The Saudi Aramco Cybersecurity Compliance Standard (SACS) sets the cybersecurity requirements that third parties must meet to work with Aramco. For suppliers it is a commercial gate, not an optional certification: if you connect to Aramco systems, handle its data, or deliver services into its environment, compliance is a condition of doing business.
Why it exists
Large operators of critical infrastructure inherit the weaknesses of their suppliers. A contractor with poor access control or an unpatched remote-access route becomes a path into an environment where the consequences are national in scale. SACS pushes a defined security baseline out to the supply chain rather than trusting that each supplier has one.
Who it applies to
- Contractors and service providers delivering into Aramco operations.
- Vendors whose systems connect to or exchange data with Aramco environments.
- Providers of software, cloud or managed services used by Aramco.
- Organisations working in or adjacent to industrial and operational technology environments.
Requirements are typically tiered by how deeply you are connected and how sensitive the data or systems involved are. Confirm your applicable tier through your Aramco contracting contact - do not assume the lightest one applies.
The control themes to expect
SACS aligns with the broader Saudi regulatory direction - the NCA Essential Cybersecurity Controls and related standards - and with international practice. Prepare for requirements across:
- Governance - documented policies, defined ownership, risk management.
- Identity and access - strong authentication, privileged access control, joiner-mover-leaver discipline, tightly controlled remote access.
- Asset and configuration management - a real inventory, hardened baselines, patching within defined timeframes.
- Data protection - classification, encryption in transit and at rest, controlled handling of Aramco data.
- Network security and segregation - especially separation between corporate IT and any operational technology.
- Logging, monitoring and incident response - with notification obligations to Aramco.
- Business continuity - tested recovery, not merely documented plans.
- Your own supply chain - the subcontractors behind you.
Assess your supplier readiness
GRC Copilot assesses you against Aramco SACS and reuses the evidence from your ISO 27001 or NCA ECC work - so you can answer supplier cybersecurity requirements without starting over.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
How it differs from a standard security questionnaire
- It is contractual. Falling short can affect eligibility, not just your score.
- Evidence is expected, not self-declaration alone.
- It reaches into operational technology where generic IT questionnaires stop.
- It is periodic. Compliance is maintained through the relationship, not proven once at onboarding.
Preparing as a supplier
- Confirm your applicable requirements and tier in writing through your contracting channel.
- Scope precisely - which of your systems, people and sites touch Aramco work.
- Run a gap assessment against the applicable controls.
- Prioritise remote access, privileged accounts and segregation - the areas of greatest concern for a critical-infrastructure customer.
- Build the evidence pack as controls operate, rather than assembling it when asked.
- Reuse what you already have. ISO 27001 or NCA ECC evidence maps across a large portion of the requirements.
- Assign an owner for ongoing compliance and reassessment.
Requirements, tiers and documentation are issued and updated by Aramco. Treat this article as orientation and confirm the current, applicable version through your official contracting channel before committing to a remediation plan.
Frequently asked questions
Does ISO 27001 certification satisfy SACS?
Not on its own, but it covers a substantial share of the underlying controls and gives you the evidence discipline. Expect additional requirements specific to connectivity, data handling and operational technology.
We are a small supplier - does it still apply?
Requirements are scaled by connection depth and data sensitivity rather than supplier size. A small vendor with privileged remote access can face significant requirements.
How does it relate to the NCA ECC?
The ECC is the national baseline; SACS is a customer-imposed standard for Aramco's supply chain that aligns with the national direction. Many suppliers address both from one control set.
How often is compliance reassessed?
Periodically through the relationship, and typically on trigger events such as a change in the service or a security incident. Build for continuous evidence rather than a one-off submission.
Key takeaways
- SACS is a commercial gate for Aramco suppliers, not an optional certification.
- Requirements scale with connectivity and data sensitivity, not company size.
- Remote access, privileged accounts and IT/OT segregation attract the most scrutiny.
- ISO 27001 and NCA ECC evidence maps across much of the requirement set.