DuoKey
Compliance

SAMA CSF

Saudi Central Bank Cyber Security Framework. Mandatory for member organisations. 3.3.9 Cryptography and 3.3.5 IAM are the KMS buy triggers.

Requirements

What the regulation expects

The SAMA Cyber Security Framework is mandatory for SAMA Member Organizations. Control 3.3.9 Cryptography covers approved solutions, restrictions and encryption key lifecycle including archiving and recovery. Control 3.3.5 Identity and Access Management covers need-to-know, MFA, privileged and remote access, and periodic review. One console that enforces catalogue, lifecycle and access review output is the practical product answer.
What the regulation expects

Mandatory for SAMA member organisations

Banks, insurance, financing and credit bureaus. Cryptography and IAM are the two controls a KMS is bought against.

Cryptographic standard as configuration

3.3.9 expects a defined, approved and implemented crypto standard. Attach platform configuration as the implementation record.

Privileged access without standing rights

JIT elevation and time-boxed impersonation instead of permanent admin, with session revocation across the cluster.

Periodic access review with a starting point

Privilege-creep audit output so the review starts from findings, not a blank spreadsheet.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

Enforced approved solutions catalogue, key states for archive and recovery, exportable inventory for examiners.

Learn more

AWS XKS

Keep data encryption keys outside the cloud operator trust boundary.

Learn more

Microsoft 365 Customer Key & DKE

Customer-held keys for mail and files that sit alongside core banking controls.

Learn more

SQL & database encryption

External key control for database encryption without redesigning every application first.

Learn more

Key themes

Where independent key control fits

Map product evidence to the SAMA Rulebook control text. The two controls below are the ones that typically drive a KMS purchase.

3.3.9 Cryptography

Approved solutions, restrictions, and key lifecycle including archiving and recovery, enforced as catalogue plus key states rather than a document alone.

3.3.5 Identity and access management

Need-to-know / least privilege, MFA for sensitive systems, privileged and remote access management, and dated access review reports.

Relevant products

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.