Home / Services / Aramco CCC Kit 2026
Limited Monthly Onboarding · CCC Kit 2026

Need an Aramco Cybersecurity Compliance Certificate (CCC)? Be Audit-Ready in 30 Days.

A turnkey SACS-210 General Requirements kit for Saudi SMEs and first-time Aramco CCC applicants — hardened laptops, 17 core compliance documents, secure cloud identity, and end-to-end audit coordination. No dedicated IT team required.

SAR 55,000 Fixed 24-Month Subscriptions + Domain 100% Pass Guarantee

Official quote within 2 business days · KSA hours Sun–Thu 9:00–17:00 · SoW signed before work begins

Qualification

Is This Kit Right for Your Company?

Built For

  • First-time CCC applicants needing a new, isolated CCC environment
  • Saudi SMEs and contractors without a dedicated cybersecurity team
  • Subcontractors Working with main Aramco Contractors like Nesma & Partners, Saipem, McDermott etc.
  • Companies seeking a turnkey two-workstation kit for SACS-210 General Requirements (TPC1.1–TPC1.33)

May Not Be the Right Fit If…

Track Record

The Numbers Behind the Guarantee

15+
CCC Certificates Delivered
100%
Audit Pass Rate
30
Days Average Delivery
~3 hrs
Total Time From You
Price Anchoring

The Alternative: Doing It Without This Kit

Without This Kit

  • Hire a cybersecurity consultant to interpret SACS-210 and manage evidence
  • Purchase laptops, cloud subscriptions, email security, logging, and a domain separately
  • Draft policies, registers, and audit documents from scratch — or use outdated templates
  • Coordinate the audit firm yourself
  • Absorb the cost and delay of a failed first attempt

With This Kit

  • One fixed price: SAR 55,000
  • One 30-day path to audit readiness
  • One accountable provider — us
  • Cloud subscriptions + private domain included for 24 months
  • 100% Pass Guarantee — we remediate free
The Cure

Everything You Receive

Complete audit-ready infrastructure with the included cloud subscriptions and private domain covered for 24 months — every item below removes a pain from the list above.

01

Hardened, Audit-Ready Laptops

Two business-grade laptops with current-generation multi-core processors, hardened at our facility and shipped to your office — audit-ready out of the box.

8GB RAM 512GB SSD Full HD Free Courier Delivery
Why it matters: Audit-ready devices arrive pre-configured. Your team sets up nothing.
02

Ransomware & Malware Protection

Real-time threat detection, automated patching, and centralized monitoring for 24 months.

The auditor verifies protected, monitored devices automatically.
03

Dedicated Secure Email & Identity

Private domain (.com/.net/.org) in your company name, enforced MFA, email authentication, anti-spam, and centralized audit logging — 24 months.

A clean, isolated identity built to produce audit evidence.
04

Audit-Ready Compliance Documents

Complete 17-core suite mapped to SACS-210 TPC1.1–TPC1.33, branded with your identity and ready for submission.

Policies, forms, registers prepared for you — not by you.
05

Official Audit Management

We coordinate the entire assessment with Seven Technologies, an independent Aramco-authorized CCC auditing firm. All fees included.

You never manage the auditor. We handle it end-to-end.
06

Security Awareness Training

Role-based training for up to two personnel named in your SoW, with completion certificates.

Training evidence required for the audit — included.
07

Drive Sanitization & Audit Evidence

We consume enterprise-grade erasure licenses (e.g., BitRaser) to generate the tamper-proof, cryptographic media sanitization reports required by the SACS-210 auditor.

You get the exact audit evidence required without managing wiping software yourself.
Technical Proof

How the Kit Covers SACS-210

All 33 mandatory controls across five domains — every control mapped to a shipped component and a piece of audit evidence.

TPC1.9–TPC1.30

PROTECT

22 of 33 controls

Identity and MFA, encryption, endpoint and email security, and patch management — the core of the hardened baseline the auditor verifies.

Identity & MFA Encryption Endpoint & Email Security Patch Management
TPC1.1–TPC1.7

GOVERN

Compliance register, AUP, policy suite, onboarding/offboarding, and CCC commitment.

TPC1.8

IDENTIFY

Centralized asset inventory with ownership and classification.

TPC1.31

DETECT

Centralized audit logging configured for audit evidence per Appendix C.

TPC1.32–TPC1.33

RESPOND

24-hour incident notification per Appendix A and credential revocation support.

Evidence-first engineering: Every component exists because a specific piece of evidence is required by the authorized audit firm.
Legitimate N/A handling: Controls that genuinely do not apply are documented through the official inapplicability process — never left blank.
Social Proof

What Our Clients Say

Saudi SMEs and new Aramco vendors across the Kingdom use the CCC Kit to win contracts faster — real results from certified clients who passed the SACS-210 audit on the first attempt.

"We were facing a 3-month delay on a SAR 3.2M contract. NHR delivered the workstations and the certificate in 30 days. We saved SAR 47,000 compared to our initial consultant quote."

A

Abdulhameed Alahmed

General Manager · Taqam Almustaqbal

"The all-in-one approach is exactly what we needed. They reduced a massive compliance effort into a simple, shipped product. Our IT team didn't have to lift a finger."

A

Ahmed Shapat

IT Manager · Arabian Gannas

"Transparent pricing and excellent remote support. We completely replaced the need for an external cybersecurity consultant. Highly recommend."

A

Aamer Khan

Procurement Head · Ozone Cool Trading

Deep Dive

For IT Teams & Compliance Officers

Explore the technical depth of the Aramco CCC Kit — exactly what your IT team never has to build, and the complete 17-core SACS-210 document suite mapped to controls TPC1.1–TPC1.33.

For IT Teams: What You Need to Know

What your IT team does NOT need to do:

  • Build or configure security controls
  • Set up or manage the cloud tenant
  • Write or format compliance documents
  • Liaise with the auditor
  • Install or harden the workstations

What your IT team DOES receive:

  • Full credential handover at project closure
  • Configuration documentation
  • Domain admin access (in your company's name)
  • Post-certification guidance for the 24-month cycle

This kit is an isolated compliance environment. It does not require changes to your existing production systems.

The Complete 17-Core Document Suite TPC1.1–TPC1.33

Policies (2)

  • • Cybersecurity Policy
  • • Acceptable Use Policy

Forms (4)

  • • AUP Acknowledgment
  • • Onboarding Checklist
  • • Offboarding Checklist
  • • Policy Exception Request

Registers (2)

  • • Asset Inventory Register
  • • Legislative & Regulatory Register

Reports (5)

  • • Access Review Report
  • • Interim Status Report
  • • Final Technical Report
  • • Final Business Report
  • • Inapplicable Controls Report

Letters (4)

  • • Confirmation for Current Environmental Status
  • • Procedure for Aramco Vendor Portal Access
  • • Remote Access Inapplicability Confirmation
  • • VPN and Remote Access Commitment

Plus Supporting Items

  • • Policy communication email template
  • • Document signing guidance
Process

Your 30-Day Path to Audit Readiness

Total typical client involvement: ~3 hours across 30 days.

1

Onboarding Days 1–5

~2 hours

Approve the quote, sign the SoW. Provide your CR number, company details, logo, and user info. Select your domain extension (.com/.net/.org).

2

Execution Days 6–25

Minimal to none

We provision and harden your workstations, register your domain, set up your cloud environment, brand your documents, and collect all audit evidence.

Delivery & Closure Days 26–30

~1 hour

The independent authorized audit firm conducts the assessment. After successful assessment and certificate issuance, you receive the CCC certificate, compliance report, credentials, and your hardened laptops.

Independent Validation

Your Audit Is Conducted by Seven Technologies

An Aramco-authorized CCC auditing firm · Assessment conducted remotely · We manage all auditor communications on your behalf.

Seven Technologies - Authorized CCC Auditor
Pricing & Quote

Fixed Price. Fixed Outcome. Get Your Quote.

One transparent price for implementation, audit coordination, and the included cloud subscriptions and private domain for 24 months — with your official VAT-compliant quote within 2 business days.

24-Month Subscriptions + Domain Included

No Year-2 renewal fee for the included subscriptions and domain

SAR 55,000

VAT Inclusive · Fixed Price

  • 2 hardened, audit-ready laptops
  • 24-month cloud subscriptions
  • Private domain in your company name
  • 17-core compliance documents
  • Audit fees + full management
  • Security training (2 personnel)
  • Tamper-proof drive sanitization reports
  • No re-audit fees (agreed scope)

Payment Milestones

Advance

41,250

After SoW signature

Success

13,750

Only on certificate issuance

100% Audit Pass Guarantee

Your responsibilities are limited to providing company info, signing documents, and making personnel available for training. All technical work is performed by us. If any control is flagged, we remediate free.

CCC Issued in Your Company Name SoW Before Work

Get My Fixed-Price Quote

Reply within 2 business days · KSA hours Sun–Thu 9:00–17:00

Full Confidentiality

Your CR and company information are used solely for the certification process. We do not share your data with third parties outside the audit scope.

SSL Secured Saudi Licensed VAT Compliant
Objections Handled

Frequently Asked Questions

Everything Saudi SMEs ask about the Aramco CCC Kit 2026 — SACS-210 audit guarantee, 24-month coverage, pricing, scope, and what happens after certification.

Why is the kit priced at SAR 55,000 instead of buying each piece separately?

Because it is a bundled fixed price, not an hourly consulting fee. Purchased separately, you would need hardware, 24-month cloud subscriptions, private domain, compliance documentation, audit fees, security configuration, and project management. That route usually involves multiple vendors, months of coordination, and a higher total cost — before adding the risk of a failed first attempt. The kit fixes the total, covers the full two-year subscription cycle, and puts the implementation risk on us.

Does the kit guarantee passing the SACS-210 audit?

Yes. The kit is engineered to satisfy all 33 General Requirements controls, TPC1.1–TPC1.33. The 100% pass guarantee applies when all recommended controls are implemented within the agreed timeline. Your responsibilities are limited to providing company information, signing documents, and making personnel available for training. All technical implementation, configuration, and evidence collection are performed by us.

What exactly does the 24-month coverage include?

The kit includes the required cloud subscriptions and the private domain for 24 months. This 24-month coverage describes the included subscriptions and domain; it is separate from the official validity period of the CCC certificate. Recertification and any services outside the agreed scope are not included unless separately agreed.

Will the authorized auditor need to visit our office?

No. Seven Technologies conducts the assessment remotely via secure screen sharing, photographic evidence, configuration screenshots, and document review. We manage all auditor communications on your behalf. The compliant workstations run as standalone, isolated endpoints, so your existing operations continue uninterrupted.

What is included in the "General Requirements" scope, TPC1.1–TPC1.33?

All 33 mandatory controls across five domains: GOVERN, IDENTIFY, PROTECT, DETECT, and RESPOND. This includes policies, asset management, identity and MFA, encryption, endpoint and email security, audit logging, incident notification, and credential revocation. Specialized classifications require separate assessment.

Can we use the hardened CCC laptops for everyday office work?

We strongly advise against it. Daily use risks introducing unapproved software or configurations that could violate the hardened baseline and compromise your CCC status. For daily work, continue using your existing systems; treat the hardened workstations as dedicated compliance assets.

How do I know this kit meets the current Aramco standard?

Aramco's current Third Party Cybersecurity Standard is SACS-210, which replaced the older SACS-002. Many publicly available templates and some consultant quotations still reference the obsolete SACS-002 and will not satisfy the current audit. This kit is engineered entirely against the current SACS-210 control set. If you receive a quotation that references SACS-002, it is outdated.

We already have a domain and employee emails. Can we use this kit?

This kit is designed around a new, isolated CCC environment using a newly provisioned private domain. It does not migrate, configure, or certify your existing corporate domain or employee mailboxes. If your compliance scope must include your current domain or existing email environment, request the Implementation Service or a custom assessment.

Do we need an Aramco vendor registration before ordering?

You need a valid Commercial Registration and primary company details to begin. If you already have an Aramco vendor registration, share those details during onboarding. If not, we guide you on the CCC evidence requirements; the Aramco vendor registration itself remains your responsibility.

Is the CCC recognized outside Aramco?

The CCC is an Aramco third-party cybersecurity certificate. It may support prequalification and customer assurance, but it does not automatically replace other certifications, regulatory requirements, or client-specific audits.

What happens when my 2-year certificate expires?

You will need to recertify. We offer recertification support for environments we delivered. Contact us before expiry to confirm the current recertification scope and price. Your supplied laptops and domain remain yours.

Can we add more hardened laptops later?

Yes. Additional hardened laptops can be added to your isolated CCC environment. Contact us for volume pricing. Adding users may require updated compliance documents and a supplementary audit.

Your CCC Requirement Shouldn't Stall Progress.Be Audit-Ready in 30 Days.

Fixed price. Minimal IT burden. We prepare the environment, manage the audit process, and remediate in-scope findings under our pass guarantee.

SAR 55,000 Fixed 24-Month Subscriptions + Domain 100% Pass Guarantee
Get My Fixed-Price Quote

Official quote within 2 business days · KSA working hours Sun–Thu