Skip to content
Aramco
The Cybersecurity Compliance Certificate (CCC) aims to ensure Third Party compliance with cybersecurity requirements.
CCC Portal: Automate Compliance, Accelerate Security Response

The Cybersecurity Compliance Certificate (CCC) was established to ensure all Aramco Group companies’ Third Parties are in compliance with the cybersecurity requirements as outlined in the Third Party Cybersecurity Standard (SACS-210). All Third Parties are required to obtain the Cybersecurity Compliance Certificate (CCC).

How to get certified

Complete the following steps in order to obtain your Cybersecurity Compliance Certificate (CCC):

STEP 1: Certification Requirements Preparation

  • 1.1. In order for a Third Party to obtain a CCC certificate, the Third Party is required to register in the Supplier Registration Portal through Aramco’s e-Marketplace system 
  • 1.2. Initiate a request with the department/proponent(s) from Aramco, or other Aramco Group company, that your company is conducting business with, to complete the Third Party Classification Template

  • 1.3. Once the Third Party Classification Template is received, the Third Party must fill out and sign the Third Party Classification Confirmation Letter
    • 1.3.1. Implement all applicable cybersecurity controls specified in the Third Party Cybersecurity Standard (SACS-210)
    • 1.3.2. If the company falls under more than one classification, then all the cybersecurity controls under the relevant/applicable classifications are required

Identify the applicable certificate type and assessment requirements:

Company Classification Certificate Type Assessment Approach
  • General Requirements
  • Outsourced Infrastructure
  • Customized Software
  • Cloud Computing
  • Operational Technology
  • Network Connectivity

Cybersecurity Compliance Certificate — CCC

A self-compliance assessment against the Third Party Cybersecurity Standard, completed first by the company, and verified remotely by the Authorized Audit Firm.

  • Critical Data Processor

Cybersecurity Compliance Certificate Plus — CCC+

An on-site compliance assessment against the Third Party Cybersecurity Standard, conducted by the Authorized Audit Firm, is required for Critical Data Processor classification.

STEP 2: Select an Authorized Audit Firm

  • 2.1. Visit the CCC Portal and complete the Third Party registration

  • 2.2. Submit a CCC request to one of the Authorized Audit Firms (see list below)

STEP 3: Compliance Verification & Issuance

  • 3.1. CCC assessment process:
  • 3.1.1. Conduct the CCC compliance assessment
    • Fill out all of the fields in the Third Party Cybersecurity Compliance Report 
    • Ensure the answers are comprehensive and clearly described, and attach all the required supporting documents 
    • Ensure that all the evidence provided is recent, clear, and time stamped, and that proof of its relation to the Third Party is clearly pointed out/highlighted in the screenshots
  • 3.1.2. The selected Authorized Audit Firm will verify the documents and generate the Third Party Cybersecurity Compliance Report
  • 3.2. CCC/CCC+ assessment process:
  • 3.2.1. Submit the completed documents
    • Third Party Classification Template
    • Third-Party Classification Confirmation Letter to the Authorized Audit Firm, prior to the assessment verification
  • 3.2.2. Arrange with the selected Authorized Audit Firm to conduct the compliance assessment in accordance with the applicable certificate type and the assessment requirements stated above
  • 3.2.3. The Authorized Audit Firm will conduct the assessment, generate the Cybersecurity Compliance Report and issue the certificate

STEP 4: Submit the Issued Certificate

  • 4.1. Submit the issued certificate and Compliance Report from the Authorized Audit Firm to Aramco, through the e-Marketplace system

STEP 5: CCC Validity & Renewal

  • 5.1. The CCC will be accepted by Aramco, Sabic, and other Aramco Group companies 
  • 5.2. The CCC is valid for two years from the issuance date
  • 5.2.1. If the company is awarded a new contract that involves a cybersecurity classification type not covered in the current valid certificate, then a new certificate needs to be obtained and submitted
  • 5.2.2. Prior to the end of the two years, your company needs to renew its CCC

Authorized audit firms

The following Authorized Audit Firms have been selected by Aramco Group companies to conduct the assessments and issue the Cybersecurity Compliance Certificate (CCC) against the Third Party Cybersecurity Standard (SACS-210). 

  Company name Email Website

Moore

Moore JFC Technologies W.L.L ccc@moorejfcgroup.com / ojanahi@moorejfcgroup.com / aisa@moorejfcgroup.com www.moorejfcgroup.com

Site

Saudi Information Technology Company (Site) falbedah@site.sa www.site.sa/en

Baker Tilly 01 logo

Baker Tilly infosec@bakertilly.sa http://www.bakertilly.sa
BDO 01 logo BDO/Dr. Mohamed Al-Amri & Co. cybersecurity@bdoalamri.com www.bdoalamri.com
Cyberani 01 logo Cyberani Solutions cs@cyberanisolutions.com https://cyberani.sa
KPMG 01 logo KPMG safmcybersecurity@kpmg.com / fmcybersecurity@kpmg.com https://kpmg.com
seven 01 logo Seven Technologies Fahad.m@sevtechs.com www.sevtechs.com

 

Downloads

SACS-210 Third Party Cybersecurity Standard (NEW:2026)

.pdf

1.2MB

Frequently asked questions

FAQ

Contact us

Inquiries:

For Cybersecurity Incident Notifications:

  • Global Security Operations Center (Aramco): +966 13 880 0000