The SAMA Toolkit equips regulated financial institutions and their partners with 38 editable templates aligned to the domains and subdomains of the Saudi Central Bank Cyber Security Framework, so documented, demonstrable controls are in place before a maturity assessment. On this page:
- What is inside the SAMA Toolkit
- Who this toolkit is for
- How the toolkit maps to the framework
- Why buy instead of months of internal drafting
- Frequently asked questions
- Related cybersecurity toolkits
What is inside the SAMA Toolkit
The pack covers governance through to security operations, with each document written to the control structure an assessor scores against a defined maturity model.
- Cyber security governance policy, charter and strategy documents
- Cyber security risk management procedure and risk register
- Identity, access and privileged-access management procedures
- Network, application, data and cryptography security policies
- Third-party and cloud security management procedures
- Security operations, threat management and incident response plans
- Business continuity, awareness training and HR security records
- Compliance monitoring, internal audit and maturity self-assessment templates

Who the SAMA Toolkit is for
Banks, insurers, finance companies and payment providers operating in the Kingdom of Saudi Arabia answer to the regulator and its mandatory framework, which sets minimum requirements for protecting the information assets of regulated financial institutions. Vendors and technology partners serving those institutions are increasingly pulled into the same expectations through contract, so the pack suits suppliers as well as licensees.
How the SAMA Toolkit maps to the framework
Documentation is organised around the framework’s control structure and its maturity-level expectations, so a self-assessment or regulator review can trace each subdomain to a named policy, procedure or record. The framework and current regulatory guidance are published by the Saudi Central Bank.
Why the SAMA Toolkit beats internal drafting
A complete control library replaces months of internal drafting and mapping, and the mapping is what determines your maturity score rather than the prose itself. The unlocked Word and Excel files are ready to reflect your institution’s systems and governance, making this a one-time purchase instead of an extended regulatory-advisory engagement.
SAMA Toolkit frequently asked questions
Does it include the maturity self-assessment?
Yes. A self-assessment workbook is included so you can score each subdomain, record evidence references and track improvement actions between reviews.
Does it cover cloud and third parties?
It does. Third-party and cloud security management procedures are included, which is where many institutions find their largest gaps.
How does it relate to the NCA controls?
The two frameworks overlap substantially. Institutions in scope of both typically run one control set and map it to each framework, and the companion NCA pack provides that second mapping.
Related cybersecurity toolkits
Pair this with the NCA Cybersecurity Toolkit for the Kingdom’s Essential Cybersecurity Controls and the ISO 27001 Toolkit for a certifiable ISMS. Financial institutions often add the Basel III Toolkit, the SWIFT CSP Toolkit and the ISO 22301 Toolkit.
Delivery, format and licence
Your SAMA Toolkit downloads immediately after checkout as native Microsoft Word and Excel files. Nothing is watermarked or locked, so you can rebrand the documents, bring them under your own document control and revise them for as long as you need them.
It is a one-time purchase with no subscription and no annual renewal. Because the source files are yours, updating a procedure after an audit finding or a change of scope is an internal edit rather than a new purchase.














Reviews
There are no reviews yet.