SACS-210 Cybersecurity Certification Consultation
We take you from the SACS-210 requirements that apply to you to a certification-ready posture. We assess your current security, prioritise the gaps, support remediation, organise your evidence, and prepare you for the formal Cybersecurity Compliance Certificate (CCC) assessment. We stay with you until the approved auditor issues your certificate.
What's included
- Gap analysis against all 33 SACS-210 controls
- Policies, procedures, and records written and approved
- Technical implementation across identity, data, email, endpoints, and logging
- Evidence collection organised for the audit
- Auditor handling and support until your CCC is issued
- Renewal planning before the two-year validity ends
What SACS-210 asks of you.
SACS-210 is the Third-Party Cybersecurity Standard issued by Saudi Aramco in February 2026. It sets the minimum requirements to protect the confidentiality, integrity, and availability of the data and information systems that third parties handle, access, or connect to. The same standard and Cybersecurity Compliance Certificate (CCC) process apply to SABIC suppliers.
Your classification adds further controls on top of these 33.
If you do any of this, it applies to you.
- Processes, transmits, or stores corporate information and personal data
- Has access to a corporate computer or server
- Supplies off-the-shelf or customised software to the corporation
- Has a connection to the corporate network
- Provides consultancy for high-sensitivity strategic projects at national level
General Requirement
The baseline for every third party, covering governance, access, passwords, MFA, data security, training, and the CCC.
Network Connectivity
Your infrastructure connects to their network through a leased line or VPN.
Outsourced and Managed Services
You run or support infrastructure they own, such as data centres, co-location, or backup centres.
Critical Data Processor
You develop, access, or process their confidential data.
Software Services
You develop or host customised software, an application, or a website for them.
Cloud Computing
You provide IaaS, PaaS, or SaaS services.
Operational Technology
You design, supply, integrate, or maintain OT systems such as DCS, SCADA, and PLCs.
What the auditor will look for.
Governance and assets
KSA law compliance, core policies, onboarding and offboarding, a valid CCC, and an asset inventory.
Access
MFA for remote, cloud, email, and privileged access, plus annual access reviews.
Data
Strong encryption, controlled external media, and secure return and deletion of their data.
SPF, DKIM, and DMARC, anti-spam, attachment checks, a private email domain, and blocked Office macros.
Platform
Firewalls on every endpoint, a web application firewall, up-to-date antivirus, and tested patches.
Detect and respond
Security event logging, time sync, protected logs, and incidents reported within 24 hours.
Reporting rules you must meet.
The standard sets firm timelines for reporting a cybersecurity incident. You also need to keep images of the affected systems and their logs for at least 90 days after the final report.
Notify
Tell them within 24 hours of discovering a cybersecurity incident.
Keep them updated
Send an interim status report every 24 hours until the incident is resolved.
Business report
A high-level report for their management within 3 business days of resolution.
Technical report
A detailed report for their cybersecurity team within 10 business days of resolution.
From first assessment to certification.
We help you through the entire process until you receive your certification from the approved auditor. We do not just document security for the audit, we help keep you secure all year round.
Gap assessment
We review your current setup against all 33 controls and find what is missing.
Policies and documentation
We write and get approved the policies, procedures, and records the standard requires.
Technical implementation
We close technical gaps across identity, data, email, endpoints, and logging.
Audit readiness and support
We prepare your evidence and support the audit that leads to your CCC.
The Cybersecurity Compliance Certificate is issued by audit firms authorised by Aramco. Arab Spec prepares your company and manages the process with them.
Choose the plan that fits.
Pick the plan you would like to proceed with and we will confirm the official pricing once you select.
Analyse
- Gap analysis against all 33 controls
Implement
- Gap analysis
- Policy documentation
- Implementation of policies and technical controls
- Evidence collection
- Auditor handling
Complete
- Gap analysis
- Policy documentation
- Implementation of policies and technical controls
- Evidence collection
- Auditor handling
- Auditor fee handling
* Final amounts may vary depending on the number of end-user devices and employees. All amounts are exclusive of VAT.
