Aramco CCC Implementation 2026 — Certify Your Existing Infrastructure.
For renewals, BYOD, and existing suppliers. We assess your current environment against SACS-210 (TPC1.1–TPC1.33), remediate the gaps remotely, customize your compliance documents to your actual tools, and manage the authorized audit — without replacing what you already own.
Free automated Gap Report within 24 hours · Email address only · KSA hours Sun–Thu 9:00–17:00
Is Implementation Right for Your Company?
Built For
- CCC renewals — your certificate is expired or expiring and your environment needs re-alignment
- BYOD — you want to certify your own devices, servers, and network instead of buying new ones
- Existing suppliers — your current domain and employee mailboxes must pass SACS-210
- Companies with existing IT assets — identity, endpoint, email, or firewall already in place and needing configuration to the standard
May Not Be the Right Fit If…
- You are a first-time applicant without an IT environment and prefer a shipped, isolated compliance setup → Aramco CCC Kit
- You need a brand-new certified workstation environment with zero internal IT involvement → Aramco CCC Kit
- Your classification is beyond General Requirements (Network Connectivity, Critical Data Processor, Cloud Computing, OT) — those require a separate assessment
The Alternative: Interpreting SACS-210 Alone
Without This Service
- Translate 33 legal-style controls into technical configurations yourself
- Draft policies that auditors reject because they don't match your actual tools
- Produce evidence without knowing the auditor's screenshot and timestamp expectations
- Coordinate the audit firm, licensing vendors, and trainers as separate projects
- Absorb re-audit cost and contract delays if a control is flagged
With This Service
- One fixed implementation fee from SAR 11,999
- Documents customized to your existing stack — not generic templates
- Evidence produced the way authorized auditors expect it
- Missing licenses or hardware quoted transparently at partner pricing — never forced
- We remediate flagged controls until closure — 25% held until your CCC is issued
Four Phases. One Certificate.
Typical delivery: 1–2 months for technically ready environments.
Assess Days 1–7
Comprehensive gap assessment across all five SACS-210 domains and the 33 mandatory controls, plus a technical questionnaire of your current stack.
Plan Days 8–14
A detailed remediation roadmap and resource plan: what to configure, what to license, what to document — with a fixed quote before work begins.
Implement Weeks 3–6
Remote configuration of your existing environment, customized Core SACS-210 documents, evidence production, and staff awareness training.
Certify Weeks 6–8
Audit preparation, submission, and full coordination with the authorized audit firm — with remediation support until every finding is closed.
Know Your Gaps Before You Spend a Riyal
Complete the TPCS 2026 assessment questionnaire and receive an automated Gap Analysis Report mapped to the General Requirements (TPC1.1–TPC1.33). Where a gap is indicated, the report outlines the associated risk and a high-level remediation action. Where all answers are compliant, the control is marked compliant.
- Email address only — no Commercial Registration or sensitive data needed at this stage
- Automated report within 24 hours with risks and remediation recommendations
- Your fixed quote is confirmed after the assessment — no surprises later
What the Report Covers
Everything Your Environment Needs to Pass
Customized to your existing infrastructure — never generic templates.
Customized Core SACS-210 Documents
Policies, procedures, forms, registers, reports, and letters written to match your actual tools and environment — mapped to TPC1.1–TPC1.33 without conflicting with the controls.
Remote Technical Remediation
Configuration of your existing identity, endpoint, email, firewall, and logging controls to the standard — identity federation, MFA enforcement, GPO hardening, macro blocking, NTP, and more.
Audit-Ready Evidence Production
Timestamped, domain-visible screenshots, configuration exports, and logs produced exactly the way authorized audit firms expect them — highlighted and readable.
Security Awareness Training
Role-based awareness training delivered online for one month, with completion records that satisfy the personnel training requirements of the standard.
Authorized Audit Management
We prepare the submission and coordinate the entire assessment. We can contract the authorized audit firm on your behalf — Seven Technologies or your preferred Aramco-authorized auditor.
Partner-Priced Recommendations
Where gaps require licenses or hardware you don't own, we recommend and quote them transparently at partner rates — as a licensed Microsoft CSP and certified security partner — never as a forced bundle.
Partner Pricing on Any Required Quote
As a certified security partner, any licenses or subscriptions your gaps require are quoted at competitive partner rates. We work with Aramco-authorized CCC auditing firms.






Existing Environments, Certified.
Saudi companies that certified their own infrastructure — renewals, BYOD, and existing domains.
"They configured our existing Microsoft 365 tenant and on-prem systems to SACS-210 without replacing anything we already owned. The customized policies matched our actual tools, and we passed on the first attempt."
Ahmed Shapat
IT Manager · Arabian Gannas
"Our CCC was due for renewal and our environment had drifted. NHR ran the gap assessment, closed every finding remotely, and managed the auditor end-to-end. Renewal completed in six weeks."
Abdulhameed Alahmed
General Manager · Taqam Almustaqbal
"Transparent pricing — the implementation fee was fixed after the free assessment, and the only extras were licenses we chose to add at their partner rates. Exactly as promised."
Aamer Khan
Procurement Head · Ozone Cool Trading
Fixed Fee. Confirmed After Your Free Assessment.
The price increases only when your infrastructure is chaotic or missing required licenses — and you know the exact figure before signing.
General Requirements TPC1.1–TPC1.33
Audit fees & required licenses billed separately or added to your quote
Base implementation fee at the agreed scope
- Gap assessment, roadmap & fixed quote
- Customized Core SACS-210 documents
- Remote technical remediation & evidence production
- Awareness training (online, 1 month)
- Audit coordination & remediation until closure
Payment Milestones (at base price)
Advance
9,000
75% · with P.O. / SoW signature
Success
2,999
25% · upon obtaining your CCC
Remediation Until Closure
If the auditor flags any control within the agreed scope, we remediate it until closed. Your final payment is held until your CCC is issued.
Have a Question? Send It Now
Reply within 2 business days · KSA hours Sun–Thu 9:00–17:00
Full Confidentiality
Your name, email, and message are used only to answer your inquiry — never shared with third parties.
Frequently Asked Questions
Everything Saudi companies ask about certifying their existing infrastructure.
Kit vs Implementation: Which One Is Right?
| Feature | CCC Kit | Implementation |
|---|---|---|
| Best for | First-time applicants | Renewals / BYOD / existing domain |
| Infrastructure | New, shipped & isolated | Your existing environment |
| Documents | Standardized suite | Customized to your stack |
| Price | SAR 55,000 fixed | From SAR 11,999 |
| Timeline | ~30 days | 1–2 months |
Can you work with the tools we already own?
Do we need to buy new hardware or licenses?
Will the audit be remote, and who manages the auditor?
How long does implementation take?
What happens if the auditor flags a control?
Is the gap assessment really free? What do we need to provide?
Our CCC is expiring — is this the right service for renewal?
What is the difference between SACS-002 and SACS-210?
Your Infrastructure Is an Asset.
Let's Get It Certified.
Start with the free gap assessment. Know your risks, your remediation plan, and your fixed price — before you commit to anything.
Automated report within 24 hours · Email address only · KSA working hours Sun–Thu