Press TechRound interviews Secure.com CEO on the future of AI security
Read

From 18 Months to Audit-Ready: A Realistic SAMA CSF Roadmap for Fintech Startups

A realistic, phase-by-phase SAMA CSF roadmap for fintech startups in Saudi Arabia, from gap assessment to Level 3 audit readiness in 18 months.

Key Takeaways

  • SAMA CSF Level 3 is the mandatory minimum for every SAMA-regulated fintech, and it requires documented, board-approved, and actively monitored controls, not just policy on paper.
  • A realistic timeline for a startup beginning at Level 0 or Level 1 is nine to eighteen months, with eighteen months being the more common real-world outcome.
  • The roadmap runs through six phases: gap assessment, governance foundations, control build-out, monitoring maturity, independent testing, and board sign-off with SAMA submission.
  • The biggest timeline risk is rarely the technical controls themselves. It is the evidence collection, monitoring, and reporting overhead that a small team cannot sustain alongside building product.
  • Governed AI Teammates can absorb that operational load, with your team keeping full authority over scope, permissions, and approvals.

Introduction

Most fintech founders in Saudi Arabia find out about the SAMA Cybersecurity Framework (CSF) the same way: a licensing requirement, an investor due diligence checklist, or a partner bank asking for proof of compliance before they will integrate. What follows is usually a scramble. Policies get written in a weekend. A vulnerability scan gets mistaken for a penetration test. Somebody spends three days manually screenshotting configurations for an auditor who will ask for the same evidence again next quarter.

None of that is a maturity problem. It is a capacity problem. SAMA CSF compliance is not hard because the controls are exotic. It is hard because a startup security team of one or two people is expected to produce the same evidence, monitoring, and board reporting that a bank builds with a full compliance department.

This guide lays out a realistic 18-month roadmap to SAMA CSF Level 3, the regulatory minimum every SAMA-supervised entity must reach, and where the work can be handed to something other than your already-stretched team.

What the SAMA CSF Actually Requires

The SAMA Cybersecurity Framework applies to every entity regulated by the Saudi Central Bank, including licensed fintechs, BNPL providers, and technology firms that process transactions or hold financial data on behalf of a SAMA-regulated institution. Compliance is not optional and it is not a one-time certificate. It is demonstrated through annual self-assessments and periodic supervisory reviews.

The framework groups its requirements into four broad areas:

  • Governance and leadership. Board accountability, a designated CISO, an approved cybersecurity strategy, and regular reporting to the board.
  • Risk management and compliance. Risk classification, compliance monitoring, regulatory reporting, and oversight of third-party risk.
  • Operations and technology. The technical backbone: identity and access management, vulnerability management, incident response, network security, secure development, and business continuity.
  • Third-party cybersecurity. Due diligence and ongoing assessment of vendors, outsourcing partners, and cloud providers.

Every control across these areas is scored on a six-point maturity scale, from non-existent to optimised. SAMA sets Level 3, “defined,” as the mandatory floor. That means controls must be formally documented, board-approved, and actively monitored, not just written down somewhere and hoped for. A policy without evidence that it is followed does not clear Level 3.

Why 18 Months Is the Honest Number

Startups that begin with little to no formal security program typically start at Level 0 or Level 1 across most domains. Reaching Level 3 from that starting point realistically takes nine to eighteen months of sustained work, and eighteen months is the more common outcome once you account for hiring lag, evidence accumulation, and the fact that a control cannot be claimed at Level 3 without first passing through Levels 1 and 2 in sequence.

Fintechs that already hold ISO 27001 or SOC 2 certification can move faster because much of the technical control mapping already exists. Fintechs starting from scratch cannot skip steps, no matter how good their engineering team is at shipping product quickly. Compliance maturity and product velocity are different clocks.

The single most expensive mistake we see is skipping the gap assessment and going straight to buying tools or writing policy. Startups that do this consistently discover, at their first SAMA review, that they over-built in areas that were already fine and left the domains carrying the most risk untouched.

An 18-Month Roadmap for Fintech Startups

Months 0 to 2: Baseline and Scope

Before anything gets built, you need an accurate picture of where you stand. This phase should produce a scored gap register across every applicable sub-domain, not a general impression that “things are mostly okay.” Scoping matters here too: which sub-domains apply to your specific licence type, and where your data and payment flows actually put you in scope.

  • Map business lines, systems, and data flows against SAMA CSF sub-domains
  • Score current maturity per control with supporting evidence, not intent
  • Flag every control below Level 3 and rank by remediation effort

Months 2 to 5: Governance Foundations

Governance is the domain fintechs most often underweight, because it produces no code and no dashboard. It is also the domain SAMA checks first. A board that has never seen a cybersecurity report will fail this section regardless of how strong the technical stack is.

  • Appoint or formally designate a CISO
  • Draft and secure board approval for a cybersecurity policy and strategy
  • Establish a cybersecurity committee with a defined reporting cadence to the board

Months 4 to 10: Control Build-Out

This is the longest phase and runs largely in parallel with governance work. Technical and procedural controls across identity management, vulnerability management, incident response, network segmentation, secure development, and business continuity all need to move from Level 1 or 2 toward Level 3, with configuration records, access logs, and procedure documents to prove it.

  • Formalise standards and procedures for each in-scope sub-domain
  • Implement access controls, logging, and monitoring with retained evidence
  • Extend security requirements into vendor and cloud contracts, and secure any required regulatory approval for cloud usage

Months 9 to 14: Monitoring and Evidence Maturity

A control that exists but is never checked is not at Level 3. This phase is where startups build the habit of ongoing compliance monitoring: tracking exceptions, running internal audits, and keeping an evidence trail current instead of reconstructed under deadline pressure.

  • Stand up recurring compliance monitoring and exception tracking
  • Run internal self-assessments against the full framework, not a sample
  • Close residual gaps identified during monitoring before they surface in a SAMA review

Months 12 to 16: Independent Testing

SAMA expects penetration testing as evidence that controls actually hold up under attack, not just on paper. This needs to cover the full regulated environment, including APIs, mobile applications, and cloud infrastructure, and it needs a documented remediation and retest cycle. A scan report filed and forgotten will not satisfy an assessor.

  • Commission full-scope penetration testing by qualified practitioners
  • Remediate findings and retest to prove the fix held
  • Retain before-and-after evidence as part of the audit trail

Months 15 to 18: Board Sign-Off and Submission

The roadmap itself must be approved by the board and submitted to SAMA, with quarterly progress reports continuing until full compliance is reached. This is not paperwork at the end. It is the formal handoff of everything built in the previous fifteen months into a form SAMA can review.

  • Finalise the remediation roadmap and secure board sign-off
  • Submit to SAMA and establish the quarterly reporting cadence
  • Set the recurring cycle for annual self-assessment and continuous evidence collection

Where the Work Actually Bottlenecks

Ask any fintech security lead what eats the most time on this roadmap and the answer is rarely the technical controls. It is the evidence chasing: pulling screenshots, chasing sign-offs, reconciling logs, rewriting the same status update for the third stakeholder this month, and stitching together a compliance picture across five different consoles. That is the grunt work. It is also exactly the toil that leads to burnout on small security teams, and it is the reason startups fall behind schedule even when their actual controls are sound.

Governed Defense, Powered by Offense. No More Grunt Work. No More Burnout.

This is where secure.com fits into a startup’s SAMA journey. Our GRC AI Teammate owns controls, compliance posture, evidence collection, audit readiness, and trust reporting, executing inside the scope, permissions, and approvals your team defines. It does not replace your CISO or your board. It does the repeatable, evidence-heavy work that currently consumes the hours your team needs for judgment calls, and hands those hours back.

For the testing phase of the roadmap, our Red AI Teammate runs continuous, approved-scope adversary simulation, and the results feed directly into what your defensive controls need to harden next. The teammate that attacks teaches the teammate that defends.

You do not need the full roster to start. A single AI Teammate is built to be complete and valuable on its own from day one, whether you bring it in for audit-readiness work first or start with continuous testing.

Common Mistakes Fintech Startups Make on the SAMA Journey

  • Treating a written policy as a finished control. SAMA assessors look for evidence of consistent implementation, not just a signed PDF.
  • Scoping penetration testing to the public website only. APIs, mobile apps, and cloud infrastructure are all in scope and all get checked.
  • Leaving the board out of the loop. Governance failures show up regardless of how strong your technical stack is.
  • Skipping the gap assessment. Building controls before scoping wastes budget on areas that were already fine.
  • Underestimating third-party and cloud requirements. Vendor contracts, security assessments, and cloud approvals are frequently the most underbuilt domain in a startup’s first year.

FAQs

How long does SAMA CSF compliance actually take for a fintech startup?
Startups beginning with little to no formal security program typically need nine to eighteen months of sustained work to reach Level 3, the mandatory minimum. Fintechs with existing ISO 27001 or SOC 2 certification can often move faster by mapping existing controls to SAMA sub-domains.
What does Level 3 actually mean in practice?
Level 3, called “defined,” means controls are formally documented, approved by the board, and actively monitored, with evidence that they are being followed day to day. Having written policies alone does not meet this bar if there is no proof the controls are working.
Do we need ISO 27001 as well as SAMA CSF?
They are not the same thing and SAMA does not issue a certificate the way ISO does. Many technical controls overlap closely, so an existing ISO 27001 program can accelerate parts of the SAMA journey, but SAMA’s governance and reporting requirements are specific to the Saudi regulatory context and still need to be built out separately.
Can a two-person security team realistically hit this timeline without a large hire?
It depends on how much of the recurring, evidence-heavy work can be offloaded from that team’s calendar. Governed AI Teammates are built to take on exactly that kind of operational load, inside boundaries your team sets, which is what makes an eighteen-month timeline achievable without a headcount increase.
What happens if a startup misses its self-imposed roadmap timeline?
SAMA requires the roadmap to be submitted with board approval and expects quarterly progress reports until full compliance is reached. Missing internal milestones is common, but the reporting cadence means slippage needs to be visible and explained, not hidden until the next supervisory review.

Conclusion

Reaching SAMA CSF Level 3 is achievable for a fintech startup in eighteen months, but only if the roadmap accounts for where the real time goes: not the technical build-out, but the governance, evidence, and monitoring work that never stops once you start. Secure.com provides governed AI security teammates that attack, harden, and prove defensive outcomes, above the stack you already own, with your team setting the rules and approving consequential action. Attack. Harden. Prove. Repeat.