All Posts

Aramco CCC Certification Guide 2026: SACS-210 Requirements, Process & Audit

Last Updated
Aramco CCC certification guide 2026 covering SACS-210 requirements, process and audit

Editor’s Note: This guide has been updated for the Saudi Aramco Third Party Cybersecurity Standard SACS-210 (2026) and is structured as a practical reference for companies preparing for the Cybersecurity Compliance Certificate (CCC).

The Aramco Cybersecurity Compliance Certificate (CCC) verifies that a third party complies with the applicable cybersecurity requirements in Saudi Aramco’s Third Party Cybersecurity Standard (SACS-210). For companies in the supplier-registration phase, Aramco requires compliance with the General Requirements. For standard CCC, the company completes a self-compliance assessment and an Aramco-authorized audit firm verifies it remotely.

This 2026 guide explains who needs CCC, how CCC differs from CCC+, the 33 SACS-210 General Requirements controls (TPC1.1–TPC1.33), the official certification process, audit evidence, certificate validity, common causes of delay, cost considerations, and the implementation options available to Saudi companies.

Aramco CCC certification process under SACS-210 showing preparation, assessment, audit verification and certificate issuance.

Aramco CCC 2026: Key Takeaways

  • Saudi Aramco’s CCC program is based on the SACS-210 Third Party Cybersecurity Standard.
  • During supplier registration, companies are required to meet the General Requirements for CCC.
  • The General Requirements contain 33 controls: TPC1.1 through TPC1.33.
  • Standard CCC uses a self-compliance assessment followed by remote verification by an Aramco-authorized audit firm.
  • CCC+ applies to Direct Network Connectivity and Critical Data Processor classifications and requires an on-site assessment.
  • An issued CCC is valid for two years from the issuance date, subject to Aramco’s classification conditions.
  • Certification requires more than policies: the applicable technical controls must be implemented and supported by clear audit evidence.

What Is Aramco CCC Certification?

The Cybersecurity Compliance Certificate (CCC) is part of Saudi Aramco’s program for verifying third-party compliance with the cybersecurity requirements defined in SACS-210. The certificate is issued through an Aramco-authorized audit firm after the applicable requirements have been assessed and full compliance has been verified.

For companies that are still in the Aramco supplier-registration phase, the starting point is the General Requirements. Companies that already have ongoing business with Aramco may need additional controls depending on their Third Party Classification.

For the official process and current program requirements, refer to Saudi Aramco’s Cybersecurity Compliance Certificate Program.

Who Needs an Aramco CCC?

Saudi Aramco states that all vendors in the registration phase are required to obtain CCC under the General Requirements. For Saudi Arabia-based suppliers, a valid CCC is also listed among Aramco’s supplier-registration requirements.

If your company already has an ongoing purchasing agreement with Aramco, the applicable scope can extend beyond the General Requirements. The relevant Aramco department/proponent completes the Third Party Classification Template, and the company completes the corresponding classification confirmation. If more than one classification applies, the applicable controls across those classifications must be addressed.

If you are currently registering for the first time, read our Aramco Supplier Registration 2026 guide for the registration-specific journey and where CCC becomes a practical bottleneck.

Comparison of Aramco CCC and CCC Plus under SACS-210 including remote and on-site assessment methods.

Aramco CCC vs. CCC+: Which Certificate Applies?

SACS-210 classifications determine both the applicable cybersecurity controls and the assessment method. Under Aramco’s current CCC program, the distinction is:

CertificateClassificationAssessment
CCCGeneral Requirements; Third Party Infrastructure Outsourcing; Customized Software DevelopmentSelf-compliance assessment verified remotely by an Aramco-authorized audit firm
CCC+Direct Network Connectivity; Critical Data ProcessorOn-site compliance assessment by an Aramco-authorized audit firm

For first-time supplier registration: Aramco requires the General Requirements. If your company later receives another cybersecurity classification, additional controls or a different certificate type may apply.

If both CCC and CCC+ classifications apply, Aramco states that only CCC+ will be accepted.

SACS-210 General Requirements framework showing 33 cybersecurity controls from TPC1.1 to TPC1.33 for Aramco CCC.

SACS-210 General Requirements: The 33 Aramco CCC Controls

The SACS-210 General Requirements contain 33 controls, TPC1.1 through TPC1.33. For a General Requirements assessment, the applicable controls must be implemented and supported by evidence that is clear enough for the authorized audit firm to verify.

GOVERN Domain Controls

ControlRequirementTypical Evidence
TPC1.1Legislative and regulatory complianceCompliance register and supporting compliance records
TPC1.2Acceptable Use Policy (AUP)Approved AUP and acknowledgements
TPC1.3Required cybersecurity policiesApproved policy suite covering the required subjects
TPC1.4Employee onboarding and offboarding controlsBackground-check, onboarding, offboarding and asset-return records
TPC1.5Obtain the applicable CCC from an authorized audit firmValid CCC
TPC1.6Renew CCC before expirationCertificate and renewal tracking
TPC1.7Restrict proponent data to contracted personnelAccess restrictions and supporting records

IDENTIFY Domain Controls

ControlRequirementTypical Evidence
TPC1.8Maintain an inventory of information and technology assetsAsset inventory covering applicable hardware, software and data assets

PROTECT Domain Controls

ControlRequirementTypical Evidence
TPC1.9Centralized identity and access management using need-to-know and least privilegeIAM configuration, roles and access records
TPC1.10Unique authentication credentialsUser-account configuration and records
TPC1.11Password requirementsPassword policy and technical configuration evidence
TPC1.12Multi-factor authentication for applicable access scenariosMFA configuration evidence
TPC1.13MFA for initial SSO authenticationSSO and MFA configuration
TPC1.14Periodic user-account and access-right reviewAccess Review Report and supporting records
TPC1.15Secure authentication of third-party technology assetsAuthentication configuration and logs
TPC1.16Secure return and deletion of proponent data at the end of its lifecycleReturn/deletion records and supporting evidence
TPC1.17Secure disposal and sanitization of technology assetsSanitization or disposal evidence
TPC1.18Protect data at rest and in transit using applicable cryptographic requirementsEncryption configuration and policy evidence
TPC1.19Restrict and secure external storage mediaDevice-control configuration and policy evidence
TPC1.20Implement SPF, DMARC and DKIM for emailDNS and mail-authentication records
TPC1.21Inspect incoming internet email for spamEmail-security configuration
TPC1.22Inspect email attachments for malicious contentAnti-malware/email-protection configuration
TPC1.23Use a private business email domainDomain ownership and email configuration
TPC1.24Block applicable Microsoft Office macros from external sourcesEndpoint or Office policy configuration
TPC1.25Synchronize technology assets with an authorized time sourceNTP/time configuration
TPC1.26Protect event logs from unauthorized alteration, destruction or accessLogging configuration and access controls
TPC1.27Enable firewalls on endpoint devicesEndpoint firewall configuration
TPC1.28Protect applicable internet-facing applications using WAF controlsWAF configuration and relevant logs
TPC1.29Maintain up-to-date malware protectionEndpoint-protection status, update and scan evidence
TPC1.30Manage and test security patches and maintain recovery capabilityPatch-management records and recovery evidence

DETECT Domain Controls

ControlRequirementTypical Evidence
TPC1.31Activate audit and cybersecurity event loggingAudit logs and logging configuration

RESPOND Domain Controls

ControlRequirementTypical Evidence
TPC1.32Notify the relevant proponent within the required incident-notification timeframeIncident-response procedure and notification records
TPC1.33Notify the proponent when personnel no longer require applicable credentials/accessAccess-revocation and notification records

Important: The “Typical Evidence” column above is practical guidance, not a substitute for the official SACS-210 standard or the evidence instructions in Aramco’s current compliance-report template. Always use the current official documents for your assessment.

What Evidence Does the Aramco CCC Audit Require?

For standard CCC, the company completes the Third Party Cybersecurity Compliance Report and attaches supporting evidence. Aramco’s published process emphasizes that evidence should be clear, readable, time-stamped, visibly related to the third party, and clearly identified in screenshots.

  • Approved policies, procedures and acknowledgement records.
  • Configuration screenshots showing controls such as MFA, endpoint protection, firewall, email authentication and logging.
  • Registers and reports such as the asset inventory and access-review records.
  • Logs or reports demonstrating that security controls are active.
  • Evidence of employee-related processes, training and applicable operational controls.
  • Classification and compliance-report documentation required for the assessment.

Official Aramco CCC Certification Process

Saudi Aramco’s published CCC process can be summarized in five practical stages:

1. Prepare the Applicable Certification Requirements

For supplier registration, prepare for the General Requirements. Companies with ongoing Aramco business should confirm their Third Party Classification and identify all applicable SACS-210 controls.

2. Implement the Applicable SACS-210 Controls

Deploy the required administrative and technical controls and prepare evidence that demonstrates how each applicable requirement is met.

3. Complete the Self-Compliance Assessment for CCC

For standard CCC, complete the Third Party Cybersecurity Compliance Report and attach the supporting documentation. CCC+ follows the on-site assessment route instead of the standard CCC self-assessment step.

4. Select an Aramco-Authorized Audit Firm

Select a firm from Aramco’s current authorized-auditor list and establish the audit engagement. For CCC, the auditor verifies the submitted assessment remotely. For CCC+, the authorized audit firm performs the assessment on site.

5. Close Findings, Receive the Certificate and Submit It

If the company is not fully compliant, the authorized audit firm identifies the controls that still need implementation. After the findings are addressed and full compliance is verified, the audit firm issues the compliance report and CCC. The issued certificate and compliance report are then submitted to Aramco through the e-Marketplace.

Aramco CCC process showing preparation, self-assessment, authorized audit verification, remediation and certificate submission.

How Long Does Aramco CCC Certification Take?

Aramco’s published CCC process does not specify one universal completion time for every company. Actual duration depends on factors such as the starting condition of your environment, the number of gaps, evidence quality, remediation effort and audit scheduling.

A company with an established security environment may mainly need gap remediation and evidence preparation. A first-time supplier without a controlled environment may need hardware, identity, email, endpoint, logging, documentation and evidence work before the audit can be completed.

NHR delivery model: For first-time applicants that fit our defined General Requirements scope, the NHR Aramco CCC Kit targets audit readiness within 30 days. This is an NHR service target, not an official universal Aramco certification timeline.

How Much Does Aramco CCC Cost?

There is no single implementation price that applies to every company. The commercial cost depends on what your company already has and what must be added or remediated: hardware, endpoint security, cloud identity, email and domain configuration, logging, documentation, evidence preparation, training, implementation support and the authorized audit engagement.

This is why comparing only an auditor’s fee with a turnkey implementation price can be misleading. The audit verifies compliance; it does not automatically build the underlying environment for you.

Current NHR turnkey option: Our defined first-time General Requirements CCC Kit is SAR 55,000 including VAT. It includes two hardened laptops, the required cloud/security environment for the package scope, 17 core compliance documents, security awareness training, audit coordination and agreed audit fees, plus the included cloud subscriptions and private domain for 24 months. Review the full CCC Kit scope and pricing before ordering.

Aramco CCC Authorized Audit Firms

The CCC or CCC+ must be assessed through an audit firm authorized by Saudi Aramco. Aramco states that it does not prefer one authorized audit firm over another, provided the company selects a firm from the current official list.

Because the authorized list can change, verify the current list directly on the official Aramco CCC program page before signing an audit engagement.

Common Mistakes That Delay Aramco CCC

  1. Treating CCC as paperwork only: Policies alone do not prove that the technical controls are implemented.
  2. Using generic policies: Documents that do not match the real environment create inconsistencies between policy, configuration and evidence.
  3. Missing MFA or incomplete identity controls: Written statements are not a substitute for configuration evidence.
  4. Using public email domains: A controlled private business domain is part of the General Requirements.
  5. Weak audit evidence: Unreadable, undated or unrelated screenshots can slow verification even when a control is technically enabled.
  6. Configuration drift: Everyday changes to endpoints can undermine the hardened state that was originally documented.
  7. Selecting the wrong assessment route: CCC and CCC+ have different classification and assessment requirements.
  8. Using a non-authorized auditor: The assessment must be performed by an audit firm on Aramco’s authorized list.

DIY vs. Done-for-You Aramco CCC: Which Approach Fits Your Company?

ApproachBest FitYour Team Handles
DIY / Documentation-LedCompanies with capable IT resources and an existing security environmentTechnical implementation, customization, evidence collection, audit engagement and remediation
Done-for-You ImplementationFirst-time applicants that want a defined isolated environment and minimal internal IT burdenCompany information, approvals and limited coordination while the implementation provider prepares the agreed scope

Option 1: SACS-210 Documentation Kit for DIY Teams

If your company already has the technical capability to implement SACS-210 and mainly needs a structured documentation foundation, the SACS-210 Compliance Kit provides editable documentation designed to support the compliance work.

  • Cybersecurity and Acceptable Use policies.
  • Operational forms and employee lifecycle records.
  • Asset and compliance registers.
  • Access-review and technical/business reporting templates.
  • Classification, confirmation and supporting letter templates.
  • A user guide and technical implementation checklist.

Important: A documentation kit does not constitute CCC certification. Your company remains responsible for implementing the applicable technical controls, operating them, generating valid evidence and completing the assessment with an Aramco-authorized audit firm.

SACS-210 documentation kit with editable policies, forms, registers and reports for Aramco CCC preparation.

Option 2: Done-for-You Aramco CCC Kit for First-Time Applicants

If you reached the CCC requirement during supplier registration and do not want to build the General Requirements environment yourself, NHR’s turnkey CCC Kit is designed for first-time applicants that fit a new, isolated SACS-210 General Requirements environment.

  • 2 hardened business laptops prepared as dedicated compliance assets.
  • Endpoint protection, identity, secure email/domain and centralized logging for the package scope.
  • 17 core compliance documents customized to the delivered environment.
  • Security awareness training for the agreed users.
  • Evidence preparation and audit coordination.
  • Agreed authorized-audit fees included in the package scope.
  • Included cloud subscriptions and private domain for 24 months.
  • Targeted 30-day audit-readiness path for the defined first-time General Requirements scope.
  • SAR 55,000 including VAT.

👉 Review the Aramco CCC Kit scope, pricing and eligibility

How Long Is an Aramco CCC Valid?

Saudi Aramco states that the CCC is valid for two years from the date of issuance. A new CCC must be submitted before the two-year period expires.

There is an important exception: if your company receives a new contract with a cybersecurity classification that is not covered by the current valid certificate, a new certificate covering the new classification must be obtained and submitted.

Do not confuse the certificate’s official two-year validity with a vendor’s commercial service term. For example, the 24-month term in NHR’s turnkey package specifically refers to the included cloud subscriptions and private domain.

Frequently asked questions about Aramco CCC requirements, SACS-210, audit process, cost and validity.

Frequently Asked Questions About Aramco CCC

Do new suppliers need CCC during Aramco registration?

Yes. Aramco’s current CCC program states that vendors in the registration phase are required to obtain CCC — General Requirements. A valid CCC is also listed among the registration requirements for Saudi Arabia-based suppliers.

What is the difference between CCC and CCC+?

CCC uses a self-compliance assessment followed by remote verification by an authorized audit firm. CCC+ requires an on-site assessment. Under Aramco’s current program, Direct Network Connectivity and Critical Data Processor classifications require CCC+.

How many SACS-210 General Requirements controls are there?

There are 33 General Requirements controls, numbered TPC1.1 through TPC1.33.

Can we obtain CCC without an internal IT team?

It is possible to outsource implementation and preparation, but the applicable controls still have to be genuinely implemented and evidenced. A documentation template by itself is not certification. Companies without internal IT resources may prefer a managed implementation model.

Does Aramco set a fixed price for CCC?

Aramco’s published CCC process does not provide one universal implementation price for every supplier. Costs vary with scope, existing readiness, required technology, remediation and the audit engagement. NHR’s current defined turnkey General Requirements package is SAR 55,000 including VAT.

How long does CCC take?

Aramco does not publish one universal completion time for every applicant. The duration depends on readiness, remediation, evidence and audit scheduling. NHR’s defined first-time General Requirements package targets audit readiness within 30 days.

What happens if the auditor finds a gap?

If full compliance has not been achieved, the authorized audit firm identifies the controls that still require implementation. The company addresses the findings, updates the compliance evidence and resubmits it for verification.

How long is CCC valid?

The certificate is valid for two years from its issuance date. A new certificate must be submitted before expiry, and a new classification not covered by the existing certificate can trigger the need for a new CCC earlier.

Official Aramco CCC Resources

Saudi company completing Aramco CCC requirements and progressing through supplier compliance.

Reached the Aramco CCC Requirement? Choose the Right Path

If you already have a capable IT environment and team, use this guide as your roadmap, work from the current official SACS-210 documents, and consider the documentation-led route.

If you are a first-time applicant and CCC has become the technical bottleneck in your supplier-registration journey, the managed route may be more practical. NHR can prepare the defined General Requirements environment, documentation and evidence and coordinate the independent audit process.

👉 View the NHR Aramco CCC Kit — SAR 55,000 including VAT

Disclaimer: This article is an independent practical guide and is not an official Saudi Aramco publication. Saudi Aramco’s current SACS-210 standard, CCC program instructions, classification requirements and authorized-auditor information remain the authoritative sources. NHR Alemtithal is an implementation and compliance-support provider; the independent authorized audit firm performs the compliance assessment and issues the certificate after successful verification.

Share this article
Fast-Track Your Compliance

Need help with Aramco CCC Certification?

Get a Free Expert Consultation.

Protected with anti-spam controls.
Trusted Technology Ecosystem

Certified Technology Partnerships

Technology partnerships that support the cybersecurity and compliance solutions we deliver.

Certified Partner
Gold Partner
Authorized Partner
Certified Partner
From Insight to Implementation

Need help turning insights into implementation?

Turn cybersecurity and compliance requirements into a practical roadmap for your environment, with implementation support when you need it.