Back to Insights
Compliance

Aramco CCC or CCC+: Which One Your Company Needs

Aramco's certificate type follows from your classification, not your size. The five classifications, what each requires, and how the assessments differ.

By Al Rashdan
7 min read
#Aramco CCC#Aramco CCC+#SACS-210#SACS-002#Aramco cybersecurity compliance certificate#Aramco third party classification#Authorized Audit Firm

A supplier cannot hold a Saudi Aramco contract without a valid Cybersecurity Compliance Certificate. That much is widely understood. What tends to be settled late, and occasionally settled wrongly, is which certificate applies.

The answer does not depend on company size, revenue, or how long you have supplied Aramco. It depends on classification, and classification is assigned by the Aramco organisations you do business with.

01

Classification decides everything downstream

Aramco's CCC Third Party Manual sets out five company classifications. Three lead to a CCC. Two lead to a CCC+.

Classification

General Requirements

Certificate

CCC

Assessment

Self-assessment by the company, verified remotely by the Authorized Audit Firm

Classification

Outsourced Infrastructure

Certificate

CCC

Assessment

Self-assessment by the company, verified remotely

Classification

Customized Software

Certificate

CCC

Assessment

Self-assessment by the company, verified remotely

Classification

Network Connectivity

Certificate

**CCC+**

Assessment

On-site assessment conducted by the Authorized Audit Firm

Classification

Critical Data Processor

Certificate

**CCC+**

Assessment

On-site assessment conducted by the Authorized Audit Firm

The right-hand column is the one to read twice. The two certificate types are not simply different tiers of the same exercise: they are assessed in fundamentally different ways.

For CCC, your own organisation completes the Third Party Cybersecurity Compliance Report. The Authorized Audit Firm then verifies that submission remotely. The quality of your self-assessment and the evidence behind it largely determines how the verification goes.

For CCC+, you do not complete a self-assessment at all. The Authorized Audit Firm conducts the assessment on site. There is no document to polish in advance, only controls that are either operating or not.

That distinction should shape how a supplier prepares. CCC rewards a rigorous, well-evidenced report. CCC+ rewards controls that hold up when someone examines them in person.

02

Two routes in, depending on where you stand

If you are seeking to register with Aramco, the requirement is to comply with all controls under the General Requirements section of the Third Party Cybersecurity Standard.

If you already hold an active procurement agreement, the process runs differently. You initiate a request to every Aramco proponent organisation your company has ongoing business with, asking each to complete the Third Party Classification Template. You then complete a Third Party Classification Confirmation Letter.

This is the step that surprises suppliers working across several parts of Aramco. Classification is assigned per relationship, and you are asking several organisations independently. The combined answer is frequently broader than a single contract would suggest.

03

Where more than one classification applies

Two rules govern the overlap, and both work in the direction of more scope rather than less.

First: where a company falls under more than one classification, all the cybersecurity controls under each determined classification are required. The classifications accumulate rather than replacing one another.

Second: where both CCC and CCC+ apply, only CCC+ is accepted.

A supplier that provides customized software to one Aramco organisation and network connectivity to another is therefore looking at a CCC+, assessed on site, against the controls of both classifications. Establishing this early changes the shape of the project. Establishing it late tends to change the timeline.

04

Compliance is assessed as a threshold, not a score

The certificate is issued where the company is fully compliant against all applicable requirements. Partial compliance does not produce a partial result: the Authorized Audit Firm returns the noncompliant controls, the company implements them, and the updated compliance report goes back for verification.

There is no partial pass to fall back on, which is the strongest practical argument for doing gap work before engaging an audit firm rather than treating the assessment as the discovery exercise.

Aramco is also specific about evidence, which is unusual and useful. Evidence must be clear, readable and time stamped, must show proof of its relation to the third party, and must be clearly highlighted within screenshots. Those are checkable criteria, and evidence that does not meet them creates avoidable findings regardless of whether the underlying control is sound.

05

Selecting an Authorized Audit Firm

The certificate is issued by an Authorized Audit Firm selected from the list Aramco publishes at aramco.com/ccc. A contract with that firm is established before assessment verification begins.

This is worth stating plainly because the market around Aramco compliance includes both audit firms and advisory firms, and they occupy different positions in the process. An advisory firm prepares you for the assessment. Only an Authorized Audit Firm verifies it and issues the certificate. A supplier benefits from understanding which one it is speaking to.

06

After issuance

The issued certificate and the compliance report are submitted to Aramco through the e-marketplace System.

The certificate is valid for two years from the issuance date, and a new one must be submitted before that period ends. It can also expire in effect before then: if your company is awarded a contract involving a cybersecurity classification type the current certificate does not cover, a new certificate is required for that work.

For a growing supplier, that second condition matters more than the calendar. Winning a contract that adds a Network Connectivity or Critical Data Processor classification moves you to CCC+ and an on-site assessment, whatever your existing certificate says.

07

A note on the standard's designation

Aramco currently refers to its Third Party Cybersecurity Standard as SACS-210. The CCC Third Party Manual, dated July 2021, refers throughout to SACS-002, and both designations remain in circulation across supplier documentation and commentary.

For scoping purposes, confirm which designation and which control set your engagement is assessed against directly from Aramco's current supplier resources. Where a published figure or control count is quoted without a version, it is worth establishing which edition it describes before planning around it.

08

Where to start

Classification first. It determines the certificate, the assessment approach, the control set, and consequently the effort. Every other decision follows from it, and it is the one question a supplier can answer without engaging anyone.

If you are preparing for a CCC or CCC+ assessment, our Aramco CCC readiness service covers classification review, gap assessment, control implementation and evidence preparation. For the broader question of which Saudi frameworks apply to your organisation, the NCA framework map works through the national controls, which are a separate matter from Aramco procurement.

Source: Saudi Aramco, Cybersecurity Compliance Certification (CCC) Third Party Manual, July 2021, and Aramco's supplier resources at aramco.com/ccc.

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Share this article

Related Reading

More insights from the Allo Technologies practice

Compliance

NCNICC-1:2025: The 26 Controls Saudi SMBs Must Meet

Class B is one component, not three. The 26 mandatory controls all sit in Cybersecurity Defence, and governance is recommended rather than required.

Read more
Compliance

NIST CSF 2.0 Mapped to NCA Requirements

Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.

Read more
Compliance

SAMA vs. NCA: Navigating Saudi Cyber Compliance

Saudi businesses often struggle differentiating SAMA CSF and NCA ECC compliance.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%