Editor’s Note: This guide has been updated for the Saudi Aramco Third Party Cybersecurity Standard SACS-210 (2026) and is structured as a practical reference for companies preparing for the Cybersecurity Compliance Certificate (CCC).
The Aramco Cybersecurity Compliance Certificate (CCC) verifies that a third party complies with the applicable cybersecurity requirements in Saudi Aramco’s Third Party Cybersecurity Standard (SACS-210). For companies in the supplier-registration phase, Aramco requires compliance with the General Requirements. For standard CCC, the company completes a self-compliance assessment and an Aramco-authorized audit firm verifies it remotely.
This 2026 guide explains who needs CCC, how CCC differs from CCC+, the 33 SACS-210 General Requirements controls (TPC1.1–TPC1.33), the official certification process, audit evidence, certificate validity, common causes of delay, cost considerations, and the implementation options available to Saudi companies.

Aramco CCC 2026: Key Takeaways
- Saudi Aramco’s CCC program is based on the SACS-210 Third Party Cybersecurity Standard.
- During supplier registration, companies are required to meet the General Requirements for CCC.
- The General Requirements contain 33 controls: TPC1.1 through TPC1.33.
- Standard CCC uses a self-compliance assessment followed by remote verification by an Aramco-authorized audit firm.
- CCC+ applies to Direct Network Connectivity and Critical Data Processor classifications and requires an on-site assessment.
- An issued CCC is valid for two years from the issuance date, subject to Aramco’s classification conditions.
- Certification requires more than policies: the applicable technical controls must be implemented and supported by clear audit evidence.
What Is Aramco CCC Certification?
The Cybersecurity Compliance Certificate (CCC) is part of Saudi Aramco’s program for verifying third-party compliance with the cybersecurity requirements defined in SACS-210. The certificate is issued through an Aramco-authorized audit firm after the applicable requirements have been assessed and full compliance has been verified.
For companies that are still in the Aramco supplier-registration phase, the starting point is the General Requirements. Companies that already have ongoing business with Aramco may need additional controls depending on their Third Party Classification.
For the official process and current program requirements, refer to Saudi Aramco’s Cybersecurity Compliance Certificate Program.
Who Needs an Aramco CCC?
Saudi Aramco states that all vendors in the registration phase are required to obtain CCC under the General Requirements. For Saudi Arabia-based suppliers, a valid CCC is also listed among Aramco’s supplier-registration requirements.
If your company already has an ongoing purchasing agreement with Aramco, the applicable scope can extend beyond the General Requirements. The relevant Aramco department/proponent completes the Third Party Classification Template, and the company completes the corresponding classification confirmation. If more than one classification applies, the applicable controls across those classifications must be addressed.
If you are currently registering for the first time, read our Aramco Supplier Registration 2026 guide for the registration-specific journey and where CCC becomes a practical bottleneck.

Aramco CCC vs. CCC+: Which Certificate Applies?
SACS-210 classifications determine both the applicable cybersecurity controls and the assessment method. Under Aramco’s current CCC program, the distinction is:
| Certificate | Classification | Assessment |
| CCC | General Requirements; Third Party Infrastructure Outsourcing; Customized Software Development | Self-compliance assessment verified remotely by an Aramco-authorized audit firm |
| CCC+ | Direct Network Connectivity; Critical Data Processor | On-site compliance assessment by an Aramco-authorized audit firm |
For first-time supplier registration: Aramco requires the General Requirements. If your company later receives another cybersecurity classification, additional controls or a different certificate type may apply.
If both CCC and CCC+ classifications apply, Aramco states that only CCC+ will be accepted.

SACS-210 General Requirements: The 33 Aramco CCC Controls
The SACS-210 General Requirements contain 33 controls, TPC1.1 through TPC1.33. For a General Requirements assessment, the applicable controls must be implemented and supported by evidence that is clear enough for the authorized audit firm to verify.
GOVERN Domain Controls
| Control | Requirement | Typical Evidence |
| TPC1.1 | Legislative and regulatory compliance | Compliance register and supporting compliance records |
| TPC1.2 | Acceptable Use Policy (AUP) | Approved AUP and acknowledgements |
| TPC1.3 | Required cybersecurity policies | Approved policy suite covering the required subjects |
| TPC1.4 | Employee onboarding and offboarding controls | Background-check, onboarding, offboarding and asset-return records |
| TPC1.5 | Obtain the applicable CCC from an authorized audit firm | Valid CCC |
| TPC1.6 | Renew CCC before expiration | Certificate and renewal tracking |
| TPC1.7 | Restrict proponent data to contracted personnel | Access restrictions and supporting records |
IDENTIFY Domain Controls
| Control | Requirement | Typical Evidence |
| TPC1.8 | Maintain an inventory of information and technology assets | Asset inventory covering applicable hardware, software and data assets |
PROTECT Domain Controls
| Control | Requirement | Typical Evidence |
| TPC1.9 | Centralized identity and access management using need-to-know and least privilege | IAM configuration, roles and access records |
| TPC1.10 | Unique authentication credentials | User-account configuration and records |
| TPC1.11 | Password requirements | Password policy and technical configuration evidence |
| TPC1.12 | Multi-factor authentication for applicable access scenarios | MFA configuration evidence |
| TPC1.13 | MFA for initial SSO authentication | SSO and MFA configuration |
| TPC1.14 | Periodic user-account and access-right review | Access Review Report and supporting records |
| TPC1.15 | Secure authentication of third-party technology assets | Authentication configuration and logs |
| TPC1.16 | Secure return and deletion of proponent data at the end of its lifecycle | Return/deletion records and supporting evidence |
| TPC1.17 | Secure disposal and sanitization of technology assets | Sanitization or disposal evidence |
| TPC1.18 | Protect data at rest and in transit using applicable cryptographic requirements | Encryption configuration and policy evidence |
| TPC1.19 | Restrict and secure external storage media | Device-control configuration and policy evidence |
| TPC1.20 | Implement SPF, DMARC and DKIM for email | DNS and mail-authentication records |
| TPC1.21 | Inspect incoming internet email for spam | Email-security configuration |
| TPC1.22 | Inspect email attachments for malicious content | Anti-malware/email-protection configuration |
| TPC1.23 | Use a private business email domain | Domain ownership and email configuration |
| TPC1.24 | Block applicable Microsoft Office macros from external sources | Endpoint or Office policy configuration |
| TPC1.25 | Synchronize technology assets with an authorized time source | NTP/time configuration |
| TPC1.26 | Protect event logs from unauthorized alteration, destruction or access | Logging configuration and access controls |
| TPC1.27 | Enable firewalls on endpoint devices | Endpoint firewall configuration |
| TPC1.28 | Protect applicable internet-facing applications using WAF controls | WAF configuration and relevant logs |
| TPC1.29 | Maintain up-to-date malware protection | Endpoint-protection status, update and scan evidence |
| TPC1.30 | Manage and test security patches and maintain recovery capability | Patch-management records and recovery evidence |
DETECT Domain Controls
| Control | Requirement | Typical Evidence |
| TPC1.31 | Activate audit and cybersecurity event logging | Audit logs and logging configuration |
RESPOND Domain Controls
| Control | Requirement | Typical Evidence |
| TPC1.32 | Notify the relevant proponent within the required incident-notification timeframe | Incident-response procedure and notification records |
| TPC1.33 | Notify the proponent when personnel no longer require applicable credentials/access | Access-revocation and notification records |
Important: The “Typical Evidence” column above is practical guidance, not a substitute for the official SACS-210 standard or the evidence instructions in Aramco’s current compliance-report template. Always use the current official documents for your assessment.
What Evidence Does the Aramco CCC Audit Require?
For standard CCC, the company completes the Third Party Cybersecurity Compliance Report and attaches supporting evidence. Aramco’s published process emphasizes that evidence should be clear, readable, time-stamped, visibly related to the third party, and clearly identified in screenshots.
- Approved policies, procedures and acknowledgement records.
- Configuration screenshots showing controls such as MFA, endpoint protection, firewall, email authentication and logging.
- Registers and reports such as the asset inventory and access-review records.
- Logs or reports demonstrating that security controls are active.
- Evidence of employee-related processes, training and applicable operational controls.
- Classification and compliance-report documentation required for the assessment.
Official Aramco CCC Certification Process
Saudi Aramco’s published CCC process can be summarized in five practical stages:
1. Prepare the Applicable Certification Requirements
For supplier registration, prepare for the General Requirements. Companies with ongoing Aramco business should confirm their Third Party Classification and identify all applicable SACS-210 controls.
2. Implement the Applicable SACS-210 Controls
Deploy the required administrative and technical controls and prepare evidence that demonstrates how each applicable requirement is met.
3. Complete the Self-Compliance Assessment for CCC
For standard CCC, complete the Third Party Cybersecurity Compliance Report and attach the supporting documentation. CCC+ follows the on-site assessment route instead of the standard CCC self-assessment step.
4. Select an Aramco-Authorized Audit Firm
Select a firm from Aramco’s current authorized-auditor list and establish the audit engagement. For CCC, the auditor verifies the submitted assessment remotely. For CCC+, the authorized audit firm performs the assessment on site.
5. Close Findings, Receive the Certificate and Submit It
If the company is not fully compliant, the authorized audit firm identifies the controls that still need implementation. After the findings are addressed and full compliance is verified, the audit firm issues the compliance report and CCC. The issued certificate and compliance report are then submitted to Aramco through the e-Marketplace.

How Long Does Aramco CCC Certification Take?
Aramco’s published CCC process does not specify one universal completion time for every company. Actual duration depends on factors such as the starting condition of your environment, the number of gaps, evidence quality, remediation effort and audit scheduling.
A company with an established security environment may mainly need gap remediation and evidence preparation. A first-time supplier without a controlled environment may need hardware, identity, email, endpoint, logging, documentation and evidence work before the audit can be completed.
NHR delivery model: For first-time applicants that fit our defined General Requirements scope, the NHR Aramco CCC Kit targets audit readiness within 30 days. This is an NHR service target, not an official universal Aramco certification timeline.
How Much Does Aramco CCC Cost?
There is no single implementation price that applies to every company. The commercial cost depends on what your company already has and what must be added or remediated: hardware, endpoint security, cloud identity, email and domain configuration, logging, documentation, evidence preparation, training, implementation support and the authorized audit engagement.
This is why comparing only an auditor’s fee with a turnkey implementation price can be misleading. The audit verifies compliance; it does not automatically build the underlying environment for you.
Current NHR turnkey option: Our defined first-time General Requirements CCC Kit is SAR 55,000 including VAT. It includes two hardened laptops, the required cloud/security environment for the package scope, 17 core compliance documents, security awareness training, audit coordination and agreed audit fees, plus the included cloud subscriptions and private domain for 24 months. Review the full CCC Kit scope and pricing before ordering.
Aramco CCC Authorized Audit Firms
The CCC or CCC+ must be assessed through an audit firm authorized by Saudi Aramco. Aramco states that it does not prefer one authorized audit firm over another, provided the company selects a firm from the current official list.
Because the authorized list can change, verify the current list directly on the official Aramco CCC program page before signing an audit engagement.
Common Mistakes That Delay Aramco CCC
- Treating CCC as paperwork only: Policies alone do not prove that the technical controls are implemented.
- Using generic policies: Documents that do not match the real environment create inconsistencies between policy, configuration and evidence.
- Missing MFA or incomplete identity controls: Written statements are not a substitute for configuration evidence.
- Using public email domains: A controlled private business domain is part of the General Requirements.
- Weak audit evidence: Unreadable, undated or unrelated screenshots can slow verification even when a control is technically enabled.
- Configuration drift: Everyday changes to endpoints can undermine the hardened state that was originally documented.
- Selecting the wrong assessment route: CCC and CCC+ have different classification and assessment requirements.
- Using a non-authorized auditor: The assessment must be performed by an audit firm on Aramco’s authorized list.
DIY vs. Done-for-You Aramco CCC: Which Approach Fits Your Company?
| Approach | Best Fit | Your Team Handles |
| DIY / Documentation-Led | Companies with capable IT resources and an existing security environment | Technical implementation, customization, evidence collection, audit engagement and remediation |
| Done-for-You Implementation | First-time applicants that want a defined isolated environment and minimal internal IT burden | Company information, approvals and limited coordination while the implementation provider prepares the agreed scope |
Option 1: SACS-210 Documentation Kit for DIY Teams
If your company already has the technical capability to implement SACS-210 and mainly needs a structured documentation foundation, the SACS-210 Compliance Kit provides editable documentation designed to support the compliance work.
- Cybersecurity and Acceptable Use policies.
- Operational forms and employee lifecycle records.
- Asset and compliance registers.
- Access-review and technical/business reporting templates.
- Classification, confirmation and supporting letter templates.
- A user guide and technical implementation checklist.
Important: A documentation kit does not constitute CCC certification. Your company remains responsible for implementing the applicable technical controls, operating them, generating valid evidence and completing the assessment with an Aramco-authorized audit firm.

Option 2: Done-for-You Aramco CCC Kit for First-Time Applicants
If you reached the CCC requirement during supplier registration and do not want to build the General Requirements environment yourself, NHR’s turnkey CCC Kit is designed for first-time applicants that fit a new, isolated SACS-210 General Requirements environment.
- 2 hardened business laptops prepared as dedicated compliance assets.
- Endpoint protection, identity, secure email/domain and centralized logging for the package scope.
- 17 core compliance documents customized to the delivered environment.
- Security awareness training for the agreed users.
- Evidence preparation and audit coordination.
- Agreed authorized-audit fees included in the package scope.
- Included cloud subscriptions and private domain for 24 months.
- Targeted 30-day audit-readiness path for the defined first-time General Requirements scope.
- SAR 55,000 including VAT.
👉 Review the Aramco CCC Kit scope, pricing and eligibility
How Long Is an Aramco CCC Valid?
Saudi Aramco states that the CCC is valid for two years from the date of issuance. A new CCC must be submitted before the two-year period expires.
There is an important exception: if your company receives a new contract with a cybersecurity classification that is not covered by the current valid certificate, a new certificate covering the new classification must be obtained and submitted.
Do not confuse the certificate’s official two-year validity with a vendor’s commercial service term. For example, the 24-month term in NHR’s turnkey package specifically refers to the included cloud subscriptions and private domain.

Frequently Asked Questions About Aramco CCC
Do new suppliers need CCC during Aramco registration?
Yes. Aramco’s current CCC program states that vendors in the registration phase are required to obtain CCC — General Requirements. A valid CCC is also listed among the registration requirements for Saudi Arabia-based suppliers.
What is the difference between CCC and CCC+?
CCC uses a self-compliance assessment followed by remote verification by an authorized audit firm. CCC+ requires an on-site assessment. Under Aramco’s current program, Direct Network Connectivity and Critical Data Processor classifications require CCC+.
How many SACS-210 General Requirements controls are there?
There are 33 General Requirements controls, numbered TPC1.1 through TPC1.33.
Can we obtain CCC without an internal IT team?
It is possible to outsource implementation and preparation, but the applicable controls still have to be genuinely implemented and evidenced. A documentation template by itself is not certification. Companies without internal IT resources may prefer a managed implementation model.
Does Aramco set a fixed price for CCC?
Aramco’s published CCC process does not provide one universal implementation price for every supplier. Costs vary with scope, existing readiness, required technology, remediation and the audit engagement. NHR’s current defined turnkey General Requirements package is SAR 55,000 including VAT.
How long does CCC take?
Aramco does not publish one universal completion time for every applicant. The duration depends on readiness, remediation, evidence and audit scheduling. NHR’s defined first-time General Requirements package targets audit readiness within 30 days.
What happens if the auditor finds a gap?
If full compliance has not been achieved, the authorized audit firm identifies the controls that still require implementation. The company addresses the findings, updates the compliance evidence and resubmits it for verification.
How long is CCC valid?
The certificate is valid for two years from its issuance date. A new certificate must be submitted before expiry, and a new classification not covered by the existing certificate can trigger the need for a new CCC earlier.
Official Aramco CCC Resources
- Saudi Aramco Cybersecurity Compliance Certificate Program — official process, authorized audit firms, downloads and FAQs.
- Become an Aramco Supplier — supplier-registration requirements and resources.

Reached the Aramco CCC Requirement? Choose the Right Path
If you already have a capable IT environment and team, use this guide as your roadmap, work from the current official SACS-210 documents, and consider the documentation-led route.
If you are a first-time applicant and CCC has become the technical bottleneck in your supplier-registration journey, the managed route may be more practical. NHR can prepare the defined General Requirements environment, documentation and evidence and coordinate the independent audit process.
👉 View the NHR Aramco CCC Kit — SAR 55,000 including VAT
Disclaimer: This article is an independent practical guide and is not an official Saudi Aramco publication. Saudi Aramco’s current SACS-210 standard, CCC program instructions, classification requirements and authorized-auditor information remain the authoritative sources. NHR Alemtithal is an implementation and compliance-support provider; the independent authorized audit firm performs the compliance assessment and issues the certificate after successful verification.
Need help with Aramco CCC Certification?
Get a Free Expert Consultation.