Group CCC Authorized Audit Firms for Aramco and SABIC Suppliers
Download the five-page English PDF published for the unified Group Cybersecurity Compliance Certification program. It lists 17 authorized audit firms and their contact details.
One Group CCC Program for a Shared Supplier Network
SABIC's official Group CCC page explains that its previous CyberTrust program transitioned into the Cybersecurity Compliance Certification program as part of unification efforts with Saudi Aramco. The program supports cybersecurity assurance across the companies' shared supplier network.
This page is a focused audit-firm reference. For the wider certification requirements, process and supplier context, read our Aramco CCC certification guide.
View the official SABIC Group CCC pageWhat the download contains
- 17 authorized audit firms listed in the Group CCC document.
- Five pages of company and representative contact information.
- English-language PDF suitable for procurement and IT teams.
The 17 Firms Listed in the Group CCC Document
Names are reproduced from the attached official document. Contact names, email addresses and phone numbers remain in the PDF.
- 1Moore JFC Technologies W.L.L
- 2Cipher
- 3Crowe Saudi Arabia
- 4Defense Cybersecurity Company
- 5Deloitte & Touche Advisory Saudi Limited
- 6Seven Technologies
- 7Saudi Information Technology Company (SITE)
- 8RSM Saudi Arabia
- 9KPMG
- 10BDO Dr. Mohamed Al-Amri Co.
- 11Managed Service Co
- 12Shanghai InsightSec Network Technology Co., Ltd.
- 13Shanghai Symphony Telecommunications Co., Ltd. (SST)
- 14Baker Tilly Professional Services
- 15Grant Thornton
- 16Trusted Partners
- 17Cybrani
Why another public list may show fewer firms
The attached document is the 17-firm list published for the unified Group CCC program through SABIC Supplier Portal. A standalone Saudi Aramco public CCC page may display a shorter list. Before signing an audit engagement, confirm the accepted firm for your supplier classification and scope through the relevant portal or requesting entity.
Implementation Support and Independent Audit Are Different Roles
NHR Alemtithal
Supports readiness and implementation: current SACS-210 controls, technology configuration, policies, evidence preparation and audit coordination. NHR Alemtithal does not issue the CCC.
Authorized Audit Firm
Performs the independent assessment and handles the formal audit and certification output within the applicable Group CCC process.
What to Confirm Before Contracting an Audit Firm
- The firm is accepted for the relevant customer, portal and supplier engagement.
- Your supplier classification and assessment scope are clearly stated.
- Availability, lead time, audit stages and required evidence are understood.
- The quotation and any re-assessment charges are documented.
- Secure communication and evidence-transfer methods are agreed.
NHR Alemtithal does not rank or endorse one listed audit firm over another.
Typical Certification Path
- 1
Confirm applicability and scope
Identify the customer requirement and supplier classification.
- 2
Implement controls and prepare evidence
Address technical and governance gaps before the formal assessment.
- 3
Select and contract an authorized firm
Confirm current acceptance, scope, availability and commercial terms.
- 4
Complete the assessment and submit the output
Follow the applicable Group CCC process and customer instructions.
Choose the Right CCC Readiness Path
Use the auditor list for the independent assessment stage. Use the option below that matches your implementation starting point.
Starting from zero
Explore the CCC Turnkey Kit for a new, separated environment.
View the Turnkey KitExisting IT environment
Remediate gaps and prepare your current environment for the audit.
View CCC ImplementationNeed the full context
Read the main guide to requirements, process and supplier decisions.
Read the CCC GuideFrequently Asked Questions
Is this the same PDF published by SABIC Supplier Portal?
Yes. The download linked on this page is the same five-page English PDF available through SABIC Supplier Portal's official Group CCC page.
How many firms are included in the Group CCC document?
The attached five-page Group CCC document lists 17 authorized audit firms and provides representative contact details.
Why can Saudi Aramco's standalone public page show a different number?
The attached document is the 17-firm list published for the unified Group CCC program through SABIC Supplier Portal, while a standalone Saudi Aramco public page may display a shorter list. Confirm the accepted firm for your specific engagement through the relevant portal or requesting entity before contracting.
Did Group CCC replace SABIC CyberTrust?
Yes. SABIC's official Group CCC page states that the previous CyberTrust program transitioned into CCC as part of the unification efforts between Saudi Aramco and SABIC.
Can NHR Alemtithal issue the CCC?
No. NHR Alemtithal supports implementation, evidence preparation and audit readiness. The independent assessment and formal certification output must follow the applicable Group CCC process through an accepted authorized audit firm.
What should we confirm before appointing an audit firm?
Confirm that the firm is currently accepted for the relevant customer and supplier scope, then verify availability, audit stages, evidence requirements, fees, re-assessment terms and secure communication methods.
How long is a Group CCC certificate valid?
The official Group CCC page states that a certificate is valid for two years from its issue date. If a new engagement has a classification not covered by the current certificate, an additional certificate may be required.