Official Standard

SACS-002 Cybersecurity Standard

The official standard for Saudi Aramco CCC certification.

Secure PDF Download
Official ٍِ}ٍ-002 Standard

Standard Overview

Our download provides the complete and official SACS-002 Third Party Cybersecurity Standard. This document outlines the minimum cybersecurity controls required by Saudi Aramco for all contractors and suppliers.

  • The Complete SACS-002 Standard: The full 26-page document outlining all cybersecurity requirements.
  • General & Specific Controls: Details on the mandatory General Requirements and additional controls for different vendor types.
  • Incident Response Instructions: The official appendix detailing Aramco's mandatory incident reporting protocol.
  • Auditing Event Requirements: The official appendix listing all system events that must be logged for compliance.

Official Aramco Standard

The essential administrative framework provided securely for corporate IT evaluation.

Document Format PDF
Document Length 26 Total Pages
Target Audience Enterprise Executives
Language English

Key Sections in the Standard

A

General Requirements (Section A)

The 23 mandatory controls for all third parties, covering Governance, Access Control, Data Security, and more.

B

Specific Requirements (Section B)

Additional controls for vendors with network connectivity, those processing critical data, or providing cloud services.

C

Appendix A - Incident Response

Detailed, step-by-step Cybersecurity Incident Response Instructions that must be followed.

D

Appendix C - Audit Events

A complete list of all system and security events that must be capable of being audited.

Frequently Asked Questions

Is this the most recently published version of SACS-002?

Who in my organization must read this entire document?

Do the "General Requirements" apply to all suppliers regardless of size?

What is the most critical element of the technical appendices?

Can we use this document as proof of implementation during an audit?