Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
SACS-002
A third-party cybersecurity standard setting security requirements for suppliers and contractors in the Saudi energy supply chain.
SACS-002, the Saudi Aramco Third Party Cybersecurity Standard, is a contractual security standard issued by Saudi Aramco in 2022. It sets baseline cybersecurity requirements for third parties, including suppliers, contractors and service providers, that connect to Saudi Aramco networks, handle its data, or provide products and services that could affect its operations. It is a mandatory condition of doing business with Saudi Aramco rather than a government law.
The standard organises requirements into control profiles that scale with the nature of the engagement, covering areas such as governance, data protection, connectivity and, where relevant, the security of manufactured or connected products and industrial control environments. Third parties are expected to demonstrate compliance, often through self-assessment and independent certification, before and during their contractual relationship.
Implement the set of controls corresponding to the risk tier of the engagement with Saudi Aramco.
Apply safeguards for any Saudi Aramco data handled and for connections into its environment.
Provide assessment evidence and required certification before and during the contract.
Address the security of manufactured or connected products and control systems relevant to the engagement.
Read more
Anove scans your stack against SACS-002 and 260+ other frameworks in minutes.