SAMA CRFR and MVC for Fintech Cybersecurity - Saudi Arabia
SAMA CRFR and MVC are the cyber requirements many Saudi fintechs must meet before and during licensing - Cyber Resilience Fundamental Requirements (CRFR) for sandbox and licence readiness, and Minimum Verification Controls (MVC) for e-wallet, lending, crowdfunding and related fintech models under SAMA supervision. CyberInTech helps you turn those requirements into working controls, gap registers, and sampleable evidence from Riyadh.
Answer first: what buyers need
If you are preparing a sandbox application, a licence file, or a bank/partner questionnaire that cites CRFR or MVC, start with a scoped gap assessment, then close gaps with owners and proof - not policy theatre.
Engagement highlights
- CRFR and/or MVC gap assessment
- Sandbox and pre-licence readiness
- Evidence pack for questionnaires
- Bridge to SAMA CSF maturity
What is SAMA CRFR (Cyber Resilience Fundamental Requirements)?
CRFR is SAMA's Cyber Resilience Fundamental Requirements - a prioritised set of cyber security and resilience controls for entities that are recently established or early in their financial-sector operations in Saudi Arabia.
Per SAMA's Rulebook (in force; dated Gregorian 1/1/2022):
- Who it applies to: entities intending to qualify for the SAMA Regulatory Sandbox and/or entities seeking a licence to operate in the Kingdom.
- Purpose: help those entities meet minimum cyber resilience licensing requirements without treating CRFR as a full substitute for later frameworks.
- Relationship to CSF / BCM: CRFR must not be treated as a replacement for SAMA's Cyber Security Framework (CSF) and Business Continuity Management Framework (BCMF). After licensing, entities remain subject to those (and other) SAMA requirements.
- Domains (structure): control requirements organised around cyber security leadership and governance, operations and technology, and resilience (including BCP/DRP and backup themes). Official control IDs and wording are in the SAMA Rulebook publication - we map your engagement to that text.
- Compliance consequence: if an entity cannot demonstrate compliance with the Fundamental Requirements, SAMA reserves the right to prohibit sandbox graduation / licence request.
In buyer language: CRFR is the pre-licence / sandbox cyber bar. Passing it does not mean you are done with SAMA CSF maturity once you are licensed.
What is SAMA MVC (Minimum Verification Controls)?
MVC is SAMA's Minimum Verification Controls (Version 1.0, September 2021) - not "Minimum Viable Cybersecurity Controls." The name refers to mandatory verification and security controls for digital fintech services.
Per SAMA's published MVC document:
- Who it applies to: any member organisation that provides e-wallet, lending products, crowdfunding, or other fintech business models under SAMA supervision, taking applicability into account against the stated objectives.
- Structure: Registration/Onboarding Controls; General Controls; Lending Application Special Controls (additional for lending companies).
- Themes buyers will recognise: secure registration and identity validation, device/application binding, OTP and MFA, session and fraud controls, official app-store distribution, jailbreak/root restrictions, backups/contingency, SMS notifications, board-approved internal policies reflecting MVC, and lending-specific checks where applicable.
MVC sits alongside other SAMA cybersecurity requirements. Exact control wording and any circular values follow current SAMA text and memos.
Who must comply (sandbox, pre-licence, licensed fintechs)?
CRFR typically bites before full licensed CSF depth: sandbox applicants and licence seekers. MVC typically bites for licensed / supervised fintech models in e-wallet, lending, crowdfunding and related categories. Many programmes need both at different stages.
Regulatory Sandbox
Fintechs preparing sandbox operational readiness, including cyber and technology criteria assessed by SAMA.
Licence seekers
Applicants who must show minimum cyber resilience before a SAMA licence.
Supervised models
E-wallet, lending, crowdfunding and similar models that must implement MVC.
Bank / partner asks
Teams answering questionnaires that ask for CRFR/MVC-aligned evidence.
Confirm your exact regulatory status with counsel and current SAMA guidance. Scope is not one-size-fits-all.
How CRFR and MVC relate to the SAMA CSF
| Instrument | Stage / role | Relationship to CSF |
|---|---|---|
| CRFR | Sandbox qualification and/or licence seeking - minimum cyber resilience | Aligned in structure/content with CSF and BCMF themes; not a replacement post-licence |
| MVC | Operating fintech models (e-wallet, lending, crowdfunding, other) under SAMA | Complements broader SAMA cybersecurity requirements; model-specific verification controls |
| SAMA CSF | Licensed / member-organisation cyber maturity programme | Primary long-term cyber framework; maturity Level 3+ is the baseline objective in the CSF maturity model |
Practical programme design: use CRFR to clear the entry bar, implement MVC for product/channel verification, then build toward CSF maturity (often Level 3 as the stated minimum objective). Deep-dive: SAMA CSF consulting.
What a fintech must prepare
You need operable controls and evidence - not a PDF folder of templates.
Scope clarity
Sandbox vs licence vs licensed model; which product lines (wallet, lending, crowdfunding, other).
Governance pack
Cyber roles, policies/procedures/standards, risk register, board or management approval trail.
Identity and access
IAM, MFA, password standards, privileged access.
Secure build and ops
Network segmentation, cryptography, patching, endpoint protection, change management, secure SDLC / app shielding where CRFR applies.
Testing evidence
Vulnerability assessment; penetration testing cadence where CRFR requires (CRFR cites PT at least twice yearly or after major/critical change).
Monitoring and incident
Logging (CRFR cites minimum one-year retention), SIEM integration, incident process, SAMA notification paths where required.
Resilience
BCP/DRP, backups and restoration tests.
MVC-specific and evidence index
Onboarding/verification flows, OTP/MFA/transaction controls, fraud use cases, lending specials if applicable, plus configs, tickets, test reports and ownership records reviewers can sample.
Prefer a structured first step? Start with a cybersecurity gap assessment.
How CyberInTech helps
We map your current state to applicable CRFR and/or MVC controls, produce a risk-ranked remediation roadmap, and support policies, technical uplift, and an evidence pack your team can defend - you keep ownership.
Gap assessment
Against applicable CRFR domains/controls and/or MVC sections.
Remediation roadmap
Sequenced by licence/sandbox deadline and operational risk.
Policy and control artefacts
Aligned to how you actually operate.
Technical and process uplift
With your engineering and ops teams.
Evidence pack
For self-assessment, SAMA sampling, or partner questionnaires.
CSF bridge
Align CRFR work toward full CSF maturity so you do not rebuild twice.
Who this is not for
- Buyers who only want a logo or policy pack with no control or evidence work
- Anyone expecting a guaranteed "SAMA pass," maturity certificate, or licence approval we cannot honestly promise
- Scopes that legally require a specialist licence we do not hold - we say so and help you route
- General IT support with no regulatory fintech angle - see Managed IT
Typical engagement flow
Discovery
Sandbox / licence / licensed-model status, product lines, deadlines, systems, owners.
Assess
CRFR and/or MVC mapping, evidence sampling, CSF linkages where relevant.
Findings workshop
Plain-language gaps for founders and control owners.
Remediate
Sequenced fixes with owners and success criteria.
Evidence pack
Index and coaching for self-assessment, SAMA review, or partner ask.
Deliverables
Typical set (confirmed on discovery):
- CRFR / MVC gap register mapped to controls in scope
- Prioritised remediation roadmap with owners
- Policy and control artefacts as scoped
- Evidence checklist / pack for readiness
- Clear list of technical and process actions still open
FAQ
What does CRFR stand for?
Cyber Resilience Fundamental Requirements - SAMA's fundamental cyber security and resilience control set for sandbox qualification and/or licence-seeking entities in Saudi Arabia's financial sector. Official text is published in the SAMA Rulebook.
What does MVC stand for?
Minimum Verification Controls (SAMA, Version 1.0, September 2021). It is not "Minimum Viable Cybersecurity Controls." It applies to e-wallet, lending, crowdfunding and other fintech models under SAMA supervision, as stated in the official document.
Do sandbox fintechs need CRFR, MVC, or both?
Sandbox and licence seekers typically focus on CRFR and sandbox operational-readiness criteria. MVC applies to supervised fintech models such as e-wallet, lending and crowdfunding. Many journeys need CRFR first, then MVC and CSF as the business licences and scales.
Does CRFR replace the SAMA Cyber Security Framework?
No. SAMA states CRFR should not be treated as a replacement for the Cyber Security Framework and Business Continuity Management frameworks. Post-licensing, relevant CSF/BCM and other requirements still apply.
What should we prepare before a CRFR or MVC gap assessment?
Entity and product scope, architecture diagrams, current policies, access and logging posture, recent vulnerability and penetration test reports if any, BCP/DRP and backup evidence, and named owners.
How long does a CRFR/MVC readiness engagement take?
It depends on product complexity, starting maturity, and whether remediation is in the same engagement. Many teams start with a focused gap assessment, then remediate in phases. CyberInTech gives a realistic timeline after discovery.
Can you help with bank questionnaires that ask for CRFR/MVC evidence?
Yes - with control and evidence work behind the answers. Questionnaire copy without operable proof rarely satisfies serious banking partners.
Are you a SAMA-approved or accredited consultant?
CyberInTech does not claim to be a regulator, certification body, or approved/accredited/licensed consultant by default. Any registration relevant to a scoped activity is confirmed on discovery.
Related pages
Next step
Tell us whether you are in sandbox, pre-licence, or licensed fintech status, your product model (wallet, lending, crowdfunding, other), and any deadline. Our Riyadh team will outline a practical CRFR/MVC plan - fees scoped on discovery. Call +966 531 446 716 or email info@cyberintech.com.
Contact CyberInTech