Aramco Cybersecurity Compliance Certificate

Aramco CCC

What it is

The Cybersecurity Compliance Certificate (CCC) Saudi Aramco requires from its third parties, showing they meet its Third Party Cybersecurity Standard.

What it covers

  1. 01General requirements
  2. 02Outsourced infrastructure
  3. 03Customized software
  4. 04Cloud computing
  5. 05Network connectivity
  6. 06Operational technology
  7. 07Critical data processing

How we help

  • Classification check
  • Readiness assessment
  • Evidence pack
  • Support through the audit firm’s review

In depth

Each contract is matched to one or more classifications, and the certificate must cover them. For the CCC, you assess yourself and an audit firm authorized by Aramco verifies remotely; the CCC+ adds an on-site assessment. A certificate is valid for two years, and a new contract with a classification it does not cover needs a new one.

The certificate is issued by the authorized audit firm. We get you ready for that review — the right classifications, the controls in place and the evidence organized — so it passes the first time.

Related services

Other frameworks we work with

Ready to meet Aramco CCC?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Trust

Built around the regulators you answer to

SAMA
Saudi Central BankCSF · BCM · CRFR
NCA
National Cybersecurity AuthorityECC-2:2024 · CSCC · CCC
SDAIA
Saudi Data & AI AuthorityPDPL
CMA
Capital Market AuthorityCSG
CST
Communications, Space & Technology CommissionCRF
14regulatory frameworks

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment