GRCCopilot
Sign In
Saudi Aramco

Saudi Aramco Cybersecurity Compliance Standard (SACS)

Mandatory cybersecurity standard for all vendors and contractors supplying services or systems to Saudi Aramco

Start Assessment Create Free Account
0
Controls
0
Questions
Active
Status

About this Framework

Saudi Aramco's Cybersecurity Compliance Standard (SACS-002) defines requirements that third-party contractors, vendors and service providers must meet before connecting to Aramco's network. Given Aramco's status as the world's largest oil company and a critical national asset, controls span network security, endpoint protection, access management, incident response and OT/ICS security throughout the supply chain.

Key Control Domains

Governance & Risk Management
Network Security
Endpoint Security
Access Management
Vulnerability Management
Incident Response
OT/ICS Security
Third-Party Management
Security Monitoring

Who Needs This?

  • Vendors and contractors connecting to Aramco networks
  • IT/OT service providers supplying to Saudi Aramco
  • Technology companies in the Saudi energy supply chain

Compliance Benefits

  • Qualification prerequisite for Aramco contracts
  • Reduced supply chain cyber risk
  • Alignment with international OT security standards
  • Demonstrated security posture for energy sector clients

Official Reference

Saudi Aramco Official Site
https://www.aramco.com

Assessment Details

Issuer / AuthoritySaudi Aramco
FrameworkSaudi Aramco Cybersecurity Compliance Standard (SACS)
Controls0
Questions0
StatusActive
Assessment Start08 May 2026

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/saudi-aramco-cybersecurity-compliance-standard-sacs

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.