Official Standard

SACS-210 Third-Party Cybersecurity Standard

The official standard for Saudi Aramco Cybersecurity Compliance Certificate (CCC/CCC+).

Secure PDF Download
Official SACS-210 Standard

SACS-210 Standard Overview

Our download provides the complete and official SACS-210 Third Party Cybersecurity Standard. This document outlines the minimum cybersecurity controls required by Saudi Aramco for all contractors and suppliers.

  • The Complete SACS-210 Standard: The full 34-page document outlining all cybersecurity requirements.
  • General & Specific Controls: Details on the mandatory General Requirements and additional controls for different vendor types.
  • Incident Response Instructions: The official appendix detailing Aramco's mandatory incident reporting protocol.
  • Auditing Event Requirements: The official appendix listing all system events that must be logged for compliance.

Official Aramco Standard

The essential administrative framework provided securely for corporate IT evaluation.

Document Format PDF
Document Length 34 Total Pages
Target Audience Enterprise Executives
Language English

Key Sections in the Standard

A

General Requirements

The 33 mandatory controls for all third parties, covering Governance, Access Control, Data Security, and more.

B

Specific Requirements

Additional controls for vendors with network connectivity, those processing critical data, or providing cloud services.

C

Appendix A - Incident Response

Detailed, step-by-step Cybersecurity Incident Response Instructions that must be followed.

D

Appendix C - Audit Events

A complete list of all system and security events that must be capable of being audited.

Frequently Asked Questions

Is this the most recently published version of SACS-210?

Who in my organization must read this entire document?

Do the "General Requirements" apply to all suppliers regardless of size?

What is the most critical element of the technical appendices?

Can we use this document as proof of implementation during an audit?