Saudi Aramco CCC (SACS-002) Compliance

Saudi Aramco CCC

Keep bidding on Aramco work

Aramco’s third-party cybersecurity standard, SACS-002, decides whether you stay on the vendor list. We assess you against it, close the gaps, and take you through the certification assessment.

SACS-002
the standard
CCC & CCC+
both achieved with a client
Gap → assessment
one team throughout
What it is

A supplier requirement, enforced commercially

The Cybersecurity Compliance Certificate — and its higher CCC+ level — is issued under SACS-002, Saudi Aramco’s cybersecurity standard for third parties. Suppliers are assessed by an authorised certifying body, and the certificate becomes a condition of doing business.

  • Which control set applies depends on how you connect to and handle Aramco data and systems
  • It covers governance, access control, network security, endpoint protection, logging, incident response, third-party risk and physical security
  • Assessment is carried out by an authorised certifying body, not by Aramco directly
  • Without it, contract awards and renewals stall — which is usually why the deadline is short
  • Much of the underlying control work maps to ISO 27001, so the two are worth planning together
How we run it

Assessed, remediated, certified

1. Applicability

Establishing which classification and control set applies to you, based on your connectivity and the data you hold. This decides the size of the whole engagement.

2. Gap assessment

Every applicable control assessed against your real environment, with findings rated and owned, and an honest timeline.

3. Remediation

Identity and access, segmentation, hardening, endpoint, logging and monitoring, backup, incident response. We implement it — we are an infrastructure and security company, not only assessors.

4. Documentation

Policies, procedures and records built to the evidence the certifying body will ask for.

5. Certification assessment

We prepare your team, attend, answer the technical questions and manage the corrective actions.

6. Staying certified

Renewal comes round, and environments drift. We keep the controls and the evidence current.

Before you ask

Common questions

How long does it take?

It depends almost entirely on the applicable control set and the state of your current environment. The gap assessment gives you a real answer within weeks rather than a guess.

We already hold ISO 27001. Does it shorten things?

Yes, considerably. The management system and much of the technical control work carries across; the effort goes into the Aramco-specific requirements and the evidence.

Can you issue the certificate?

No. An authorised certifying body does. We get you ready and stand with you through their assessment.

Our deadline is tight. Is it worth starting?

Almost always. Even where the date slips, a documented remediation plan in progress is a very different conversation with a customer than nothing at all.

Do not let the certificate decide the contract.

Call and we will tell you honestly how far away you are, and whether the deadline is reachable.

02 3537 5791