Skip to content
Tenant Excellence

Applies toSaudi Arabia · financial sector

SAMA

The Saudi Central Bank Cyber Security Framework for supervised financial institutions, evaluated from Microsoft 365 and Azure configuration.

From Complete

Scope as evaluated

  • Identity and access, including privileged access and MFA
  • Secure configuration, logging and monitoring
  • Data protection, email security and cloud controls

Read from the tenant

  • Conditional Access and role configuration
  • Audit logging and Defender settings
  • Sharing, DLP and Azure security posture

Sample controls

  • 3.3.5 Identity and access management
  • 3.3.14 Security event management
  • 3.3.10 Cryptography
Results are configuration indications drawn from your tenant. They are not an audit opinion or a certification.

In depth

Give the auditor a link, not a folder

Every covered control shows the data Microsoft Graph returned and the endpoint it came from. One click creates a read-only snapshot for one framework; it needs no account and expires after 24 hours.

  • Structured proof per control, with its Graph or ARM source
  • Scoped to one framework, read-only, no sign-in for the auditor
  • Expires after 24 hours; creation is written to the audit log
Learn more

Questions

Questions about SAMA

Does the assessment cover SAMA’s maturity levels?

No. It reports control status from configuration; maturity is assessed by your own programme.

Can the auditor link be shared with SAMA reviewers?

The link is read-only, scoped to SAMA and expires in 24 hours. Who you share it with is your decision.

Which package includes SAMA?

Complete and Premium, together with the other four frameworks.

Request a demo

Which frameworks do you report against?

Tell us in the demo request and we will show the matching controls on a demo tenant.

0 / 2,000