Get Aramco CCC and CCC+ certified, and stay on the vendor list.
We guide you from first assessment to final certificate under Saudi Aramco's Third-Party Cybersecurity Standard (SACS-002), then keep you compliant for renewal.
Cybersecurity compliance is now a condition of doing business with Aramco.
Saudi Aramco requires its suppliers, contractors and service providers to meet the Saudi Aramco Third-Party Cybersecurity Standard, known as SACS-002. Vendors prove compliance with a Cybersecurity Compliance Certificate (CCC), or the stricter CCC+ for those with deeper access to Aramco systems and data. Without a valid certificate you cannot bid, renew or keep many existing contracts.
The standard is detailed and the certification audit is strict. Most companies fail on the same things: missing policies, weak access control, untested backups and no evidence trail. Matrix Analytica runs the whole journey for you. We assess where you stand, fix the gaps, build the evidence, and prepare you for the audit carried out by an Aramco-approved audit firm.
Why companies struggle to get certified
Lost contracts and bids
Without a valid certificate, procurement can stop your registration, renewals and new tenders until you comply.
A long, technical control list
Over a hundred controls cover policies, people, networks, endpoints, data and suppliers. Each one needs evidence.
Failed or delayed audits
Gaps found during the audit mean corrective actions, re-audits and months of lost time.
End-to-end support, from scoping to certificate
Scoping and classification
We review the services you provide to Aramco and confirm whether you need CCC or CCC+, and which systems, sites and people are in scope.
Gap assessment
We assess your ICT environment against every applicable SACS-002 control and score each one: compliant, partial or missing.
Remediation roadmap
A prioritised, costed plan that tells you what to fix first, who owns it and how long it should take.
Policies and procedures
We write or rework the full policy set: information security, access control, acceptable use, incident response, backup, business continuity, asset and supplier management.
Technical implementation
Hands-on help with multi-factor authentication, endpoint protection, patching, logging, email security, secure configuration and network segmentation.
Penetration testing and vulnerability assessment
External and internal testing to find weaknesses before the auditor does, with a clear report and re-test after fixes.
Security awareness training
Short, practical training for your staff, with attendance records you can present as audit evidence.
Audit preparation and support
We assemble the evidence pack, run a mock audit, coordinate with the approved audit firm and support you through to certificate.
Which certificate do you need?
| Certificate | Typical vendor | What it means for you |
|---|---|---|
| CCC | General IT services, cloud services, custom software development, and vendors with limited system access | The core set of controls. A strong baseline that most suppliers can reach with focused remediation. |
| CCC+ | Vendors handling critical data processing or with network connectivity to Aramco | A deeper control set and stricter evidence requirements. Plan more time for technical controls and testing. |
Your classification depends on the services in your Aramco contract. We confirm it in the free scoping call.
Five steps to your certificate
Free scoping call
We learn which services you provide to Aramco, confirm CCC or CCC+, and agree what is in scope.
Gap assessment
Interviews, document review and technical checks against each control. You get a gap report and a scored baseline.
Remediation
We close the gaps with you: policies written, controls configured, penetration test run and issues fixed.
Pre-audit review
A mock audit against the full standard. We check every piece of evidence before the auditor sees it.
Certification and renewal
We support the formal audit and submission, then track your certificate expiry and keep controls current for renewal.
What you receive
- Scoping and classification report
- Control-by-control gap assessment
- Prioritised remediation roadmap
- Complete, approved policy and procedure set
- Penetration test report and re-test results
- Security awareness training records
- Organised audit evidence pack
- Renewal calendar and compliance checklist
Built for vendors in the Aramco supply chain
Common questions
What is SACS-002?
SACS-002 is the Saudi Aramco Third-Party Cybersecurity Standard. It sets out the cybersecurity controls that Aramco's suppliers and contractors must meet to protect Aramco's systems and data.
Do we need CCC or CCC+?
It depends on the services you provide. Vendors with critical data processing or network connectivity to Aramco usually need CCC+. Most other IT, cloud and software vendors need CCC. We confirm this in the free scoping call.
Who issues the certificate?
The certification audit is carried out by an Aramco-approved audit firm. We prepare you, assemble the evidence and coordinate with the auditor, so the audit goes smoothly.
How long does it take?
It depends on how many gaps you have. A company with good basics moves faster than one starting from scratch. After the gap assessment we give you a realistic timeline for your case.
How long is the certificate valid?
Certificates are valid for two years. We track your expiry date and help you keep controls and evidence current so renewal is straightforward.
We failed an audit. Can you help?
Yes. We review the audit findings, build a corrective action plan and help you close each finding before the re-audit.
Often paired with Aramco CCC Certification
Every week without certification is a contract you can't bid on.
Book a free readiness call. We'll confirm your certificate type and tell you exactly what stands between you and the audit.