Home / Services / Aramco CCC Implementation 2026
100% Remote · SACS-210 Feb 2026 · General Requirements

Aramco CCC Implementation 2026 — Certify Your Existing Infrastructure.

For renewals, BYOD, and existing suppliers. We assess your current environment against SACS-210 (TPC1.1–TPC1.33), remediate the gaps remotely, customize your compliance documents to your actual tools, and manage the authorized audit — without replacing what you already own.

From SAR 11,999 · VAT Inclusive 1–2 Months Typical Remediation Until Closure

Free automated Gap Report within 24 hours · Email address only · KSA hours Sun–Thu 9:00–17:00

Qualification

Is Implementation Right for Your Company?

Built For

  • CCC renewals — your certificate is expired or expiring and your environment needs re-alignment
  • BYOD — you want to certify your own devices, servers, and network instead of buying new ones
  • Existing suppliers — your current domain and employee mailboxes must pass SACS-210
  • Companies with existing IT assets — identity, endpoint, email, or firewall already in place and needing configuration to the standard

May Not Be the Right Fit If…

  • You are a first-time applicant without an IT environment and prefer a shipped, isolated compliance setup → Aramco CCC Kit
  • You need a brand-new certified workstation environment with zero internal IT involvement → Aramco CCC Kit
  • Your classification is beyond General Requirements (Network Connectivity, Critical Data Processor, Cloud Computing, OT) — those require a separate assessment
15+
CCC Certificates Delivered
100%
Audit Pass Rate
1–2
Months Typical Delivery
100%
Remote Implementation
Price Anchoring

The Alternative: Interpreting SACS-210 Alone

Without This Service

  • Translate 33 legal-style controls into technical configurations yourself
  • Draft policies that auditors reject because they don't match your actual tools
  • Produce evidence without knowing the auditor's screenshot and timestamp expectations
  • Coordinate the audit firm, licensing vendors, and trainers as separate projects
  • Absorb re-audit cost and contract delays if a control is flagged

With This Service

  • One fixed implementation fee from SAR 11,999
  • Documents customized to your existing stack — not generic templates
  • Evidence produced the way authorized auditors expect it
  • Missing licenses or hardware quoted transparently at partner pricing — never forced
  • We remediate flagged controls until closure — 25% held until your CCC is issued
Methodology

Four Phases. One Certificate.

Typical delivery: 1–2 months for technically ready environments.

1

Assess Days 1–7

Comprehensive gap assessment across all five SACS-210 domains and the 33 mandatory controls, plus a technical questionnaire of your current stack.

2

Plan Days 8–14

A detailed remediation roadmap and resource plan: what to configure, what to license, what to document — with a fixed quote before work begins.

3

Implement Weeks 3–6

Remote configuration of your existing environment, customized Core SACS-210 documents, evidence production, and staff awareness training.

Certify Weeks 6–8

Audit preparation, submission, and full coordination with the authorized audit firm — with remediation support until every finding is closed.

Free · Automated · No CR Required

Know Your Gaps Before You Spend a Riyal

Complete the TPCS 2026 assessment questionnaire and receive an automated Gap Analysis Report mapped to the General Requirements (TPC1.1–TPC1.33). Where a gap is indicated, the report outlines the associated risk and a high-level remediation action. Where all answers are compliant, the control is marked compliant.

  • Email address only — no Commercial Registration or sensitive data needed at this stage
  • Automated report within 24 hours with risks and remediation recommendations
  • Your fixed quote is confirmed after the assessment — no surprises later
Take the Free Assessment

What the Report Covers

GOVERN — policies, AUP, onboarding/offboarding
IDENTIFY — asset inventory & ownership
PROTECT — IAM, MFA, encryption, endpoint & email
DETECT — audit logging per Appendix C
RESPOND — 24-hour incident notification per Appendix A
Scope of Work

Everything Your Environment Needs to Pass

Customized to your existing infrastructure — never generic templates.

01

Customized Core SACS-210 Documents

Policies, procedures, forms, registers, reports, and letters written to match your actual tools and environment — mapped to TPC1.1–TPC1.33 without conflicting with the controls.

02

Remote Technical Remediation

Configuration of your existing identity, endpoint, email, firewall, and logging controls to the standard — identity federation, MFA enforcement, GPO hardening, macro blocking, NTP, and more.

03

Audit-Ready Evidence Production

Timestamped, domain-visible screenshots, configuration exports, and logs produced exactly the way authorized audit firms expect them — highlighted and readable.

04

Security Awareness Training

Role-based awareness training delivered online for one month, with completion records that satisfy the personnel training requirements of the standard.

05

Authorized Audit Management

We prepare the submission and coordinate the entire assessment. We can contract the authorized audit firm on your behalf — Seven Technologies or your preferred Aramco-authorized auditor.

06

Partner-Priced Recommendations

Where gaps require licenses or hardware you don't own, we recommend and quote them transparently at partner rates — as a licensed Microsoft CSP and certified security partner — never as a forced bundle.

Evidence-first engineering: Every configuration, document, and recommendation exists because a specific piece of evidence is required by the authorized audit firm.
Legitimate N/A handling: Controls that genuinely do not apply are documented through the official inapplicability process — never left blank.
Auditors & Partnerships

Partner Pricing on Any Required Quote

As a certified security partner, any licenses or subscriptions your gaps require are quoted at competitive partner rates. We work with Aramco-authorized CCC auditing firms.

Seven Technologies
Authorized Auditor
Microsoft
CSP Partner
Bitdefender
MSP Gold Partner
Fortinet
Authorized
Acronis
Certified
Advisera
Training
Social Proof

Existing Environments, Certified.

Saudi companies that certified their own infrastructure — renewals, BYOD, and existing domains.

"They configured our existing Microsoft 365 tenant and on-prem systems to SACS-210 without replacing anything we already owned. The customized policies matched our actual tools, and we passed on the first attempt."

A

Ahmed Shapat

IT Manager · Arabian Gannas

"Our CCC was due for renewal and our environment had drifted. NHR ran the gap assessment, closed every finding remotely, and managed the auditor end-to-end. Renewal completed in six weeks."

A

Abdulhameed Alahmed

General Manager · Taqam Almustaqbal

"Transparent pricing — the implementation fee was fixed after the free assessment, and the only extras were licenses we chose to add at their partner rates. Exactly as promised."

A

Aamer Khan

Procurement Head · Ozone Cool Trading

Pricing & Quote

Fixed Fee. Confirmed After Your Free Assessment.

The price increases only when your infrastructure is chaotic or missing required licenses — and you know the exact figure before signing.

General Requirements TPC1.1–TPC1.33

Audit fees & required licenses billed separately or added to your quote

SAR 11,999 starting · VAT inclusive

Base implementation fee at the agreed scope

  • Gap assessment, roadmap & fixed quote
  • Customized Core SACS-210 documents
  • Remote technical remediation & evidence production
  • Awareness training (online, 1 month)
  • Audit coordination & remediation until closure

Payment Milestones (at base price)

Advance

9,000

75% · with P.O. / SoW signature

Success

2,999

25% · upon obtaining your CCC

Remediation Until Closure

If the auditor flags any control within the agreed scope, we remediate it until closed. Your final payment is held until your CCC is issued.

Have a Question? Send It Now

Reply within 2 business days · KSA hours Sun–Thu 9:00–17:00

Protected with anti-spam controls.

Full Confidentiality

Your name, email, and message are used only to answer your inquiry — never shared with third parties.

SSL Secured Saudi Licensed VAT Compliant
Objections Handled

Frequently Asked Questions

Everything Saudi companies ask about certifying their existing infrastructure.

Kit vs Implementation: Which One Is Right?

Feature CCC Kit Implementation
Best forFirst-time applicantsRenewals / BYOD / existing domain
InfrastructureNew, shipped & isolatedYour existing environment
DocumentsStandardized suiteCustomized to your stack
PriceSAR 55,000 fixedFrom SAR 11,999
Timeline~30 days1–2 months

Can you work with the tools we already own?

Yes — that is the core of this service. We customize your compliance documents and configure your existing identity, endpoint protection, email security, firewall, and logging controls to SACS-210. Where a gap requires a tool you don't own, we recommend options and quote them at partner pricing, but the choice remains yours.

Do we need to buy new hardware or licenses?

Only if your gap assessment shows a control that cannot be met with your current assets. Any required licenses or hardware are billed separately or added to your quote transparently — as a licensed Microsoft CSP and certified partner, you receive competitive rates, never a forced bundle.

Will the audit be remote, and who manages the auditor?

The assessment is conducted remotely via secure screen sharing, screenshots, and document review. We prepare the submission and manage all auditor communications. We can contract the authorized audit firm on your behalf — for example Seven Technologies — or coordinate with your preferred Aramco-authorized auditor. Auditor fees are billed separately or added to your quote.

How long does implementation take?

Typically 1–2 months for technically ready environments. The exact timeline depends on the gaps identified in your free assessment — environments missing core controls (identity, logging, email security) take longer, and your fixed quote and plan confirm both price and schedule before signing.

What happens if the auditor flags a control?

We remediate it until closed, within the agreed scope. Your final 25% payment is held until your CCC is issued, so our incentive is aligned with yours: the certificate.

Is the gap assessment really free? What do we need to provide?

Yes, completely free. At this stage we only need your email address — no Commercial Registration or sensitive data. You receive an automated Gap Analysis Report within 24 hours outlining risks and high-level remediation actions for any indicated gaps.

Our CCC is expiring — is this the right service for renewal?

Yes. Renewals are a primary use case. We assess how far your environment has drifted from SACS-210, close the gaps remotely, update your documents and evidence, and manage the re-audit before your current certificate expires.

What is the difference between SACS-002 and SACS-210?

SACS-210 replaced SACS-002 as the applicable Third Party Cybersecurity Standard. Many older guides and quotations still reference the obsolete SACS-002 and will not satisfy the current audit. This service is engineered entirely against the current SACS-210 control set.

Your Infrastructure Is an Asset.Let's Get It Certified.

Start with the free gap assessment. Know your risks, your remediation plan, and your fixed price — before you commit to anything.

From SAR 11,999 1–2 Months Typical Remediation Until Closure
Start Free Gap Assessment

Automated report within 24 hours · Email address only · KSA working hours Sun–Thu