Cybersecurity
Regulatory compliance, governance and assessment work for organisations operating under Saudi cybersecurity requirements.
Cybersecurity
These five services overlap by design. A regulatory programme rests on governance, governance is tested by assessment, and an information security management system carries the evidence for all of them. Most engagements begin in one and draw on the others.
- Aramco CCC & CCC+ ComplianceGap assessment, remediation and evidence preparation against Aramco SACS-210 cybersecurity requirements.
- NCA, SAMA & CST ComplianceAlignment with the national and sector cybersecurity frameworks that apply to your organization.
- Cybersecurity GRC ConsultingGovernance, risk and compliance structures your team can operate day to day.
- Cybersecurity Assessment & AuditIndependent assessment, internal audit and readiness review ahead of a formal audit.
- ISO 27001 Information SecurityISMS design and implementation aligned with ISO/IEC 27001:2022, through to certification readiness.
Not sure which applies to you?
One control set,
several regulators
Most organisations in Saudi Arabia are not facing a single cybersecurity requirement. A company supplying Saudi Aramco meets SACS-210 through the Cybersecurity Compliance Certificate programme. A financial institution answers to SAMA. A licensed communications or IT service provider answers to the Communications, Space and Technology Commission. A government-linked entity answers to the National Cybersecurity Authority's controls. The frameworks overlap heavily, and the practical work is to build one control environment that satisfies all the ones that apply to you.
Aramco CCC and CCC+ preparation begins from the Third Party Classification agreed with Aramco and the sponsoring department, because the classification decides which SACS-210 controls are in scope and whether the assessment is a self-assessment with remote verification or a full on-site assessment. From there the work is gap assessment, risk treatment, policies, technical remediation and evidence an assessor can trace. The formal assessment and the certificate come from an Aramco-authorised audit firm.
NCA, SAMA and CST compliance is approached the same way: a gap and maturity assessment against the applicable framework, a cybersecurity risk assessment, governance documents people can actually follow, control implementation and remediation, and an evidence pack organised for audit. Where several frameworks apply, controls are mapped once and evidenced once rather than maintained in parallel.
Cybersecurity GRC consulting is what keeps that in place after the audit — a governance framework, a risk register that is reviewed rather than filed, policies and procedures, third-party cybersecurity risk management, KPIs and KRIs, executive reporting, and continuing advisory support where there is no in-house security leadership. Cybersecurity assessment and audit provides the independent view: internal audit, readiness review and control testing ahead of a formal assessment.
ISO/IEC 27001 sits in this group rather than beside the other ISO standards, because an information security management system built to ISO/IEC 27001:2022 carries much of the evidence the Saudi frameworks ask for. For an organisation facing several requirements at once, it is often the most economical place to start.
The organisations we work with usually arrive from one of three directions: a buyer has made a certificate a condition of continuing to supply, a regulator has set a deadline, or an assessment has already produced findings that need closing. The starting point differs; the work is the same control environment, built so the next requirement does not start from nothing.
Cost and duration depend on the frameworks in scope, the size and complexity of the environment, how much governance already exists in writing, and whether remediation is needed before an assessment can realistically be attempted. We scope after the gap assessment rather than before it, because a figure quoted earlier than that is a guess presented as a quotation.
Nour Solutions prepares organisations for assessment. Certification bodies, authorised audit firms and regulators carry out the assessments and issue the certificates, and compliance outcomes remain theirs to determine.
How a compliance engagement runs
Scope and classification
We establish which frameworks apply, which systems, data and connections are in scope, and — for Aramco work — which classification and therefore which SACS-210 controls you are assessed against.
Gap and risk assessment
Current policies, processes and technical controls are measured against the applicable requirements, and the gaps are prioritised by risk rather than listed in the order the standard happens to use.
Remediation and documentation
Governance documents, procedures and technical controls are implemented or corrected, with the control-to-evidence mapping built as the work is done rather than reconstructed before the audit.
Readiness and assessment support
A control-by-control internal review is run ahead of the formal assessment, remaining gaps are closed, and we support the assessment itself and the closure of any findings.
Before you start,
the usual questions
What is Aramco CCC, and who needs it?
The Cybersecurity Compliance Certificate programme verifies an applicable third party's cybersecurity compliance against Aramco's SACS-210 standard. The scope depends on the Third Party Classification agreed with the Aramco department you work with. CCC uses a self-assessment followed by remote verification; CCC+ requires an on-site assessment and currently applies to specified higher-assurance classifications.
Does Nour Solutions issue the CCC certificate?
No. We prepare the organisation: scope, gap assessment, remediation, documentation, evidence and readiness review. The formal assessment and certificate issuance are handled by an Aramco-authorised audit firm, which keeps the consultancy and the independent assessment properly separate.
We fall under more than one framework. Does that mean separate projects?
Usually not. The NCA, SAMA, CST and SACS-210 control sets share a large proportion of their intent. We map the applicable requirements onto one control environment, implement once and evidence once, then produce the framework-specific views each regulator or buyer expects to see.
What is the difference between a gap assessment and an audit?
A gap assessment measures where you are against a requirement so the work can be planned. An audit or assessment tests whether implemented controls operate and whether the evidence supports them. Most engagements begin with the first and use the second as a readiness check before a formal assessment.
Do we need ISO 27001 if we already have a regulatory programme?
Not necessarily, but it is often worth it. ISO/IEC 27001 puts a management system around the programme — scope, risk treatment, internal audit, management review — and produces evidence that Saudi regulators and major buyers already recognise. Whether it earns its cost depends on who is asking you for what.
Can you provide ongoing support rather than a one-off project?
Yes. GRC advisory, including virtual CISO support, covers risk register upkeep, policy review, third-party risk, metrics, executive reporting and the re-assessment cycle. Compliance is a recurring obligation, and a programme maintained only before an audit tends to fail the one after it.
What does a readiness review actually test?
Each applicable control is reviewed against the documentation, the configuration and the evidence, in the form an assessor will ask for it. The common finding is not a missing control but a control that is implemented and cannot be demonstrated — a difference that only appears when somebody asks for the record.
Let's Talk About
Your Requirement.
Tell us where you are today and we will set out the practical route from here — scope, sequence and what your team needs to provide.