All services

Aramco CCC and CCC+ Readiness

A valid Cybersecurity Compliance Certificate is a precondition for doing business with Saudi Aramco. We prepare suppliers to reach it, and the Authorized Audit Firm issues it.

What the CCC is, and where we fit

The Cybersecurity Compliance Certificate confirms that an Aramco third party meets the requirements of Aramco's Third Party Cybersecurity Standard. Aramco's own Third Party Manual sets out the route: the supplier establishes its classification, implements the applicable controls, and then works with an Aramco Authorized Audit Firm, which verifies the result and issues the certificate.

Allo works on the supplier's side of that line. We prepare you for the assessment: confirming classification, closing control gaps, and assembling evidence in the form the audit firm expects. The certificate itself is issued by an Authorized Audit Firm selected from Aramco's published list, not by us.

Aramco currently refers to the standard as SACS-210. Its Third Party Manual, dated July 2021, refers throughout to SACS-002, and both designations remain in circulation. Confirm which applies to your engagement against Aramco's current supplier documentation before scoping work.

What we deliver

Preparation for the assessment. The certificate is issued by an Authorized Audit Firm.

Classification review

Establish which of the five classifications apply across every Aramco proponent organisation you work with, and what that combination requires.

Gap assessment

Assess current controls against the applicable requirements and produce a risk-rated remediation plan.

Control implementation

Close the gaps: technical controls, policy, and the operational practices behind them.

Evidence pack

Assemble evidence to the criteria Aramco states: clear, readable, time stamped, provably related to your organisation, and highlighted within screenshots.

Compliance report preparation

Prepare the Third Party Cybersecurity Compliance Report so the audit firm's verification is a check rather than a discovery exercise.

Audit support

Support through verification, including remediation and resubmission where noncompliant controls come back.

The certification route

1

Classification

Suppliers registering with Aramco comply with the General Requirements section. Suppliers with an active procurement agreement ask each Aramco proponent organisation to complete the Third Party Classification Template, plus a Classification Confirmation Letter. Where more than one classification applies, all the controls under each of them are required, and where both CCC and CCC+ apply, only CCC+ is accepted.

2

Control implementation

Implement every control applicable to the confirmed classifications. This is the bulk of the effort and the point at which most timelines slip.

3

Self-compliance assessment

For CCC, the supplier completes the Third Party Cybersecurity Compliance Report itself. Evidence must be clear, readable and time stamped, show its relation to the supplier, and be highlighted within screenshots. CCC+ suppliers skip this step, because the audit firm performs the assessment on site.

4

Select an Authorized Audit Firm

Choose a firm from Aramco's Authorized Audit Firms list and contract with it before verification begins.

5

Verification and issuance

The certificate is issued only where the supplier is fully compliant against all applicable requirements. Where it is not, the audit firm returns the noncompliant controls for implementation and re-verification.

6

Submission, validity and renewal

The issued certificate and compliance report are submitted to Aramco through the e-marketplace System. The certificate is valid for two years, and a new contract carrying a classification the certificate does not cover requires a new one.

Which certificate applies to you

Certificate type follows from classification, and the assessment approach differs materially between the two. Source: Aramco CCC Third Party Manual.

Company classificationCertificateAssessment approach
General RequirementsCCCSelf-assessment by the company, verified remotely by the Authorized Audit Firm
Outsourced InfrastructureCCCSelf-assessment by the company, verified remotely by the Authorized Audit Firm
Customized SoftwareCCCSelf-assessment by the company, verified remotely by the Authorized Audit Firm
Network ConnectivityCCC+On-site assessment conducted by the Authorized Audit Firm
Critical Data ProcessorCCC+On-site assessment conducted by the Authorized Audit Firm

Start with your classification

Classification determines the certificate, the assessment approach and the control set. It is the right first conversation.

Related services

NCA ECC 2:2024 Compliance

The national controls for government and CNI.

Explore

NCA CCC Cloud Compliance

A different CCC: the NCA's Cloud Cybersecurity Controls, not the Aramco certificate.

Explore

Cybersecurity Audit

Maturity audits and risk-rated remediation.

Explore

Aramco CCC FAQ

Do you issue the Cybersecurity Compliance Certificate?

No. The certificate is issued by an Aramco Authorized Audit Firm, selected from the list Aramco publishes at aramco.com/ccc. Our work is everything that comes before that: classification, control implementation, evidence, and preparation of the compliance report. We are explicit about this because the distinction determines who you need to contract with and when.

What decides whether I need CCC or CCC+?

Your classification. General Requirements, Outsourced Infrastructure and Customized Software lead to CCC. Network Connectivity and Critical Data Processor lead to CCC+. If more than one classification applies, all the controls under each are required, and if both certificate types apply, only CCC+ is accepted.

How do I find out my classification?

If you are registering with Aramco, you comply with the General Requirements section. If you already hold a procurement agreement, you ask each Aramco proponent organisation you do business with to complete the Third Party Classification Template, and you complete a Classification Confirmation Letter. Suppliers working across several Aramco organisations often find the combined result broader than expected.

What is the practical difference between the CCC and CCC+ assessments?

For CCC, your organisation completes the compliance assessment itself and the audit firm verifies it remotely. For CCC+, the audit firm conducts the assessment on site. That changes where preparation effort goes: CCC rewards a well-built self-assessment and evidence pack, while CCC+ rewards having the controls genuinely operating before anyone arrives.

Is partial compliance enough to get certified?

No. Aramco's manual states the certificate is issued where the company is fully compliant against all applicable requirements. Anything short of that returns a list of noncompliant controls to implement, followed by resubmission and re-verification. This is the main reason readiness work pays for itself: a second cycle costs more than getting the first one right.

How long is the certificate valid?

Two years from issuance. A new certificate is needed before that period ends, and also sooner if you are awarded a contract involving a classification type your current certificate does not cover. Both the certificate and the compliance report are submitted to Aramco through the e-marketplace System.

Is this the same as the NCA's CCC?

No, and the shared acronym causes real confusion. Aramco's CCC is a Cybersecurity Compliance Certificate for its own suppliers. The NCA's CCC is the Cloud Cybersecurity Controls framework, which applies to cloud service providers and tenants and is unrelated to Aramco procurement. If cloud controls are what you need, our NCA CCC Cloud Compliance service covers that.

We already hold ISO 27001. Does that cover us?

It helps considerably but does not substitute. An existing management system means governance, risk and evidence practices are already in place, which shortens the work. The assessment is still against Aramco's own standard and its own control set, so the gap analysis maps what you have onto what Aramco requires rather than assuming equivalence.