Vulnerability Management control (3.3.17).
How often does SAMA require penetration testing?
Annually, for customer and internet-facing services, under 3.2.4. Unlike the NCA ECC's "periodically," SAMA specifies annual.
Does SAMA require red teaming?
Yes, under the separate Financial Entities Ethical Red-Teaming (FEER) Framework — at least once every three years, for all SAMA-regulated member organizations, not tied to size or maturity tier.
What maturity level must we reach?
The CSF uses a six-level model (0–5); member organizations should operate at level 3 (Structured and formalized) or higher.
Who must comply?
Banks, insurance and reinsurance companies, financing companies, credit bureaus and the financial market infrastructure; money exchangers and sandbox fintechs are generally treated as in scope.
Is SAMA CSF the same as NCA ECC?
No — separate frameworks operating in parallel. Banks typically comply with both and map controls once to reuse evidence.
// 09 Sources
- Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework, Version 1.0, May 2017 — control 3.2.4 "Cyber Security Review" (penetration testing consideration quoted verbatim), 3.3.17 "Vulnerability Management," 3.3.16 "Threat Management."
- SAMA Cyber Security Framework, Section 2.4 — six-level maturity model and the "level 3 or higher" target.
- SAMA Financial Entities Ethical Red-Teaming (FEER) Framework, Document No. 562240000067, 13 May 2019 — objective, applicability (Section 1.3) and periodicity (Section 1.6, "at least once every three years").
- SAMA Rulebook (rulebook.sama.gov.sa) — online control text for 3.2.4, 3.3.17, 2.4 and the FEER framework.
- NCA Essential Cybersecurity Controls (ECC) — for the parallel obligation and control-mapping.
Control references reflect the SAMA CSF v1.0 (2017) and the FEER Framework (2019) as published by the Saudi Central Bank. Confirm current control text on the SAMA Rulebook for your institution before relying on it for a supervisory submission.