Follow Us On Social Media

Riyadh, Saudi Arabia
Request a Consultation
SAMA CRFR and MVC for Fintech Cybersecurity – Saudi Arabia
Home » SAMA CRFR and MVC for Fintech Cybersecurity – Saudi Arabia
SAMA CRFR & MVC - Fintech

SAMA CRFR and MVC for Fintech Cybersecurity - Saudi Arabia

SAMA CRFR and MVC are the cyber requirements many Saudi fintechs must meet before and during licensing - Cyber Resilience Fundamental Requirements (CRFR) for sandbox and licence readiness, and Minimum Verification Controls (MVC) for e-wallet, lending, crowdfunding and related fintech models under SAMA supervision. CyberInTech helps you turn those requirements into working controls, gap registers, and sampleable evidence from Riyadh.

Answer first: what buyers need

If you are preparing a sandbox application, a licence file, or a bank/partner questionnaire that cites CRFR or MVC, start with a scoped gap assessment, then close gaps with owners and proof - not policy theatre.

CyberInTech

Engagement highlights

  • CRFR and/or MVC gap assessment
  • Sandbox and pre-licence readiness
  • Evidence pack for questionnaires
  • Bridge to SAMA CSF maturity

What is SAMA CRFR (Cyber Resilience Fundamental Requirements)?

CRFR is SAMA's Cyber Resilience Fundamental Requirements - a prioritised set of cyber security and resilience controls for entities that are recently established or early in their financial-sector operations in Saudi Arabia.

Per SAMA's Rulebook (in force; dated Gregorian 1/1/2022):

  • Who it applies to: entities intending to qualify for the SAMA Regulatory Sandbox and/or entities seeking a licence to operate in the Kingdom.
  • Purpose: help those entities meet minimum cyber resilience licensing requirements without treating CRFR as a full substitute for later frameworks.
  • Relationship to CSF / BCM: CRFR must not be treated as a replacement for SAMA's Cyber Security Framework (CSF) and Business Continuity Management Framework (BCMF). After licensing, entities remain subject to those (and other) SAMA requirements.
  • Domains (structure): control requirements organised around cyber security leadership and governance, operations and technology, and resilience (including BCP/DRP and backup themes). Official control IDs and wording are in the SAMA Rulebook publication - we map your engagement to that text.
  • Compliance consequence: if an entity cannot demonstrate compliance with the Fundamental Requirements, SAMA reserves the right to prohibit sandbox graduation / licence request.

In buyer language: CRFR is the pre-licence / sandbox cyber bar. Passing it does not mean you are done with SAMA CSF maturity once you are licensed.

What is SAMA MVC (Minimum Verification Controls)?

MVC is SAMA's Minimum Verification Controls (Version 1.0, September 2021) - not "Minimum Viable Cybersecurity Controls." The name refers to mandatory verification and security controls for digital fintech services.

Per SAMA's published MVC document:

  • Who it applies to: any member organisation that provides e-wallet, lending products, crowdfunding, or other fintech business models under SAMA supervision, taking applicability into account against the stated objectives.
  • Structure: Registration/Onboarding Controls; General Controls; Lending Application Special Controls (additional for lending companies).
  • Themes buyers will recognise: secure registration and identity validation, device/application binding, OTP and MFA, session and fraud controls, official app-store distribution, jailbreak/root restrictions, backups/contingency, SMS notifications, board-approved internal policies reflecting MVC, and lending-specific checks where applicable.

MVC sits alongside other SAMA cybersecurity requirements. Exact control wording and any circular values follow current SAMA text and memos.

Who must comply (sandbox, pre-licence, licensed fintechs)?

CRFR typically bites before full licensed CSF depth: sandbox applicants and licence seekers. MVC typically bites for licensed / supervised fintech models in e-wallet, lending, crowdfunding and related categories. Many programmes need both at different stages.

01

Regulatory Sandbox

Fintechs preparing sandbox operational readiness, including cyber and technology criteria assessed by SAMA.

02

Licence seekers

Applicants who must show minimum cyber resilience before a SAMA licence.

03

Supervised models

E-wallet, lending, crowdfunding and similar models that must implement MVC.

04

Bank / partner asks

Teams answering questionnaires that ask for CRFR/MVC-aligned evidence.

Confirm your exact regulatory status with counsel and current SAMA guidance. Scope is not one-size-fits-all.

How CRFR and MVC relate to the SAMA CSF

InstrumentStage / roleRelationship to CSF
CRFRSandbox qualification and/or licence seeking - minimum cyber resilienceAligned in structure/content with CSF and BCMF themes; not a replacement post-licence
MVCOperating fintech models (e-wallet, lending, crowdfunding, other) under SAMAComplements broader SAMA cybersecurity requirements; model-specific verification controls
SAMA CSFLicensed / member-organisation cyber maturity programmePrimary long-term cyber framework; maturity Level 3+ is the baseline objective in the CSF maturity model

Practical programme design: use CRFR to clear the entry bar, implement MVC for product/channel verification, then build toward CSF maturity (often Level 3 as the stated minimum objective). Deep-dive: SAMA CSF consulting.

What a fintech must prepare

You need operable controls and evidence - not a PDF folder of templates.

1

Scope clarity

Sandbox vs licence vs licensed model; which product lines (wallet, lending, crowdfunding, other).

2

Governance pack

Cyber roles, policies/procedures/standards, risk register, board or management approval trail.

3

Identity and access

IAM, MFA, password standards, privileged access.

4

Secure build and ops

Network segmentation, cryptography, patching, endpoint protection, change management, secure SDLC / app shielding where CRFR applies.

5

Testing evidence

Vulnerability assessment; penetration testing cadence where CRFR requires (CRFR cites PT at least twice yearly or after major/critical change).

6

Monitoring and incident

Logging (CRFR cites minimum one-year retention), SIEM integration, incident process, SAMA notification paths where required.

7

Resilience

BCP/DRP, backups and restoration tests.

8

MVC-specific and evidence index

Onboarding/verification flows, OTP/MFA/transaction controls, fraud use cases, lending specials if applicable, plus configs, tickets, test reports and ownership records reviewers can sample.

Prefer a structured first step? Start with a cybersecurity gap assessment.

How CyberInTech helps

We map your current state to applicable CRFR and/or MVC controls, produce a risk-ranked remediation roadmap, and support policies, technical uplift, and an evidence pack your team can defend - you keep ownership.

01

Gap assessment

Against applicable CRFR domains/controls and/or MVC sections.

02

Remediation roadmap

Sequenced by licence/sandbox deadline and operational risk.

03

Policy and control artefacts

Aligned to how you actually operate.

04

Technical and process uplift

With your engineering and ops teams.

05

Evidence pack

For self-assessment, SAMA sampling, or partner questionnaires.

06

CSF bridge

Align CRFR work toward full CSF maturity so you do not rebuild twice.

Delivery experience (counts kept separate). CyberInTech has delivered 2 SAMA consulting engagements, alongside 5 CST, 2 ISO/IEC 27001, 4 ERP, and 3 complex low-current projects in Saudi Arabia. No named clients; no invented licences. Fees are scoped on discovery. We are not a regulator, not a certification body, and we do not claim to be an "approved/accredited/licensed consultant" unless a specific registration is confirmed for your scoped activity on discovery.

Who this is not for

  • Buyers who only want a logo or policy pack with no control or evidence work
  • Anyone expecting a guaranteed "SAMA pass," maturity certificate, or licence approval we cannot honestly promise
  • Scopes that legally require a specialist licence we do not hold - we say so and help you route
  • General IT support with no regulatory fintech angle - see Managed IT

Typical engagement flow

1

Discovery

Sandbox / licence / licensed-model status, product lines, deadlines, systems, owners.

2

Assess

CRFR and/or MVC mapping, evidence sampling, CSF linkages where relevant.

3

Findings workshop

Plain-language gaps for founders and control owners.

4

Remediate

Sequenced fixes with owners and success criteria.

5

Evidence pack

Index and coaching for self-assessment, SAMA review, or partner ask.

Deliverables

Typical set (confirmed on discovery):

  • CRFR / MVC gap register mapped to controls in scope
  • Prioritised remediation roadmap with owners
  • Policy and control artefacts as scoped
  • Evidence checklist / pack for readiness
  • Clear list of technical and process actions still open

FAQ

What does CRFR stand for?

Cyber Resilience Fundamental Requirements - SAMA's fundamental cyber security and resilience control set for sandbox qualification and/or licence-seeking entities in Saudi Arabia's financial sector. Official text is published in the SAMA Rulebook.

What does MVC stand for?

Minimum Verification Controls (SAMA, Version 1.0, September 2021). It is not "Minimum Viable Cybersecurity Controls." It applies to e-wallet, lending, crowdfunding and other fintech models under SAMA supervision, as stated in the official document.

Do sandbox fintechs need CRFR, MVC, or both?

Sandbox and licence seekers typically focus on CRFR and sandbox operational-readiness criteria. MVC applies to supervised fintech models such as e-wallet, lending and crowdfunding. Many journeys need CRFR first, then MVC and CSF as the business licences and scales.

Does CRFR replace the SAMA Cyber Security Framework?

No. SAMA states CRFR should not be treated as a replacement for the Cyber Security Framework and Business Continuity Management frameworks. Post-licensing, relevant CSF/BCM and other requirements still apply.

What should we prepare before a CRFR or MVC gap assessment?

Entity and product scope, architecture diagrams, current policies, access and logging posture, recent vulnerability and penetration test reports if any, BCP/DRP and backup evidence, and named owners.

How long does a CRFR/MVC readiness engagement take?

It depends on product complexity, starting maturity, and whether remediation is in the same engagement. Many teams start with a focused gap assessment, then remediate in phases. CyberInTech gives a realistic timeline after discovery.

Can you help with bank questionnaires that ask for CRFR/MVC evidence?

Yes - with control and evidence work behind the answers. Questionnaire copy without operable proof rarely satisfies serious banking partners.

Are you a SAMA-approved or accredited consultant?

CyberInTech does not claim to be a regulator, certification body, or approved/accredited/licensed consultant by default. Any registration relevant to a scoped activity is confirmed on discovery.

Related pages

Next step

Tell us whether you are in sandbox, pre-licence, or licensed fintech status, your product model (wallet, lending, crowdfunding, other), and any deadline. Our Riyadh team will outline a practical CRFR/MVC plan - fees scoped on discovery. Call +966 531 446 716 or email info@cyberintech.com.

Contact CyberInTech
Scroll to Top