Press TechRound interviews Secure.com CEO on the future of AI security
Read

SAMA CSF Maturity Levels Explained: What “Level 3” Actually Requires of a Saudi Fintech

SAMA CSF maturity levels explain what "Level 3: Structured and Formalized" requires of a Saudi fintech and where most compliance programs fall short.

Key Takeaways

  • SAMA’s Cyber Security Framework scores every control on a six-level maturity model (0–5), and Member Organizations — including licensed fintechs — must operate at Level 3 or higher.
  • Level 3 (“Structured and Formalized”) requires controls to be defined, approved, and implemented through a policy-standards-procedures documentation set, with compliance to that documentation actively monitored.
  • Good informal practice doesn’t count. If a control isn’t written down, approved, and checked for compliance, it sits at Level 2 regardless of how well it works.
  • A subset of subdomains — commonly SOC capabilities and event management — are often held to Level 4, which adds measurable KRIs and KPIs on top of Level 3’s documentation requirements.
  • The hardest part of Level 3 isn’t reaching it once; it’s maintaining the evidence trail that proves ongoing compliance at every assessment cycle.

Every fintech licensed or sandboxed under SAMA hears the same phrase from auditors and consultants: “you need to be at Level 3.” Few people stop to explain what that sentence is actually asking for. It isn’t a badge. It isn’t a score on a slide. It’s a specific, checkable claim about how your controls are written, approved, and monitored — and SAMA will test that claim against evidence, not intentions.

This is the level every SAMA-regulated fintech is expected to reach at minimum. Here’s what it actually takes to get there, where teams quietly get stuck, and why “Level 3” is a lower bar than most compliance decks make it sound, and a harder one than most security teams expect.

What The SAMA Cyber Security Framework Covers

SAMA published the Cyber Security Framework (CSF) in 2017, and it applies to every SAMA-regulated Member Organization: banks, insurers, financing companies, credit bureaus, financial market infrastructure providers, and licensed fintechs. It’s built on established standards (NIST, ISO, ISF, PCI, BASEL) but it isn’t a checklist you can copy-paste from one of those. It’s principle-based: SAMA states the outcome it wants and leaves the “how” to you, then grades that “how” against a maturity model.

SAMA CSF Structure

The Four Control Domains

Every control consideration in the framework sits under one of these — and gets graded on the same 0–5 maturity scale.

01

Leadership & Governance

Board and executive accountability for cyber security — policy ownership, strategy, and oversight.

02

Risk Management & Compliance

How cyber risk gets identified, assessed, and tracked against regulatory and internal requirements.

03

Operations & Technology

The day-to-day controls — detection, response, infrastructure hardening, and technical safeguards.

04

Third-Party Cyber Security

Extending the same standard to vendors, processors, and any partner touching in-scope systems or data.

Principle-based, not a checklist: SAMA states the outcome it wants in each domain and leaves the “how” to you — then grades that “how” against the maturity model.

Every control consideration under those domains gets scored on the same six-level maturity scale. That scale, not the domain list, is where most fintechs actually get tripped up.

The Six Maturity Levels At A Glance

SAMA’s maturity model runs from 0 to 5. To claim a level, an organization has to meet every criterion of the levels below it first — you can’t be “Level 3 in some areas.”

SAMA Cyber Security Framework

The Six-Level Maturity Scale

Every control gets graded 0–5. You can’t skip rungs — each level requires everything below it, plus more.

0

Non-Existent

No awareness, no documentation, no controls.

1

Ad-Hoc

Depends on individual effort, not process.

2

Repeatable but Informal

Consistent, but never written down or approved.

3

Structured and Formalized

Defined, approved, implemented & monitored.

Minimum required
4

Managed and Measurable

Tracked with real KRIs and KPIs.

Often SOC / events
5

Adaptive

Real-time, continuously improved.

The floor, not the ceiling: SAMA member organizations — including licensed fintechs — must operate at Level 3 or higher on every in-scope control.

  • Level 0 — Non-Existent: No awareness, no documentation, no controls.
  • Level 1 — Ad-Hoc: Controls exist in an unstructured, inconsistent way. They depend on individual effort, not process.
  • Level 2 — Repeatable but Informal: Controls are applied consistently, but they aren’t written down or formally approved. What works depends on who’s doing it.
  • Level 3 — Structured and Formalized: Controls are defined, approved, and implemented through documented policies, standards, and procedures — and compliance with that documentation is actively monitored.
  • Level 4 — Managed and Measurable: Control effectiveness is measured with key risk indicators (KRIs) and key performance indicators (KPIs), not just tracked as “done” or “not done.”
  • Level 5 — Adaptive: Controls are integrated into enterprise risk management, monitored in near real time, and continuously improved based on evidence.

Why Level 3 Is The Line Regulators Actually Draw

SAMA’s own rulebook is direct about it: Member Organizations should operate at maturity Level 3 or higher. That makes Level 3 the regulatory floor, not an aspirational target. Everything below it — ad-hoc effort, tribal knowledge, controls that work but were never approved by anyone fails the assessment regardless of how effective those controls feel day to day.

That’s the part fintechs underestimate. A fast-moving security team can genuinely be doing good work — patching fast, catching incidents, running informal reviews and still sit at Level 2, because none of it is written down, approved, or checked for compliance. SAMA isn’t grading your intent. It’s grading whether a control exists on paper, was signed off by the right people, and is being followed in practice.

What “Structured And Formalized” Requires In Practice

Level 3 · Structured and Formalized

What “Structured and Formalized” Actually Requires

To claim Level 3 for any control, a fintech has to clear all three of these — in order.

1
Define

Write down what the control is, and why

The control gets a clear description and a stated purpose — not tribal knowledge sitting in one person’s head.

2
Approve

Get it formally signed off

Starting with a board-endorsed cyber security policy, then the standards and procedures built on top of it.

3
Implement & Monitor

Put it into operation — then prove people follow it

The step most programs skip. SAMA isn’t asking “do you have a policy?” It’s asking “can you prove people comply with it?”

Missing any one step — or never checking compliance — caps the control at Level 2.

= Level 3

Only when all three steps are demonstrable, with evidence, does a control clear the regulatory floor.

To claim Level 3, a fintech has to do three things, in order, for every control in scope:

  • Define it. Write down what the control is and why it exists.
  • Approve it. Get it formally signed off — starting with a board-endorsed cyber security policy.
  • Implement and monitor it. Put the control into operation, then actively check that people are actually following the documentation.

That last step is the one most programs skip. SAMA’s requirement isn’t “have a policy.” It’s “have a policy, and prove people comply with it.”

The documentation itself has a specific shape, and SAMA expects all three layers:

  • Policy: Board-endorsed, states why cyber security matters to the organization and which information assets must be protected.
  • Standards: Built on the policy, define what principles and objectives have to be met.
  • Procedures: Define how those standards get carried out day to day.
Level 3 documentation set

The Documentation Stack SAMA Expects

Level 3 isn’t “have a policy.” It’s all three layers, in place together, and checked against reality.

Layer 1

Policy

Board-endorsed. States why cyber security matters and which information assets must be protected.

Layer 2

Standards

Built on the policy — defines the specific principles and objectives that must be met.

Layer 3

Procedures

Defines exactly how those standards get carried out, day to day, by the people doing the work.

If any one layer is missing — or was approved but never checked for compliance — the control doesn’t clear Level 3, regardless of how mature the underlying practice looks.

If any one of those three layers is missing — or exists but was never formally approved, or was approved but nobody checks whether teams follow it — the control doesn’t clear Level 3, no matter how mature the underlying practice looks.

The Gap Most Fintechs Fall Into

The most common failure pattern isn’t a missing control. It’s a control that was implemented informally, then documented after the fact to look compliant on paper. That gets a fintech through a self-assessment questionnaire, but not through an audit because SAMA reviews evidence, and “evidence” means proof of ongoing monitoring, not a policy PDF that was written the week before the assessment was due.

The work that actually earns Level 3 looks less like writing documents and more like maintaining them: keeping policies, standards, and procedures current as the environment changes, tracking who owns each control, and generating the evidence trail that shows compliance was checked not assumed.

When Level 3 Isn’t Enough: The Push To Level 4

Level 3 is the floor, not the ceiling, everywhere. A number of subdomains security operations center capabilities and event management among them are commonly expected to operate at Level 4, which means the fintech has to show it’s measuring control effectiveness with KRIs and KPIs, not just confirming the control is “in place.” Which subdomains carry that higher bar can vary by organization type and by the current version of the framework, so it’s worth confirming directly against SAMA’s rulebook rather than assuming it’s uniform across every control.

Beyond the floor

Level 3 vs. Level 4: What Actually Changes

Level 3 is the regulatory minimum everywhere. A subset of subdomains — commonly SOC capabilities and event management — are held to a higher bar.

L3

Structured & Formalized

The regulatory floor
  • Controls defined, approved & documented
  • Policy → standards → procedures in place
  • Compliance with documentation is monitored
  • Graded “in place” vs. “not in place”
Required for every in-scope control, every Member Organization
L4

Managed & Measurable

Everything in L3, plus:
  • Effectiveness measured with KRIs
  • Effectiveness measured with KPIs
  • Graded on real performance, not just presence
  • Common in SOC & event management subdomains
Scope varies by org type — confirm against SAMA’s current rulebook

Level 5, by contrast, is where controls get folded into enterprise risk management and monitored automatically in near real time materially higher lift most fintechs won’t need to reach unless SAMA specifically requires it for their risk profile.

SECURE.COM · GRC AI TEAMMATE

Where The Work Actually Piles Up

Ask any Saudi fintech security or GRC lead where the time goes, and it’s rarely writing the first version of a policy. It’s the maintenance — chasing evidence across teams, re-verifying procedures, and stitching audit packages together, over and over. That’s the cost of staying at Level 3 — not reaching it once, but proving it continuously.

Governed Defense, Powered by Offense

Controls & posture

Owns controls and compliance posture, mapped straight to what Level 3 demands — defined, approved, monitored.

Evidence collection

Builds the evidence trail continuously, not once a quarter when the assessment deadline is already looming.

Audit-ready trust reporting

Turns tracked controls into the exact reporting trail SAMA’s assessors are checking for — kept current, not rebuilt.

No More Grunt Work. No More Burnout.

Secure.com delivers Governed Defense, Powered by Offense — AI teammates that attack your environment to find what’s actually exploitable, harden what they find, and hand your team back hours that used to go into evidence-chasing and documentation upkeep. Your team sets the rules; the teammates do the work.

Turn Documentation Into Proof

See how the GRC AI Teammate keeps your Level 3 evidence trail current, continuously.

GRC AI Teammate
Related Reads

FAQs

Is SAMA CSF Level 3 mandatory for fintechs, or just recommended?
Is SAMA CSF Level 3 mandatory for fintechs, or just recommended? It’s the regulatory expectation, not a suggestion. SAMA’s rulebook states that Member Organizations — which includes SAMA-licensed and sandboxed fintechs — should operate at maturity Level 3 or higher. A fintech assessed below Level 3 is expected to close that gap, not treat it as an aspirational goal.
What’s the actual difference between Level 2 and Level 3?
Level 2 controls can be applied consistently and still fail the assessment, because they aren’t written down or formally approved they run on institutional knowledge. Level 3 requires that same control to exist in approved documentation (policy, standards, procedures) and requires proof that compliance with that documentation is being monitored, not assumed.
Does having written security policies automatically put us at Level 3?
No. A policy alone typically reflects Level 1 or 2. Level 3 requires the full documentation set — policy, standards, and procedures each formally approved, plus active monitoring that shows people are actually following them. Documentation without a monitoring trail is the single most common reason fintechs stall below Level 3.
How does SAMA verify a claimed maturity level?
Member Organizations conduct periodic self-assessments against a SAMA questionnaire, which SAMA then reviews and audits. That review checks for evidence — approval records, monitoring logs, audit trails — not just the existence of a document.
What’s the fastest way for a fintech to close the gap to Level 3?
Start with whichever controls are documented but unmonitored, since that’s usually the largest and cheapest gap to close. Build (or automate) the evidence trail — who approved what, when it was last checked, where compliance broke down — so monitoring becomes continuous instead of a scramble before each assessment cycle.

Conclusion

Level 3 isn’t a compliance milestone a fintech clears once and moves past — it’s a standing requirement to keep proving, assessment after assessment, that documented controls are actually being followed. The teams that struggle with it usually aren’t missing controls; they’re missing the evidence trail that turns a policy into something SAMA can verify. Getting that trail right, and keeping it current, is what separates a fintech that passes on paper from one that’s actually built to hold the line.