What is SAMA CRFR?
The Saudi Central Bank (SAMA) introduced the Cyber Resilience Fundamental Requirements (CRFR) in January 2022 as part of its commitment to strengthen the cyber resilience of the Kingdom’s financial sector. The CRFR framework was specifically designed for newly established entities, fintech startups, and financial service providers that are either seeking entry into the SAMA Regulatory Sandbox or applying for a license to operate in Saudi Arabia.
In today’s digital economy, customers expect uninterrupted services, flawless user experience, and strong protection of their sensitive data. With the rapid growth of fintech solutions, online banking platforms, and digital payment services, organizations face increased exposure to cyberattacks, fraud, and operational disruptions. SAMA CRFR addresses these challenges by defining a minimum but fundamental set of cybersecurity and resilience requirements that organizations must implement to ensure service availability, data confidentiality, and regulatory compliance. By adopting SAMA CRFR compliance, organizations not only meet licensing requirements but also establish a foundation for trust, operational stability, and long-term growth.
Domains Covered Under SAMA CRFR
The CRFR framework is structured into three key domains, each addressing essential aspects of cybersecurity and operational resilience. Together, they form the baseline controls that financial institutions must implement before scaling towards advanced frameworks like SAMA CSF (Cybersecurity Framework) and BCMF (Business Continuity Management Framework).
Cyber Security Leadership and Governance
Effective cyber resilience starts at the leadership level. CRFR emphasizes that organizations must establish strong governance practices to oversee and manage cybersecurity efforts strategically. Key requirements include:
- Governance structure — establish a cybersecurity governance structure with defined responsibilities.
- Policy framework — develop and approve policies, procedures, and standards.
- Periodic review — conduct regular reviews to keep policies aligned with evolving threats.
- Risk integration — integrate cyber and fraud risk assessments into business models.
- Access control — enforce strong password and access control policies.
Cyber Security Operations and Technology
The operations and technology domain of CRFR focuses on practical security controls and technical safeguards required to protect an organization’s IT infrastructure, applications, and digital services. Key requirements include:
- Identity and access management — implement IAM across systems and services.
- Change and development — enforce change management and secure SDLC practices.
- Secure architecture — maintain secure network architecture and encryption protocols.
- Assurance testing — conduct regular vulnerability assessments and penetration tests.
- Monitoring — deploy SIEM and monitoring tools for continuous incident detection.
- Endpoint hygiene — ensure timely patching and endpoint protection.
Resilience
The resilience domain ensures that organizations can withstand, respond to, and recover from disruptions, whether caused by cyberattacks, system failures, or natural disasters. Key requirements include:
- Continuity planning — defining, approving, and periodically testing Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP).
- Backup and restoration — establishing backup and restoration procedures, including backup frequency (daily, weekly, monthly), encryption of sensitive data, secure offsite or offline backup storage, and secure destruction of obsolete backup media.
- Restoration testing — conducting restoration tests to ensure data can be recovered quickly and reliably.
Our Methodology for SAMA CRFR Compliance
We offer a structured approach to help organizations achieve SAMA CRFR compliance through comprehensive audit, consultancy, and advisory services:
- Gap assessment — a detailed review of your current controls, governance, and resilience measures against SAMA CRFR requirements.
- Risk identification and mapping — analysing each gap to determine the cyber and business risks it poses, ensuring remediation is risk-driven.
- Remediation roadmap — providing a prioritized, step-by-step action plan for achieving compliance efficiently.
- Implementation support — assisting in deploying the required policies, technical safeguards, and resilience measures.
- Independent compliance audit — performing a full audit to ensure your entity meets all CRFR controls before SAMA reviews or licensing.
- Ongoing advisory & training — providing continuous guidance, awareness training, and compliance monitoring as threats evolve.
Why You Need SAMA CRFR Compliance
Adopting SAMA CRFR is not just about ticking a regulatory checkbox — it is about building a trusted, resilient, and secure fintech environment.
- Regulatory obligation — mandatory for organizations applying for a SAMA license or participating in the Regulatory Sandbox.
- Enhanced cyber resilience — strengthens your ability to anticipate, withstand, and recover from cyberattacks, fraud, and operational disruptions.
- Customer confidence — demonstrates your commitment to safeguarding data and ensuring uninterrupted services, building stronger trust with clients.
- Foundation for future compliance — serves as a stepping stone towards broader SAMA frameworks such as the Cybersecurity Framework (CSF) and Business Continuity Management Framework (BCMF).
- Reduced licensing risks — minimizes the chance of application rejection, regulatory penalties, or operational restrictions due to non-compliance.
Why Choose Us
Partnering with us for SAMA CRFR compliance audit and consultancy services ensures that you are working with experienced professionals who understand both local regulatory requirements and global best practices.
- Specialized expertise in SAMA standards — extensive experience with SAMA CRFR, CSF, BCMF, and MVC, ensuring deep understanding of regulatory expectations.
- Comprehensive end-to-end services — from gap assessments and remediation planning to audits and ongoing advisory, we provide complete compliance support.
- Tailored compliance strategies — customized solutions that align security and resilience requirements with your unique business model and operational needs.
- Proven track record in the Saudi financial sector — trusted by fintech startups, financial institutions, and regulated entities across the Kingdom.
- Practical and business-oriented approach — recommendations designed to achieve compliance while minimizing disruption and supporting long-term growth.
