SACS-210 Third-Party Cybersecurity Standard Official PDF Download
Download the official 34-page standard published by Saudi Aramco and review the General Requirements, classification-specific controls, cloud applicability, and incident-response appendices.
NHR Alemtithal provides this download as a reference for Saudi suppliers. The standard itself is issued and owned by Saudi Aramco.
What Is Included in the SACS-210 Download?
A direct copy of the official February 2026 standard—not a summary, checklist, or substitute assessment.
- 33 General Requirements: TPC1.1 through TPC1.33, covering the minimum baseline controls stated in the General Requirements section.
- Specific Requirements: Additional controls that may apply according to the third party’s classification and contracted activities.
- Cloud Applicability: Tables showing how controls apply across IaaS, PaaS, and SaaS service models.
- Official Appendices: Incident-response procedures, subsequent reports, auditable events, OT certification requirements, and definitions.
Official SACS-210 File
Use the document as the authoritative reference when identifying requirements and planning implementation.
Navigate the Standard Faster
Start with the section that matches the question you are trying to answer.
General Requirements
Review TPC1.1–TPC1.33 for the baseline governance, identity, data, email, endpoint, logging, and incident-management requirements.
Specific Requirements
Check the classification matrix for additional requirements related to network connectivity, managed services, critical data processing, software, cloud, or OT.
Incident Response
TPC1.32 and Appendices A and B cover the initial 24-hour notification and the subsequent incident-reporting process.
Auditable Events
TPC1.31 points to Appendix C for the minimum events and attributes that information systems must be capable of auditing.
From the Standard to an Actionable Readiness Plan
The PDF defines requirements. Your classification, implementation decisions, evidence, and audit coordination require separate work.
Read the official file
Use the downloaded PDF as the source of truth for control wording and appendices.
Confirm classification
Coordinate with your Aramco proponent to identify whether Specific Requirements apply.
Screen readiness
Use a preliminary assessment to identify likely gaps before engaging an authorized audit firm.
Implement and prepare evidence
Remediate applicable gaps and assemble clear, readable, time-stamped evidence for verification.
Not sure where your current environment stands?
Complete the free 33-question TPCS assessment for an instant preliminary report based on your responses. It is not an audit, certificate, or guarantee of compliance.
Already have an IT environment and need help implementing applicable requirements?
Explore Aramco CCC ImplementationFrequently Asked Questions
Is this the current official SACS-210 standard?
Yes. The downloadable file is the official 34-page SACS-210 Third-Party Cybersecurity Standard dated February 2026 and published by Saudi Aramco. Suppliers should also check Aramco’s CCC program page for any future revision.
How many controls are in the General Requirements?
The General Requirements section contains 33 controls, numbered TPC1.1 through TPC1.33. Additional Specific Requirements may apply depending on the third party’s classification and contracted activities.
Does the PDF determine which Specific Requirements apply to my company?
No. The standard explains the classifications and control applicability, but your Aramco proponent completes the Third Party Classification process that determines the applicable scope.
Is downloading the standard evidence of compliance?
No. The PDF defines the requirements. Compliance verification requires implementation of the applicable controls and supporting evidence reviewed through the official assessment process.
Is an Arabic version of the official PDF included?
No. The official downloadable standard is in English. NHR Alemtithal’s Arabic page explains the resource in Arabic, but the file itself remains the official English document.