Note: The Listed platform will permanently shut down December 31, 2026. Your data published on Listed will still be available in your personal Standard Notes account. Learn more

From "Non-Existent" to "Adaptive": Decoding SAMA CSF's Maturity Scale

One of the more genuinely useful things about Saudi Arabia's cybersecurity framework for financial institutions is that it doesn't just ask a yes-or-no question about compliance. Instead, it measures maturity across a six-point scale, running from Level 0 to Level 5, and that distinction matters far more in practice than it might sound on paper.

At Level 0, described as "non-existent," controls simply aren't in place often because the underlying risk hasn't even been recognized as a risk yet. This isn't necessarily about negligence; sometimes an organization genuinely hasn't identified a particular threat as something worth addressing. Level 1, "ad-hoc," is the "we do something, sort of" stage. Controls exist in some form, but they're applied inconsistently one team handles a process one way, another team handles it differently, and there's no standard everyone follows.

By Level 2, "repeatable but informal," practices have become consistent enough that people do them the same way each time, but they still aren't formally documented or officially approved. This is a common trap that organizations fall into without realizing it. Teams assume that because everyone follows the same informal routine, that counts as being compliant. It doesn't at least not according to how auditors evaluate maturity. Without documentation and approval, a repeatable practice is still considered informal.

Level 3, "structured and formalized," is usually the level SAMA expects regulated institutions to reach at minimum. At this stage, policies, standards, and procedures are formally defined, approved by the appropriate authority, actually implemented, and critically demonstrated with evidence. This is the point where an organization can show an auditor not just a policy document, but proof that the policy is followed in practice.

Level 4, "managed and measurable," builds on that foundation by adding ongoing measurement. Control effectiveness gets periodically evaluated and improved based on what that measurement reveals, rather than being set once and left alone. And Level 5, "adaptive," represents the top of the scale security here is continuously improved and woven directly into enterprise risk management and broader organizational performance information, rather than existing as a separate, siloed function.

Here's where a lot of institutions run into trouble during actual audits: the gap between Level 2 and Level 3. It's an easy trap to fall into precisely because Level 2 can feel like "we're basically doing everything right" from the inside. Teams have good habits, processes get followed, nothing seems obviously broken. But without formal documentation, approval, and demonstrable evidence, none of that counts toward the maturity level SAMA is actually looking for.

The full maturity level breakdown and requirements table lays out exactly what auditors expect to see as evidence at each stage across all four domains, along with a practical checklist for closing the gap between informal and formalized practices.

What makes this maturity model particularly valuable, compared to a simple pass/fail compliance check, is that it gives institutions a realistic roadmap rather than an all-or-nothing target. An organization doesn't need to jump from Level 1 straight to Level 5 in one cycle and honestly, trying to do so usually backfires, because rushed documentation tends to be shallow and doesn't hold up well under audit scrutiny. A more sustainable approach is closing one level at a time, starting with whichever domain carries the most risk exposure, and building the evidence trail as controls mature rather than reconstructing it retroactively right before an assessment is due.

For most institutions, reaching and maintaining Level 3 consistently across all four domains is a realistic and defensible near-term goal and it's exactly the level where most of the audit friction tends to disappear.


You'll only receive email when they publish something new.

More from Cyber Security Blogs
All posts