SACS-210 Cybersecurity Certification Consultation

We take you from the SACS-210 requirements that apply to you to a certification-ready posture. We assess your current security, prioritise the gaps, support remediation, organise your evidence, and prepare you for the formal Cybersecurity Compliance Certificate (CCC) assessment. We stay with you until the approved auditor issues your certificate.

What's included

  • Gap analysis against all 33 SACS-210 controls
  • Policies, procedures, and records written and approved
  • Technical implementation across identity, data, email, endpoints, and logging
  • Evidence collection organised for the audit
  • Auditor handling and support until your CCC is issued
  • Renewal planning before the two-year validity ends
10+
YEARS IN BUSINESS
200+
CUSTOMERS SERVED
50+
PARTNER CHANNELS
300+
PROJECTS DELIVERED

What SACS-210 asks of you.

SACS-210 is the Third-Party Cybersecurity Standard issued by Saudi Aramco in February 2026. It sets the minimum requirements to protect the confidentiality, integrity, and availability of the data and information systems that third parties handle, access, or connect to. The same standard and Cybersecurity Compliance Certificate (CCC) process apply to SABIC suppliers.

7
Govern
Laws, policies, people, CCC
1
Identify
Asset inventory
22
Protect
Access, data, email, platform
1
Detect
Security event logging
2
Respond
Incident notice, access changes
33
Total
General controls for every third party

Your classification adds further controls on top of these 33.

If you do any of this, it applies to you.

  • Processes, transmits, or stores corporate information and personal data
  • Has access to a corporate computer or server
  • Supplies off-the-shelf or customised software to the corporation
  • Has a connection to the corporate network
  • Provides consultancy for high-sensitivity strategic projects at national level

General Requirement

The baseline for every third party, covering governance, access, passwords, MFA, data security, training, and the CCC.

Network Connectivity

Your infrastructure connects to their network through a leased line or VPN.

Outsourced and Managed Services

You run or support infrastructure they own, such as data centres, co-location, or backup centres.

Critical Data Processor

You develop, access, or process their confidential data.

Software Services

You develop or host customised software, an application, or a website for them.

Cloud Computing

You provide IaaS, PaaS, or SaaS services.

Operational Technology

You design, supply, integrate, or maintain OT systems such as DCS, SCADA, and PLCs.

What the auditor will look for.

TPC1.1 to 1.8

Governance and assets

KSA law compliance, core policies, onboarding and offboarding, a valid CCC, and an asset inventory.

TPC1.9 to 1.15

Access

MFA for remote, cloud, email, and privileged access, plus annual access reviews.

TPC1.16 to 1.19

Data

Strong encryption, controlled external media, and secure return and deletion of their data.

TPC1.20 to 1.24

Email

SPF, DKIM, and DMARC, anti-spam, attachment checks, a private email domain, and blocked Office macros.

TPC1.27 to 1.30

Platform

Firewalls on every endpoint, a web application firewall, up-to-date antivirus, and tested patches.

TPC1.25, 1.26, 1.31 to 1.33

Detect and respond

Security event logging, time sync, protected logs, and incidents reported within 24 hours.

Reporting rules you must meet.

The standard sets firm timelines for reporting a cybersecurity incident. You also need to keep images of the affected systems and their logs for at least 90 days after the final report.

01

Notify

Tell them within 24 hours of discovering a cybersecurity incident.

02

Keep them updated

Send an interim status report every 24 hours until the incident is resolved.

03

Business report

A high-level report for their management within 3 business days of resolution.

04

Technical report

A detailed report for their cybersecurity team within 10 business days of resolution.

From first assessment to certification.

We help you through the entire process until you receive your certification from the approved auditor. We do not just document security for the audit, we help keep you secure all year round.

STEP 1

Gap assessment

We review your current setup against all 33 controls and find what is missing.

STEP 2

Policies and documentation

We write and get approved the policies, procedures, and records the standard requires.

STEP 3

Technical implementation

We close technical gaps across identity, data, email, endpoints, and logging.

STEP 4

Audit readiness and support

We prepare your evidence and support the audit that leads to your CCC.

The Cybersecurity Compliance Certificate is issued by audit firms authorised by Aramco. Arab Spec prepares your company and manages the process with them.

Choose the plan that fits.

Pick the plan you would like to proceed with and we will confirm the official pricing once you select.

 

Analyse

Starting from
5,000 SAR*
Timeline: 1 to 2 weeks
  • Gap analysis against all 33 controls
 

Implement

Starting from
15,000 SAR*
Timeline: 3 to 4 weeks
  • Gap analysis
  • Policy documentation
  • Implementation of policies and technical controls
  • Evidence collection
  • Auditor handling
Recommended

Complete

Starting from
25,000 SAR*
Timeline: 3 to 4 weeks
  • Gap analysis
  • Policy documentation
  • Implementation of policies and technical controls
  • Evidence collection
  • Auditor handling
  • Auditor fee handling

* Final amounts may vary depending on the number of end-user devices and employees. All amounts are exclusive of VAT.

Questions we get asked.

What is SACS-210?
SACS-210 is the Third-Party Cybersecurity Standard issued by Saudi Aramco in February 2026. It sets the minimum cybersecurity requirements for suppliers and contractors that handle, access, or connect to Aramco data and systems. You may still see the earlier reference SACS-002 in older documents.
What is the Cybersecurity Compliance Certificate (CCC)?
The CCC is the certificate that shows Aramco and SABIC that your company meets their third-party cybersecurity requirements. It is issued after an assessment by an audit firm authorised by Aramco, and it is valid for two years.
How many controls are there?
There are 33 general controls that apply to every third party, across five functions: Govern (7), Identify (1), Protect (22), Detect (1), and Respond (2). Your classification, such as network connectivity, software, or cloud, adds further controls.
Does this also apply to SABIC suppliers?
Yes. SABIC has moved its supplier cybersecurity programme into the same Cybersecurity Compliance Certificate programme as Aramco, and the standard names SABIC in its incident reporting process.
Who issues the certificate?
An audit firm authorised by Aramco carries out the assessment and issues the certificate. Arab Spec prepares your company, communicates with the auditor on your behalf, and makes sure the process is completed.
How long does it take?
The Analyse plan takes 1 to 2 weeks. The Implement and Complete plans take 3 to 4 weeks. The exact time depends on your size and how many gaps we find.
How much does it cost?
Plans start from SAR 5,000, exclusive of VAT. The final amount depends on the number of end-user devices and employees, and we confirm the official price once you choose a plan.
What must we do if there is a security incident?
You must notify them within 24 hours of discovering it, send interim updates every 24 hours until it is resolved, and provide a business report within 3 business days and a technical report within 10 business days of resolution.
What happens when the certificate expires?
The certificate is valid for two years and must be renewed before it expires. We plan the renewal with you in advance so your status with Aramco and SABIC does not lapse.

Start a project

Tell us a little about what you need, and we'll get back to you shortly.