A supplier cannot hold a Saudi Aramco contract without a valid Cybersecurity Compliance Certificate. That much is widely understood. What tends to be settled late, and occasionally settled wrongly, is which certificate applies.
The answer does not depend on company size, revenue, or how long you have supplied Aramco. It depends on classification, and classification is assigned by the Aramco organisations you do business with.
01
Classification decides everything downstream
| Classification | Certificate | Assessment |
|---|---|---|
| General Requirements | CCC | Self-assessment by the company, verified remotely by the Authorized Audit Firm |
| Outsourced Infrastructure | CCC | Self-assessment by the company, verified remotely |
| Customized Software | CCC | Self-assessment by the company, verified remotely |
| Network Connectivity | **CCC+** | On-site assessment conducted by the Authorized Audit Firm |
| Critical Data Processor | **CCC+** | On-site assessment conducted by the Authorized Audit Firm |
Classification
General Requirements
Certificate
CCC
Assessment
Self-assessment by the company, verified remotely by the Authorized Audit Firm
Classification
Outsourced Infrastructure
Certificate
CCC
Assessment
Self-assessment by the company, verified remotely
Classification
Customized Software
Certificate
CCC
Assessment
Self-assessment by the company, verified remotely
Classification
Network Connectivity
Certificate
**CCC+**
Assessment
On-site assessment conducted by the Authorized Audit Firm
Classification
Critical Data Processor
Certificate
**CCC+**
Assessment
On-site assessment conducted by the Authorized Audit Firm
The right-hand column is the one to read twice. The two certificate types are not simply different tiers of the same exercise: they are assessed in fundamentally different ways.
For CCC, your own organisation completes the Third Party Cybersecurity Compliance Report. The Authorized Audit Firm then verifies that submission remotely. The quality of your self-assessment and the evidence behind it largely determines how the verification goes.
For CCC+, you do not complete a self-assessment at all. The Authorized Audit Firm conducts the assessment on site. There is no document to polish in advance, only controls that are either operating or not.
That distinction should shape how a supplier prepares. CCC rewards a rigorous, well-evidenced report. CCC+ rewards controls that hold up when someone examines them in person.
02
Two routes in, depending on where you stand
If you are seeking to register with Aramco, the requirement is to comply with all controls under the General Requirements section of the Third Party Cybersecurity Standard.
If you already hold an active procurement agreement, the process runs differently. You initiate a request to every Aramco proponent organisation your company has ongoing business with, asking each to complete the Third Party Classification Template. You then complete a Third Party Classification Confirmation Letter.
This is the step that surprises suppliers working across several parts of Aramco. Classification is assigned per relationship, and you are asking several organisations independently. The combined answer is frequently broader than a single contract would suggest.
03
Where more than one classification applies
Two rules govern the overlap, and both work in the direction of more scope rather than less.
First: where a company falls under more than one classification, all the cybersecurity controls under each determined classification are required. The classifications accumulate rather than replacing one another.
Second: where both CCC and CCC+ apply, only CCC+ is accepted.
A supplier that provides customized software to one Aramco organisation and network connectivity to another is therefore looking at a CCC+, assessed on site, against the controls of both classifications. Establishing this early changes the shape of the project. Establishing it late tends to change the timeline.
04
Compliance is assessed as a threshold, not a score
The certificate is issued where the company is fully compliant against all applicable requirements. Partial compliance does not produce a partial result: the Authorized Audit Firm returns the noncompliant controls, the company implements them, and the updated compliance report goes back for verification.
There is no partial pass to fall back on, which is the strongest practical argument for doing gap work before engaging an audit firm rather than treating the assessment as the discovery exercise.
Aramco is also specific about evidence, which is unusual and useful. Evidence must be clear, readable and time stamped, must show proof of its relation to the third party, and must be clearly highlighted within screenshots. Those are checkable criteria, and evidence that does not meet them creates avoidable findings regardless of whether the underlying control is sound.
The certificate is issued by an Authorized Audit Firm selected from the list Aramco publishes at aramco.com/ccc. A contract with that firm is established before assessment verification begins.
This is worth stating plainly because the market around Aramco compliance includes both audit firms and advisory firms, and they occupy different positions in the process. An advisory firm prepares you for the assessment. Only an Authorized Audit Firm verifies it and issues the certificate. A supplier benefits from understanding which one it is speaking to.
06
After issuance
The issued certificate and the compliance report are submitted to Aramco through the e-marketplace System.
The certificate is valid for two years from the issuance date, and a new one must be submitted before that period ends. It can also expire in effect before then: if your company is awarded a contract involving a cybersecurity classification type the current certificate does not cover, a new certificate is required for that work.
For a growing supplier, that second condition matters more than the calendar. Winning a contract that adds a Network Connectivity or Critical Data Processor classification moves you to CCC+ and an on-site assessment, whatever your existing certificate says.
07
A note on the standard's designation
Aramco currently refers to its Third Party Cybersecurity Standard as SACS-210. The CCC Third Party Manual, dated July 2021, refers throughout to SACS-002, and both designations remain in circulation across supplier documentation and commentary.
For scoping purposes, confirm which designation and which control set your engagement is assessed against directly from Aramco's current supplier resources. Where a published figure or control count is quoted without a version, it is worth establishing which edition it describes before planning around it.
08
Where to start
Classification first. It determines the certificate, the assessment approach, the control set, and consequently the effort. Every other decision follows from it, and it is the one question a supplier can answer without engaging anyone.
If you are preparing for a CCC or CCC+ assessment, our Aramco CCC readiness service covers classification review, gap assessment, control implementation and evidence preparation. For the broader question of which Saudi frameworks apply to your organisation, the NCA framework map works through the national controls, which are a separate matter from Aramco procurement.
Source: Saudi Aramco, Cybersecurity Compliance Certification (CCC) Third Party Manual, July 2021, and Aramco's supplier resources at aramco.com/ccc.
Need Expert Guidance?
Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.
Schedule a ConsultationAllo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.
Share this article
Related Reading
More insights from the Allo Technologies practice
NCNICC-1:2025: The 26 Controls Saudi SMBs Must Meet
Class B is one component, not three. The 26 mandatory controls all sit in Cybersecurity Defence, and governance is recommended rather than required.
Read moreNIST CSF 2.0 Mapped to NCA Requirements
Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.
Read moreSAMA vs. NCA: Navigating Saudi Cyber Compliance
Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.
Read moreTalk to an Expert
Get personalized guidance from our senior security and compliance practitioners