2022-01-11

Added

Cyber Resilience Fundamental Requirements (CRFR)

The document establishes mandatory cyber security and resilience control requirements for entities intending to qualify for the SAMA Regulatory Sandbox or seeking a license to operate in the Kingdom of Saudi Arabia. It mandates specific controls across governance, operations, and resilience, including biannual penetration testing, a one-year minimum security log retention period, and immediate incident reporting for medium or above severity events. Non-compliance with these requirements may result in the prohibition of sandbox graduation or license requests.

Saudi Central Bank logo

Saudi Arabia

Saudi Central Bank

Scan of the document's first page
Share

Get SAMA alerts — same-day email on every new publication.

Read the rest free

Source: Saudi Central Bank — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from SAMA

We email you every new SAMA publication the day it's published.