Cybersecurity and regulatory engineering
The delivery program behind SAMA and NCA control implementation.
Cybersecurity and regulatory engineeringCompliance service
Limaz assesses readiness, maps applicable controls, designs remediation, supports implementation, builds the evidence model, and validates progress for SAMA-supervised organizations.
The SAMA Cyber Security Framework sets cybersecurity expectations for institutions supervised by the Saudi Central Bank. Implementation requires a target control set, named owners, technical and process changes, and current evidence for review.
01
Establish which controls apply to your licence and activities, and which systems and owners they land on.
02
Review the policies, systems, owners, evidence, and gaps that exist today.
03
Control architecture, decision rights, and what must change in process and technology.
04
Create an implementation backlog with owners, dependencies, priorities, and acceptance criteria.
05
Logs, approvals, tests, and artefacts tied to owners so reviews do not start from zero.
06
Prove operation, then close residual risk as measurable work.
SAMA CSF is broader than financial crime. Limaz implements the control program through cybersecurity and regulatory engineering. Where fraud, AML, screening, and decisioning need a product layer, Naiza by Limaz is used only in that slice.
Do not treat a fraud platform as a substitute for SAMA CSF implementation, and do not treat a policy pack as a substitute for either.
The delivery program behind SAMA and NCA control implementation.
Cybersecurity and regulatory engineeringWhen national cybersecurity controls also apply.
NCA ECC implementationControl and resilience expectations for payment operations.
SAMA payment systemsDecision rights and oversight for technology in supervised institutions.
SAMA IT governance frameworkFraud and AML decisioning where it belongs in the operating model.
Naiza by LimazTechnical controls that make the framework operable.
Security control implementationThe Saudi Central Bank publishes the SAMA Cyber Security Framework for supervised financial institutions.
Map the current control state, define the target architecture and owners, sequence the implementation backlog, connect evidence sources, then validate and remediate. Limaz delivers the implementation work.
Applicability depends on SAMA supervision, licence, and activities.
SAMA CSF applies to SAMA-supervised financial institutions. NCA Essential Cybersecurity Controls apply to in-scope national entities as defined by NCA. Some organizations must operate both.
Last reviewed: Sep 12, 2026
Tell us which system, control, or requirement you are working on. We’ll review the scope and suggest the next step.