The CyberTrust Program Overview
The CyberTrust Program is designed to ensure that all third parties comply with SABIC's cybersecurity requirements. This initiative has been established to ensure the adherence of SABIC's third parties to the cybersecurity standards specified in the Third Party CyberTrust Cybersecurity Standard.
Program Scope
Certification under the CyberTrust Program is mandatory for both new and existing suppliers who fall under specific classifications, as detailed in the table below. Furthermore, any supplier with access to SABIC data is required to undergo this certification process.
Certificates are valid for two years from the issue date. However, if the engagement involves a cybersecurity classification not covered in the current valid certificate, an additional certificate must be obtained and submitted.
List of Authorized Audit Firms and contact information:
CyberTrust Authorized Audit Firms List
Downloads:
SABIC CyberTrust StandardSABIC CyberTrust GuidelinesSABIC CyberTrust Supplier ManualSABIC CyberTrust Report Template
Frequently Asked Questions:
- What is the objective of SABIC CyberTrust Program?
The program aims to certify suppliers’ compliance with the SABIC CyberTrust Standard to protect against cybersecurity threats and strengthen their cybersecurity posture
- What is the validity of SABIC CyberTrust Certificate, and when to renew it?
Certificates are valid for two years from the issue date and must be renewed before expiry.
- I’m not included in any of the specific categories, do I need to obtain the certification?
If you are not included in specific categories but having access to SABIC data, obtaining the SABIC CyberTrust certificate for General Requirements is mandatory. Otherwise, it is voluntary to demonstrate commitment to cybersecurity.
- Do I need to obtain a new certificate each time I bid for a new contract?
If the scope of the engagement aligns with the existing certification classification, it is not required to obtain a new certificate. However, if the engagement falls outside the current certification classification, it is necessary to obtain certification for the additional controls relevant to the identified classification.
- Which audit firm should be chosen to conduct the assessment?
You can choose any audit firm from the list of authorized audit firms. You need to sign a contract with the authorized audit firm prior to assessment verification
- How do I submit the certificate once obtained from the audit firm?
You need to submit the SABIC CyberTrust Certificate along with SABIC CyberTrust Report at CyberTrust@sabic.com