Official PDF · February 2026

SACS-210 Third-Party Cybersecurity Standard Official PDF Download

Download the official 34-page standard published by Saudi Aramco and review the General Requirements, classification-specific controls, cloud applicability, and incident-response appendices.

Understand the Aramco CCC process
Official 34-page PDF English document Free download

NHR Alemtithal provides this download as a reference for Saudi suppliers. The standard itself is issued and owned by Saudi Aramco.

What Is Included in the SACS-210 Download?

A direct copy of the official February 2026 standard—not a summary, checklist, or substitute assessment.

  • 33 General Requirements: TPC1.1 through TPC1.33, covering the minimum baseline controls stated in the General Requirements section.
  • Specific Requirements: Additional controls that may apply according to the third party’s classification and contracted activities.
  • Cloud Applicability: Tables showing how controls apply across IaaS, PaaS, and SaaS service models.
  • Official Appendices: Incident-response procedures, subsequent reports, auditable events, OT certification requirements, and definitions.

Official SACS-210 File

Use the document as the authoritative reference when identifying requirements and planning implementation.

Document SACS-210
Issue Date February 2026
Length 34 Pages
Language English

Navigate the Standard Faster

Start with the section that matches the question you are trying to answer.

1

General Requirements

Review TPC1.1–TPC1.33 for the baseline governance, identity, data, email, endpoint, logging, and incident-management requirements.

2

Specific Requirements

Check the classification matrix for additional requirements related to network connectivity, managed services, critical data processing, software, cloud, or OT.

3

Incident Response

TPC1.32 and Appendices A and B cover the initial 24-hour notification and the subsequent incident-reporting process.

4

Auditable Events

TPC1.31 points to Appendix C for the minimum events and attributes that information systems must be capable of auditing.

From the Standard to an Actionable Readiness Plan

The PDF defines requirements. Your classification, implementation decisions, evidence, and audit coordination require separate work.

STEP 1

Read the official file

Use the downloaded PDF as the source of truth for control wording and appendices.

STEP 2

Confirm classification

Coordinate with your Aramco proponent to identify whether Specific Requirements apply.

STEP 3

Screen readiness

Use a preliminary assessment to identify likely gaps before engaging an authorized audit firm.

STEP 4

Implement and prepare evidence

Remediate applicable gaps and assemble clear, readable, time-stamped evidence for verification.

Not sure where your current environment stands?

Complete the free 33-question TPCS assessment for an instant preliminary report based on your responses. It is not an audit, certificate, or guarantee of compliance.

Already have an IT environment and need help implementing applicable requirements?

Explore Aramco CCC Implementation

Frequently Asked Questions

Is this the current official SACS-210 standard?

How many controls are in the General Requirements?

Does the PDF determine which Specific Requirements apply to my company?

Is downloading the standard evidence of compliance?

Is an Arabic version of the official PDF included?