GRADUM
    FeaturesMaturity ModelsFor CreatorsPricingBlogCompareSupport
    DashboardSign Up Free
    Blog/Compare/EN 1090 vs SAMA CSF
    Standards Comparison

    EN 1090 vs SAMA CSF

    EN 1090

    Mandatory
    2009

    European standard for steel/aluminium structural execution and CE marking

    VS

    SAMA CSF

    Mandatory
    2017

    Saudi regulatory framework for financial cybersecurity.

    Quick Verdict

    EN 1090 ensures CE-marked structural steel/aluminium compliance for EU construction, while SAMA CSF mandates cybersecurity maturity for Saudi financial institutions. Fabricators adopt EN 1090 for market access; banks use SAMA CSF for regulatory resilience and threat defense.

    Structural Metalwork

    EN 1090

    EN 1090 Execution of steel and aluminium structures

    Cost
    €€€€
    Complexity
    High
    Implementation Time
    6-12 months

    Key Features

    • Enables mandatory CE marking via FPC certification
    • Risk-based Execution Classes (EXC1-4) scaling controls
    • Factory Production Control with notified body surveillance
    • Technical rules for welding, tolerances, corrosion protection
    • Declaration of Performance for structural components
    Cybersecurity

    SAMA CSF

    SAMA Cyber Security Framework Version 1.0

    Cost
    €€€€
    Complexity
    High
    Implementation Time
    6-12 months

    Key Features

    • Six-level maturity model with Level 3 baseline
    • Four domains including third-party cybersecurity
    • Principle-based controls across 114+ subcontrols
    • Board oversight and independent CISO mandate
    • Alignment with NIST, ISO 27001, PCI-DSS

    Detailed Analysis

    A comprehensive look at the specific requirements, scope, and impact of each standard.

    EN 1090 Details

    What It Is

    EN 1090 is a harmonized European standard family (EN 1090-1/2/3) for execution and conformity assessment of steel and aluminium structural components under the Construction Products Regulation (CPR). It enables CE marking through a risk-based framework scaling requirements via Execution Classes (EXC1-4).

    Key Components

    • **EN 1090-1Conformity assessment, Factory Production Control (FPC) certification by notified bodies.
    • **EN 1090-2/3Technical rules for steel/aluminium (welding per ISO 3834, tolerances, corrosion protection, NDT).
    • Core: Traceability, personnel qualification, Declaration of Performance (DoP), ongoing surveillance.

    Why Organizations Use It

    • Mandatory for EU market access of load-bearing components.
    • Reduces liability, ensures safety via risk-proportional controls.
    • Builds trust, enables high-risk projects (bridges, stadia), competitive edge through certification.

    Implementation Overview

    Phased: gap analysis, FPC build, welding quals, NB certification (3-12 months). Applies to fabricators EU-wide; requires audits, training, digital traceability.

    SAMA CSF Details

    What It Is

    The Saudi Arabian Monetary Authority Cyber Security Framework (SAMA CSF), Version 1.0 (May 2017), is a mandatory regulatory framework for SAMA-regulated financial institutions in Saudi Arabia, including banks, insurers, and finance companies. It adopts a principle-based, risk-oriented approach with a maturity model to ensure detection, resistance, response, and recovery from cyber threats, focusing on information assets' confidentiality, integrity, and availability.

    Key Components

    • Four main **domainsCyber Security Leadership & Governance, Risk Management & Compliance, Operations & Technology, Third-Party Cyber Security.
    • Numerous subdomains with principles, objectives, and control considerations (114+ subcontrols).
    • Six-level maturity model (0: Non-existent to 5: Adaptive), baseline at Level 3.
    • Aligned with NIST CSF, ISO 27001, PCI-DSS; self-assessment via questionnaire, SAMA audits.

    Why Organizations Use It

    • Mandatory compliance avoids fines, audits, operational halts.
    • Enhances resilience, efficiency, reduces incidents; strategic edge in partnerships.
    • Builds stakeholder trust, supports Vision 2030 digital growth.

    Implementation Overview

    • **Phased roadmapInitiation/gap analysis, risk assessment, design/deployment, operate/audit.
    • Applies to all sizes in Saudi finance; iterative self-assessments, no external certification.

    Key Differences

    AspectEN 1090SAMA CSF
    ScopeExecution and conformity of steel/aluminium structuresCybersecurity governance, risk, operations, third-party
    IndustryConstruction, fabrication (EU/EEA)Financial sector (Saudi Arabia only)
    NatureHarmonized technical standard, CE marking mandatoryMandatory regulatory framework, maturity-based compliance
    TestingFPC certification, notified body audits/surveillanceSelf-assessments, SAMA audits, maturity level reviews
    PenaltiesMarket exclusion, no CE marking, legal liabilityFines, license suspension, supervisory actions

    Scope

    EN 1090
    Execution and conformity of steel/aluminium structures
    SAMA CSF
    Cybersecurity governance, risk, operations, third-party

    Industry

    EN 1090
    Construction, fabrication (EU/EEA)
    SAMA CSF
    Financial sector (Saudi Arabia only)

    Nature

    EN 1090
    Harmonized technical standard, CE marking mandatory
    SAMA CSF
    Mandatory regulatory framework, maturity-based compliance

    Testing

    EN 1090
    FPC certification, notified body audits/surveillance
    SAMA CSF
    Self-assessments, SAMA audits, maturity level reviews

    Penalties

    EN 1090
    Market exclusion, no CE marking, legal liability
    SAMA CSF
    Fines, license suspension, supervisory actions

    Frequently Asked Questions

    Common questions about EN 1090 and SAMA CSF

    EN 1090 FAQ

    SAMA CSF FAQ

    You Might also be Interested in These Articles...

    Measuring NIST CSF 2.0 Success: KPIs, Dashboards, and Continuous Improvement Using Tiers & Profiles

    Measuring NIST CSF 2.0 Success: KPIs, Dashboards, and Continuous Improvement Using Tiers & Profiles

    Transform NIST CSF 2.0 into quantifiable success: Define board-ready KPIs for Functions, build Profile dashboards, track Tier progression. Prove ROI amid cyber

    CMMC Sustainment Mastery: Continuous Monitoring, Annual Affirmations, and Subcontractor Flow-Down Playbook

    CMMC Sustainment Mastery: Continuous Monitoring, Annual Affirmations, and Subcontractor Flow-Down Playbook

    Master CMMC sustainment beyond certification: continuous monitoring dashboards, SPRS/eMASS affirmations, enforceable subcontractor clauses. Get templates for ve

    Why the SEC Stepped In: The Investor-Driven Push for Cybersecurity Transparency

    Why the SEC Stepped In: The Investor-Driven Push for Cybersecurity Transparency

    Discover why the SEC's 2023 cybersecurity rules treat cyber risks as material financial threats. Explore the 'stick and carrot' approach for standardized disclo

    Run Maturity Assessments with GRADUM

    Transform your compliance journey with our AI-powered assessment platform

    Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.

    100+ Standards & Regulations
    AI-Powered Insights
    Collaborative Assessments
    Actionable Recommendations

    Explore More Comparisons

    See how EN 1090 and SAMA CSF compare against other standards

    Other EN 1090 Comparisons

    • EN 1090 vs NERC CIP
    • EN 1090 vs GRI
    • EPA vs EN 1090
    • SQF vs EN 1090
    • ISO 14001 vs EN 1090

    Other SAMA CSF Comparisons

    • GDPR vs SAMA CSF
    • COPPA vs SAMA CSF
    • CIS Controls vs SAMA CSF
    • MLPS 2.0 (Multi-Level Protection Scheme) vs SAMA CSF
    • ISO 27017 vs SAMA CSF
    GRADUM

    Transform your assessment process with collaborative, AI-powered maturity evaluations that deliver actionable insights.

    Navigation

    FeaturesMaturity ModelsFor CreatorsPricing

    Legal

    Terms and ConditionsPrivacy PolicyImprintCopyright PolicyCookie Policy

    © 2026 Gradum. All Rights Reserved