WhatsApp +971 55 274 9815KSA +966 58 200 2658info@matrixanalytica.ukSun–Thu · 8 AM–5 PM
Cybersecurity compliance

Get Aramco CCC and CCC+ certified, and stay on the vendor list.

We guide you from first assessment to final certificate under Saudi Aramco's Third-Party Cybersecurity Standard (SACS-002), then keep you compliant for renewal.

SACS-002Aramco third-party standard
111Controls: 24 common + 87 specific
2 yearsCertificate validity
250+Cybersecurity implementations
Overview

Cybersecurity compliance is now a condition of doing business with Aramco.

Saudi Aramco requires its suppliers, contractors and service providers to meet the Saudi Aramco Third-Party Cybersecurity Standard, known as SACS-002. Vendors prove compliance with a Cybersecurity Compliance Certificate (CCC), or the stricter CCC+ for those with deeper access to Aramco systems and data. Without a valid certificate you cannot bid, renew or keep many existing contracts.

The standard is detailed and the certification audit is strict. Most companies fail on the same things: missing policies, weak access control, untested backups and no evidence trail. Matrix Analytica runs the whole journey for you. We assess where you stand, fix the gaps, build the evidence, and prepare you for the audit carried out by an Aramco-approved audit firm.

The challenge

Why companies struggle to get certified

Risk 01

Lost contracts and bids

Without a valid certificate, procurement can stop your registration, renewals and new tenders until you comply.

Risk 02

A long, technical control list

Over a hundred controls cover policies, people, networks, endpoints, data and suppliers. Each one needs evidence.

Risk 03

Failed or delayed audits

Gaps found during the audit mean corrective actions, re-audits and months of lost time.

What's included

End-to-end support, from scoping to certificate

Scoping and classification

We review the services you provide to Aramco and confirm whether you need CCC or CCC+, and which systems, sites and people are in scope.

Gap assessment

We assess your ICT environment against every applicable SACS-002 control and score each one: compliant, partial or missing.

Remediation roadmap

A prioritised, costed plan that tells you what to fix first, who owns it and how long it should take.

Policies and procedures

We write or rework the full policy set: information security, access control, acceptable use, incident response, backup, business continuity, asset and supplier management.

Technical implementation

Hands-on help with multi-factor authentication, endpoint protection, patching, logging, email security, secure configuration and network segmentation.

Penetration testing and vulnerability assessment

External and internal testing to find weaknesses before the auditor does, with a clear report and re-test after fixes.

Security awareness training

Short, practical training for your staff, with attendance records you can present as audit evidence.

Audit preparation and support

We assemble the evidence pack, run a mock audit, coordinate with the approved audit firm and support you through to certificate.

CCC or CCC+

Which certificate do you need?

CertificateTypical vendorWhat it means for you
CCCGeneral IT services, cloud services, custom software development, and vendors with limited system accessThe core set of controls. A strong baseline that most suppliers can reach with focused remediation.
CCC+Vendors handling critical data processing or with network connectivity to AramcoA deeper control set and stricter evidence requirements. Plan more time for technical controls and testing.

Your classification depends on the services in your Aramco contract. We confirm it in the free scoping call.

How we work

Five steps to your certificate

  1. Free scoping call

    We learn which services you provide to Aramco, confirm CCC or CCC+, and agree what is in scope.

  2. Gap assessment

    Interviews, document review and technical checks against each control. You get a gap report and a scored baseline.

  3. Remediation

    We close the gaps with you: policies written, controls configured, penetration test run and issues fixed.

  4. Pre-audit review

    A mock audit against the full standard. We check every piece of evidence before the auditor sees it.

  5. Certification and renewal

    We support the formal audit and submission, then track your certificate expiry and keep controls current for renewal.

Deliverables

What you receive

  • Scoping and classification report
  • Control-by-control gap assessment
  • Prioritised remediation roadmap
  • Complete, approved policy and procedure set
  • Penetration test report and re-test results
  • Security awareness training records
  • Organised audit evidence pack
  • Renewal calendar and compliance checklist
Who it's for

Built for vendors in the Aramco supply chain

IT service providersCloud and SaaS vendorsSoftware developersEngineering contractorsConstruction and maintenance firmsLogistics providersConsultanciesCompanies renewing an expiring CCC
FAQ

Common questions

What is SACS-002?

SACS-002 is the Saudi Aramco Third-Party Cybersecurity Standard. It sets out the cybersecurity controls that Aramco's suppliers and contractors must meet to protect Aramco's systems and data.

Do we need CCC or CCC+?

It depends on the services you provide. Vendors with critical data processing or network connectivity to Aramco usually need CCC+. Most other IT, cloud and software vendors need CCC. We confirm this in the free scoping call.

Who issues the certificate?

The certification audit is carried out by an Aramco-approved audit firm. We prepare you, assemble the evidence and coordinate with the auditor, so the audit goes smoothly.

How long does it take?

It depends on how many gaps you have. A company with good basics moves faster than one starting from scratch. After the gap assessment we give you a realistic timeline for your case.

How long is the certificate valid?

Certificates are valid for two years. We track your expiry date and help you keep controls and evidence current so renewal is straightforward.

We failed an audit. Can you help?

Yes. We review the audit findings, build a corrective action plan and help you close each finding before the re-audit.

Free consultation

Every week without certification is a contract you can't bid on.

Book a free readiness call. We'll confirm your certificate type and tell you exactly what stands between you and the audit.

Emailinfo@matrixanalytica.uk
WhatsApp+971 55 274 9815
KSA+966 58 200 2658