Keep bidding on Aramco work
Aramco’s third-party cybersecurity standard, SACS-002, decides whether you stay on the vendor list. We assess you against it, close the gaps, and take you through the certification assessment.
A supplier requirement, enforced commercially
The Cybersecurity Compliance Certificate — and its higher CCC+ level — is issued under SACS-002, Saudi Aramco’s cybersecurity standard for third parties. Suppliers are assessed by an authorised certifying body, and the certificate becomes a condition of doing business.
- Which control set applies depends on how you connect to and handle Aramco data and systems
- It covers governance, access control, network security, endpoint protection, logging, incident response, third-party risk and physical security
- Assessment is carried out by an authorised certifying body, not by Aramco directly
- Without it, contract awards and renewals stall — which is usually why the deadline is short
- Much of the underlying control work maps to ISO 27001, so the two are worth planning together
Assessed, remediated, certified
1. Applicability
Establishing which classification and control set applies to you, based on your connectivity and the data you hold. This decides the size of the whole engagement.
2. Gap assessment
Every applicable control assessed against your real environment, with findings rated and owned, and an honest timeline.
3. Remediation
Identity and access, segmentation, hardening, endpoint, logging and monitoring, backup, incident response. We implement it — we are an infrastructure and security company, not only assessors.
4. Documentation
Policies, procedures and records built to the evidence the certifying body will ask for.
5. Certification assessment
We prepare your team, attend, answer the technical questions and manage the corrective actions.
6. Staying certified
Renewal comes round, and environments drift. We keep the controls and the evidence current.
Common questions
How long does it take?
It depends almost entirely on the applicable control set and the state of your current environment. The gap assessment gives you a real answer within weeks rather than a guess.
We already hold ISO 27001. Does it shorten things?
Yes, considerably. The management system and much of the technical control work carries across; the effort goes into the Aramco-specific requirements and the evidence.
Can you issue the certificate?
No. An authorised certifying body does. We get you ready and stand with you through their assessment.
Our deadline is tight. Is it worth starting?
Almost always. Even where the date slips, a documented remediation plan in progress is a very different conversation with a customer than nothing at all.
Do not let the certificate decide the contract.
Call and we will tell you honestly how far away you are, and whether the deadline is reachable.
02 3537 5791
