ISO 26000 vs SAMA CSF
ISO 26000
International guidance standard for social responsibility integration
SAMA CSF
Saudi framework for financial sector cybersecurity.
Quick Verdict
ISO 26000 offers voluntary global guidance on social responsibility for all organizations, emphasizing principles and stakeholder engagement. SAMA CSF mandates cybersecurity maturity for Saudi financial firms, requiring structured controls and audits. Companies adopt ISO 26000 for ethical leadership; SAMA CSF for regulatory compliance.
ISO 26000
ISO 26000:2010 Guidance on social responsibility
Key Features
- Explicitly non-certifiable guidance avoiding compliance burdens
- Seven principles underpinning all responsible decisions
- Seven holistic core subjects spanning governance to community
- Stakeholder engagement drives contextual prioritization
- Universal applicability across all organization types
SAMA CSF
Saudi Arabian Monetary Authority Cyber Security Framework
Key Features
- Six-level maturity model targeting Level 3 minimum
- Four core domains with detailed subdomains
- Board-level governance and CISO requirements
- Principle-based risk management approach
- Third-party security and payment systems controls
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
ISO 26000 Details
What It Is
ISO 26000:2010 is a non-certifiable international guidance standard on social responsibility (SR). It provides a conceptual framework and practical advice for organizations to address impacts on society and environment through transparent, ethical behavior. Applicable universally, it uses a holistic, stakeholder-informed approach emphasizing context-specific prioritization over rigid requirements.
Key Components
- Seven principles: Accountability, transparency, ethical behavior, respect for stakeholder interests, rule of law, international norms, human rights.
- Seven core subjects: Organizational governance, human rights, labor practices, environment, fair operating practices, consumer issues, community involvement.
- Built on multi-stakeholder consensus; no auditable requirements, rejecting certification.
Why Organizations Use It
Enhances sustainability commitment, risk management, and stakeholder trust. Aligns with SDGs, OECD, GRI; reduces reputational/legal risks; boosts resilience, talent attraction, market access without certification costs.
Implementation Overview
Phased PDCA cycle: materiality assessment, stakeholder engagement, policy integration, training, reporting. Suits all sizes/sectors; embed in existing systems like ISO 14001/45001; transparent communication via ISO protocols.
SAMA CSF Details
What It Is
The Saudi Arabian Monetary Authority Cyber Security Framework (SAMA CSF), Version 1.0 (May 2017), is a mandatory regulatory framework for SAMA-regulated financial institutions in Saudi Arabia. It prescribes principle-based, outcome-oriented controls across governance and operations to detect, resist, respond to, and recover from cyber threats, using a risk-based maturity model.
Key Components
- Four main domains: Cyber Security Leadership and Governance, Risk Management and Compliance, Operations and Technology, Third-Party Cyber Security.
- Numerous subdomains with principles, objectives, and control considerations.
- Six-level maturity model (minimum Level 3: structured/formalized).
- Aligned with NIST, ISO 27001, PCI-DSS; enforced via self-assessments and SAMA audits.
Why Organizations Use It
- Mandatory compliance for banks, insurers, etc., avoiding fines and scrutiny.
- Enhances resilience, reduces incidents, improves efficiency.
- Builds trust, enables partnerships, supports Vision 2030 digital growth.
Implementation Overview
- Phased: initiation/gap analysis, risk assessment, design/deployment, operate/monitor, audit/improve.
- Targets financial sector in Saudi Arabia; all sizes via maturity scaling.
- Requires self-assessments; no external certification but SAMA review.
Key Differences
| Aspect | ISO 26000 | SAMA CSF |
|---|---|---|
| Scope | Social responsibility: 7 core subjects (governance, human rights, environment, etc.) | Cybersecurity: 4 domains (governance, risk mgmt, operations, third-party) |
| Industry | All organizations globally, all sectors/sizes | Saudi financial institutions (banks, insurance, fintech) |
| Nature | Voluntary guidance, non-certifiable | Mandatory regulation with maturity levels |
| Testing | Self-assessment, stakeholder engagement, no formal audits | Periodic self-assessments, SAMA audits, maturity model reviews |
| Penalties | No legal penalties, reputational risks only | Fines, license suspension, regulatory enforcement |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about ISO 26000 and SAMA CSF
ISO 26000 FAQ
SAMA CSF FAQ
You Might also be Interested in These Articles...

NIST CSF 2.0 Implementation Tiers Roadmap: Step-by-Step Guide from Partial to Adaptive Cybersecurity Maturity
Master NIST CSF 2.0 Implementation Tiers with a step-by-step roadmap. Assess your tier, build gap analyses, and advance from Partial (Tier 1) to Adaptive (Tier

NIST CSF 2.0 Supply Chain Risk Management: Complete Playbook with Profiles, Tiers, and Vendor Assessment Templates
Master NIST CSF 2.0 ID.SC supply chain risk management with vendor assessment templates, profile gap analysis, and tier strategies. Mitigate third-party threats

SEC Cybersecurity Rules Implementation Guide: Mastering Form 8-K Item 1.05 Materiality Determination and 4-Business-Day Reporting Workflow
Master SEC Form 8-K Item 1.05 compliance with step-by-step materiality assessment, incident workflows & Inline XBRL tagging. Beat the 4-business-day clock. Esse
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Explore More Comparisons
See how ISO 26000 and SAMA CSF compare against other standards