Key Takeaways
- SAMA’s Cyber Security Framework scores every control on a six-level maturity model (0–5), and Member Organizations — including licensed fintechs — must operate at Level 3 or higher.
- Level 3 (“Structured and Formalized”) requires controls to be defined, approved, and implemented through a policy-standards-procedures documentation set, with compliance to that documentation actively monitored.
- Good informal practice doesn’t count. If a control isn’t written down, approved, and checked for compliance, it sits at Level 2 regardless of how well it works.
- A subset of subdomains — commonly SOC capabilities and event management — are often held to Level 4, which adds measurable KRIs and KPIs on top of Level 3’s documentation requirements.
- The hardest part of Level 3 isn’t reaching it once; it’s maintaining the evidence trail that proves ongoing compliance at every assessment cycle.
Every fintech licensed or sandboxed under SAMA hears the same phrase from auditors and consultants: “you need to be at Level 3.” Few people stop to explain what that sentence is actually asking for. It isn’t a badge. It isn’t a score on a slide. It’s a specific, checkable claim about how your controls are written, approved, and monitored — and SAMA will test that claim against evidence, not intentions.
This is the level every SAMA-regulated fintech is expected to reach at minimum. Here’s what it actually takes to get there, where teams quietly get stuck, and why “Level 3” is a lower bar than most compliance decks make it sound, and a harder one than most security teams expect.
What The SAMA Cyber Security Framework Covers
SAMA published the Cyber Security Framework (CSF) in 2017, and it applies to every SAMA-regulated Member Organization: banks, insurers, financing companies, credit bureaus, financial market infrastructure providers, and licensed fintechs. It’s built on established standards (NIST, ISO, ISF, PCI, BASEL) but it isn’t a checklist you can copy-paste from one of those. It’s principle-based: SAMA states the outcome it wants and leaves the “how” to you, then grades that “how” against a maturity model.
The Four Control Domains
Every control consideration in the framework sits under one of these — and gets graded on the same 0–5 maturity scale.
Leadership & Governance
Board and executive accountability for cyber security — policy ownership, strategy, and oversight.
Risk Management & Compliance
How cyber risk gets identified, assessed, and tracked against regulatory and internal requirements.
Operations & Technology
The day-to-day controls — detection, response, infrastructure hardening, and technical safeguards.
Third-Party Cyber Security
Extending the same standard to vendors, processors, and any partner touching in-scope systems or data.
Principle-based, not a checklist: SAMA states the outcome it wants in each domain and leaves the “how” to you — then grades that “how” against the maturity model.
Every control consideration under those domains gets scored on the same six-level maturity scale. That scale, not the domain list, is where most fintechs actually get tripped up.
The Six Maturity Levels At A Glance
SAMA’s maturity model runs from 0 to 5. To claim a level, an organization has to meet every criterion of the levels below it first — you can’t be “Level 3 in some areas.”
The Six-Level Maturity Scale
Every control gets graded 0–5. You can’t skip rungs — each level requires everything below it, plus more.
Non-Existent
No awareness, no documentation, no controls.
Ad-Hoc
Depends on individual effort, not process.
Repeatable but Informal
Consistent, but never written down or approved.
Structured and Formalized
Defined, approved, implemented & monitored.
Managed and Measurable
Tracked with real KRIs and KPIs.
Adaptive
Real-time, continuously improved.
The floor, not the ceiling: SAMA member organizations — including licensed fintechs — must operate at Level 3 or higher on every in-scope control.
- Level 0 — Non-Existent: No awareness, no documentation, no controls.
- Level 1 — Ad-Hoc: Controls exist in an unstructured, inconsistent way. They depend on individual effort, not process.
- Level 2 — Repeatable but Informal: Controls are applied consistently, but they aren’t written down or formally approved. What works depends on who’s doing it.
- Level 3 — Structured and Formalized: Controls are defined, approved, and implemented through documented policies, standards, and procedures — and compliance with that documentation is actively monitored.
- Level 4 — Managed and Measurable: Control effectiveness is measured with key risk indicators (KRIs) and key performance indicators (KPIs), not just tracked as “done” or “not done.”
- Level 5 — Adaptive: Controls are integrated into enterprise risk management, monitored in near real time, and continuously improved based on evidence.
Why Level 3 Is The Line Regulators Actually Draw
SAMA’s own rulebook is direct about it: Member Organizations should operate at maturity Level 3 or higher. That makes Level 3 the regulatory floor, not an aspirational target. Everything below it — ad-hoc effort, tribal knowledge, controls that work but were never approved by anyone fails the assessment regardless of how effective those controls feel day to day.
That’s the part fintechs underestimate. A fast-moving security team can genuinely be doing good work — patching fast, catching incidents, running informal reviews and still sit at Level 2, because none of it is written down, approved, or checked for compliance. SAMA isn’t grading your intent. It’s grading whether a control exists on paper, was signed off by the right people, and is being followed in practice.
What “Structured And Formalized” Requires In Practice
What “Structured and Formalized” Actually Requires
To claim Level 3 for any control, a fintech has to clear all three of these — in order.
Write down what the control is, and why
The control gets a clear description and a stated purpose — not tribal knowledge sitting in one person’s head.
Get it formally signed off
Starting with a board-endorsed cyber security policy, then the standards and procedures built on top of it.
Put it into operation — then prove people follow it
The step most programs skip. SAMA isn’t asking “do you have a policy?” It’s asking “can you prove people comply with it?”
Missing any one step — or never checking compliance — caps the control at Level 2.
Only when all three steps are demonstrable, with evidence, does a control clear the regulatory floor.
To claim Level 3, a fintech has to do three things, in order, for every control in scope:
- Define it. Write down what the control is and why it exists.
- Approve it. Get it formally signed off — starting with a board-endorsed cyber security policy.
- Implement and monitor it. Put the control into operation, then actively check that people are actually following the documentation.
That last step is the one most programs skip. SAMA’s requirement isn’t “have a policy.” It’s “have a policy, and prove people comply with it.”
The documentation itself has a specific shape, and SAMA expects all three layers:
- Policy: Board-endorsed, states why cyber security matters to the organization and which information assets must be protected.
- Standards: Built on the policy, define what principles and objectives have to be met.
- Procedures: Define how those standards get carried out day to day.
The Documentation Stack SAMA Expects
Level 3 isn’t “have a policy.” It’s all three layers, in place together, and checked against reality.
Policy
Board-endorsed. States why cyber security matters and which information assets must be protected.
Standards
Built on the policy — defines the specific principles and objectives that must be met.
Procedures
Defines exactly how those standards get carried out, day to day, by the people doing the work.
If any one layer is missing — or was approved but never checked for compliance — the control doesn’t clear Level 3, regardless of how mature the underlying practice looks.
If any one of those three layers is missing — or exists but was never formally approved, or was approved but nobody checks whether teams follow it — the control doesn’t clear Level 3, no matter how mature the underlying practice looks.
The Gap Most Fintechs Fall Into
The most common failure pattern isn’t a missing control. It’s a control that was implemented informally, then documented after the fact to look compliant on paper. That gets a fintech through a self-assessment questionnaire, but not through an audit because SAMA reviews evidence, and “evidence” means proof of ongoing monitoring, not a policy PDF that was written the week before the assessment was due.
The work that actually earns Level 3 looks less like writing documents and more like maintaining them: keeping policies, standards, and procedures current as the environment changes, tracking who owns each control, and generating the evidence trail that shows compliance was checked not assumed.
When Level 3 Isn’t Enough: The Push To Level 4
Level 3 is the floor, not the ceiling, everywhere. A number of subdomains security operations center capabilities and event management among them are commonly expected to operate at Level 4, which means the fintech has to show it’s measuring control effectiveness with KRIs and KPIs, not just confirming the control is “in place.” Which subdomains carry that higher bar can vary by organization type and by the current version of the framework, so it’s worth confirming directly against SAMA’s rulebook rather than assuming it’s uniform across every control.
Level 3 vs. Level 4: What Actually Changes
Level 3 is the regulatory minimum everywhere. A subset of subdomains — commonly SOC capabilities and event management — are held to a higher bar.
Structured & Formalized
The regulatory floor- Controls defined, approved & documented
- Policy → standards → procedures in place
- Compliance with documentation is monitored
- Graded “in place” vs. “not in place”
Managed & Measurable
Everything in L3, plus:- Effectiveness measured with KRIs
- Effectiveness measured with KPIs
- Graded on real performance, not just presence
- Common in SOC & event management subdomains
Level 5, by contrast, is where controls get folded into enterprise risk management and monitored automatically in near real time materially higher lift most fintechs won’t need to reach unless SAMA specifically requires it for their risk profile.
Where The Work Actually Piles Up
Ask any Saudi fintech security or GRC lead where the time goes, and it’s rarely writing the first version of a policy. It’s the maintenance — chasing evidence across teams, re-verifying procedures, and stitching audit packages together, over and over. That’s the cost of staying at Level 3 — not reaching it once, but proving it continuously.
Governed Defense, Powered by OffenseControls & posture
Owns controls and compliance posture, mapped straight to what Level 3 demands — defined, approved, monitored.
Evidence collection
Builds the evidence trail continuously, not once a quarter when the assessment deadline is already looming.
Audit-ready trust reporting
Turns tracked controls into the exact reporting trail SAMA’s assessors are checking for — kept current, not rebuilt.
No More Grunt Work. No More Burnout.
Secure.com delivers Governed Defense, Powered by Offense — AI teammates that attack your environment to find what’s actually exploitable, harden what they find, and hand your team back hours that used to go into evidence-chasing and documentation upkeep. Your team sets the rules; the teammates do the work.
Turn Documentation Into Proof
See how the GRC AI Teammate keeps your Level 3 evidence trail current, continuously.
FAQs
Is SAMA CSF Level 3 mandatory for fintechs, or just recommended?
What’s the actual difference between Level 2 and Level 3?
Does having written security policies automatically put us at Level 3?
How does SAMA verify a claimed maturity level?
What’s the fastest way for a fintech to close the gap to Level 3?
Conclusion
Level 3 isn’t a compliance milestone a fintech clears once and moves past — it’s a standing requirement to keep proving, assessment after assessment, that documented controls are actually being followed. The teams that struggle with it usually aren’t missing controls; they’re missing the evidence trail that turns a policy into something SAMA can verify. Getting that trail right, and keeping it current, is what separates a fintech that passes on paper from one that’s actually built to hold the line.