SACS-210 Self-Assessment for Aramco CCC Readiness
Answer 33 focused questions aligned with the SACS-210 2026 General Requirements, TPC1.1–TPC1.33, and receive an automated preliminary readiness report immediately by email.
What You Receive in the Instant Report
The report converts your answers into a practical starting point for prioritizing SACS-210 work before formal evidence review and audit verification.
Readiness Overview
An initial view of your organization’s alignment with the SACS-210 General Requirements, based on the answers submitted.
Control-Level Findings
A status for every assessed control, with potential risks highlighted where an answer indicates a gap or uncertainty.
Recommended Next Actions
High-level remediation suggestions to help you organize priorities and decide whether to remediate internally or request implementation support.
What the SACS-210 Self-Assessment Covers
The questionnaire is structured around all 33 General Requirements, from TPC1.1 through TPC1.33. The topics below are grouped for easier navigation and do not replace the official control wording.
Governance, Policies and People
Governance responsibilities, documented policies, awareness, employee lifecycle controls and regulatory obligations.
Identity, Access and Endpoints
Account administration, authentication, access reviews, endpoint protection, secure configuration and update management.
Email, Network and Data Protection
Business email and domain safeguards, network protection, secure data handling, encryption and controlled information sharing.
Logging and Incident Response
Security logging, monitoring responsibilities, access revocation and incident notification and response arrangements.
Need the full certification context, control scope and audit process?
Read the complete Aramco CCC and SACS-210 guideHow the Assessment Works
The 33-question assessment is normally completed in 5–10 minutes by an IT manager, technical lead or another person familiar with your current environment.
Answer the Questionnaire
Select the answer that best reflects the controls currently implemented in your organization.
The Report Is Generated Automatically
The workflow maps your answers to each assessed control and prepares the corresponding status, potential risks and high-level recommendations.
Receive the Report by Email
The automated report is sent immediately to the email address entered in the form. Normal email delivery delays or spam filtering may occasionally apply.
Start Your Free Assessment
The questionnaire opens in Microsoft Forms. Use a business email address that you can access to receive the generated report.
Start the Free AssessmentAutomated report sent immediately by email
What the Result Does—and Does Not—Confirm
This NHR Alemtithal assessment is a preliminary planning tool based solely on the answers you provide. It helps identify possible gaps and priorities, but it does not inspect configurations, validate evidence or confirm formal compliance.
- Use the report to organize internal remediation and decide your next step.
- It is not the official Third Party Cybersecurity Compliance Report.
- It does not replace evidence preparation or verification by an Aramco-authorized audit firm.
- It does not issue or guarantee a CCC certificate.
Review Aramco’s current requirements and authorized audit process before making a formal submission. View the official Aramco CCC program.
Choose the Right Next Step
Your best route depends on whether you are starting from zero, improving an existing environment or preparing evidence for an upcoming audit.
Starting from Zero
For a first-time applicant that needs a new, isolated environment for the General Requirements.
Explore the CCC Turnkey KitUsing an Existing Environment
For an organization that wants to assess and remediate its current identity, devices, email and security systems.
Review CCC ImplementationPreparing for Verification
For a supplier approaching authorized verification and needing to organize evidence and close common readiness gaps.
Use the Audit Readiness ChecklistFrequently Asked Questions
Common questions about the free preliminary SACS-210 self-assessment and its instant report.
Is this the official Saudi Aramco CCC self-assessment?
No. This is a free preliminary tool from NHR Alemtithal. The formal CCC process requires the official compliance report, supporting evidence and verification by an Aramco-authorized audit firm.
Does the assessment cover all 33 SACS-210 General Requirements?
Yes. The questionnaire is structured around TPC1.1 through TPC1.33. Its result remains preliminary because it is based on your answers and does not validate configurations or supporting evidence.
What does the generated report include?
The report provides an initial summary and, for each assessed control, a response-based status, potential risks where a gap or uncertainty is indicated, and high-level remediation recommendations.
How quickly will I receive the report?
The automated report is generated and sent immediately after submission to the email address entered in the form. If it does not appear, allow for normal email delivery delays and check the spam or junk folder.
Who should complete the assessment, and how long does it take?
It is best completed by an IT manager, technical lead or another person familiar with the organization’s users, devices, email, network and security practices. The 33 questions normally take 5–10 minutes.
Are my answers automatically sent to Aramco or an audit firm?
No. The described workflow uses Microsoft Forms and Power Automate to generate and email your report; it does not automatically submit your answers or report to Saudi Aramco or an authorized audit firm.
What should I do if the report identifies gaps?
Review the findings by priority and decide whether your team can remediate them internally. If you need a new isolated environment, consider the CCC Turnkey Kit. If you want to improve existing systems, use the CCC Implementation service before arranging authorized verification.