Driving SAMA CSF maturity from Level 2 to Level 3 by Adil ShahzadDriving SAMA CSF maturity from Level 2 to Level 3 by Adil Shahzad

Driving SAMA CSF maturity from Level 2 to Level 3

 Adil Shahzad

Adil Shahzad

SAMA CSF compliance driven from Level 2 to Level 3

Control mapping, policy and audit readiness that moved a regulated payments environment up a full maturity level.
Who it was for: A SAMA-regulated payments company on Google Cloud.
The problem. The regulator expects maturity Level 3 across multiple control domains. The stack was live, the audit clock was running, and controls existed in practice but couldn't be demonstrated on demand.
What I did. Mapped each control to the specific cloud services and configurations implementing it. Ran a gap analysis against the framework, then built the change-management policy, security architecture documentation and IAM access-review cycle needed to close what was missing. Packaged it as an evidence pack an assessor can open.
The result. Maturity moved from Level 2 toward Level 3 with evidence on hand per domain, plus a prioritised remediation roadmap for what remains.
Like this project

Posted Aug 6, 2026

Control mapping, policy and audit readiness that moved a regulated payments environment up a full maturity level.