Aramco Cybersecurity Compliance Certificate
Aramco CCC
What it is
The Cybersecurity Compliance Certificate (CCC) Saudi Aramco requires from its third parties, showing they meet its Third Party Cybersecurity Standard.
What it covers
- 01General requirements
- 02Outsourced infrastructure
- 03Customized software
- 04Cloud computing
- 05Network connectivity
- 06Operational technology
- 07Critical data processing
How we help
- Classification check
- Readiness assessment
- Evidence pack
- Support through the audit firm’s review
In depth
Each contract is matched to one or more classifications, and the certificate must cover them. For the CCC, you assess yourself and an audit firm authorized by Aramco verifies remotely; the CCC+ adds an on-site assessment. A certificate is valid for two years, and a new contract with a classification it does not cover needs a new one.
The certificate is issued by the authorized audit firm. We get you ready for that review — the right classifications, the controls in place and the evidence organized — so it passes the first time.
Related services
Other frameworks we work with
Ready to meet Aramco CCC?
Tell us where you stand. We will show you the shortest path to what your regulator expects.
Built around the regulators you answer to
Ready to talk about your compliance?
Tell us where you stand. We will show you the shortest path to what your regulator expects.