The SAMA Cyber Security Framework requires SAMA-regulated financial entities to conduct penetration testing as part of a maturity-based cyber security programme, with expectations scaling to the entity's required maturity. At higher maturity, adversary simulation applies, governed by the FEER (Financial Entities Ethical Red-Teaming) framework for major institutions. CyberFortify maps testing and red teaming to the SAMA model, remediates and retests.
// 01 What the SAMA CSF is
The Cyber Security Framework issued by the Saudi Central Bank (SAMA) to regulate the cyber security of the financial entities it supervises. It is a maturity-based framework: entities are assessed against defined maturity levels across domains covering leadership, risk management, operations and third-party security.
Within it, penetration testing and vulnerability management are required controls, and adversary simulation is expected at higher maturity - governed by the separate FEER red-teaming framework for major institutions.
The SAMA CSF has shaped the security posture of the entire Saudi financial sector. For the practitioner view of the testing and red-teaming obligations, see our SAMA CSF penetration testing & red teaming guide.
// 02 Testing & red-teaming expectations
Penetration testing
Regulated entities conduct penetration testing of their systems as part of the programme. Our manual-led testing satisfies the intent.
Scales with maturity
Expectations rise with the entity's required maturity level - more rigour and frequency for larger, systemic institutions.
Intelligence-led red teaming
Major institutions run adversary simulation under FEER - realistic, threat-led testing of people, process and technology. See our red teaming service.
Mapped to the model
Findings and coverage mapped to the SAMA domains and maturity so the supervisor sees the controls satisfied.
// 03 Who is in scope
The framework applies to entities regulated by the Saudi Central Bank: banks, insurance and reinsurance companies, financing companies, credit bureaus and the financial market infrastructure. Any SAMA-supervised financial entity is expected to implement the framework and demonstrate the required maturity, including the penetration testing controls - with the largest, most systemically important institutions facing the higher expectations, including FEER red teaming. These entities also typically fall under the national NCA ECC, handle cards under PCI DSS, and connect to SWIFT under the SWIFT CSP. Our industry work in banking and insurance maps directly to this population.
SAMA's supervisor does not just want a test - they want evidence mapped to your required maturity, and for major institutions, a genuine intelligence-led red team under FEER, not a scoped scan. We build engagements to deliver at exactly that level.
CyberFortify SAMA-facing reporting// 04 FEER vs a standard penetration test
The distinction matters. A penetration test assesses defined systems for vulnerabilities and proves impact within a scope. A FEER exercise is a realistic, threat-intelligence-driven simulation of a genuine adversary against live production, testing people, processes and technology together and overseen per the framework - closer to a full red-team engagement than a scoped test. It parallels the EU's DORA TLPT and the TIBER model. Most SAMA entities run regular penetration testing; the larger institutions SAMA identifies additionally run FEER. Map the cadence alongside the region with the GCC compliance calendar.
// 05 Frequently asked questions
Does the SAMA CSF require penetration testing?
Yes. It requires SAMA-regulated financial entities to conduct penetration testing as part of their cyber security programme, alongside vulnerability management. The framework is maturity-based, so expectations scale with required maturity, and at higher maturity adversary simulation is expected. The FEER framework governs intelligence-led red teaming for major institutions.
Who must comply?
Entities regulated by the Saudi Central Bank - banks, insurance and reinsurance companies, financing companies, credit bureaus and financial market infrastructure. Any SAMA-supervised entity is expected to implement the framework and demonstrate maturity, including penetration testing. Larger institutions face higher expectations, including FEER red teaming.
What is FEER?
The Financial Entities Ethical Red-Teaming framework - SAMA's framework for intelligence-led red teaming of major institutions. Unlike a scoped penetration test, a FEER exercise is a realistic, threat-intelligence-driven simulation against live production, testing people, process and technology together. It's closer to a full red team and applies to the larger institutions SAMA identifies.
How does the CSF relate to the NCA ECC?
They are separate regimes that often both apply to a Saudi financial entity. The SAMA CSF is the central bank's sector-specific framework; the NCA ECC is the national baseline. A bank may need to satisfy both, so engagements map evidence to each. Card handling adds PCI DSS and personal data adds the Saudi PDPL.