Aramco CCC and CCC+ Readiness
A valid Cybersecurity Compliance Certificate is a precondition for doing business with Saudi Aramco. We prepare suppliers to reach it, and the Authorized Audit Firm issues it.
What the CCC is, and where we fit
The Cybersecurity Compliance Certificate confirms that an Aramco third party meets the requirements of Aramco's Third Party Cybersecurity Standard. Aramco's own Third Party Manual sets out the route: the supplier establishes its classification, implements the applicable controls, and then works with an Aramco Authorized Audit Firm, which verifies the result and issues the certificate.
Allo works on the supplier's side of that line. We prepare you for the assessment: confirming classification, closing control gaps, and assembling evidence in the form the audit firm expects. The certificate itself is issued by an Authorized Audit Firm selected from Aramco's published list, not by us.
Aramco currently refers to the standard as SACS-210. Its Third Party Manual, dated July 2021, refers throughout to SACS-002, and both designations remain in circulation. Confirm which applies to your engagement against Aramco's current supplier documentation before scoping work.
What we deliver
Preparation for the assessment. The certificate is issued by an Authorized Audit Firm.
Classification review
Establish which of the five classifications apply across every Aramco proponent organisation you work with, and what that combination requires.
Gap assessment
Assess current controls against the applicable requirements and produce a risk-rated remediation plan.
Control implementation
Close the gaps: technical controls, policy, and the operational practices behind them.
Evidence pack
Assemble evidence to the criteria Aramco states: clear, readable, time stamped, provably related to your organisation, and highlighted within screenshots.
Compliance report preparation
Prepare the Third Party Cybersecurity Compliance Report so the audit firm's verification is a check rather than a discovery exercise.
Audit support
Support through verification, including remediation and resubmission where noncompliant controls come back.
The certification route
Classification
Suppliers registering with Aramco comply with the General Requirements section. Suppliers with an active procurement agreement ask each Aramco proponent organisation to complete the Third Party Classification Template, plus a Classification Confirmation Letter. Where more than one classification applies, all the controls under each of them are required, and where both CCC and CCC+ apply, only CCC+ is accepted.
Control implementation
Implement every control applicable to the confirmed classifications. This is the bulk of the effort and the point at which most timelines slip.
Self-compliance assessment
For CCC, the supplier completes the Third Party Cybersecurity Compliance Report itself. Evidence must be clear, readable and time stamped, show its relation to the supplier, and be highlighted within screenshots. CCC+ suppliers skip this step, because the audit firm performs the assessment on site.
Select an Authorized Audit Firm
Choose a firm from Aramco's Authorized Audit Firms list and contract with it before verification begins.
Verification and issuance
The certificate is issued only where the supplier is fully compliant against all applicable requirements. Where it is not, the audit firm returns the noncompliant controls for implementation and re-verification.
Submission, validity and renewal
The issued certificate and compliance report are submitted to Aramco through the e-marketplace System. The certificate is valid for two years, and a new contract carrying a classification the certificate does not cover requires a new one.
Which certificate applies to you
Certificate type follows from classification, and the assessment approach differs materially between the two. Source: Aramco CCC Third Party Manual.
| Company classification | Certificate | Assessment approach |
|---|---|---|
| General Requirements | CCC | Self-assessment by the company, verified remotely by the Authorized Audit Firm |
| Outsourced Infrastructure | CCC | Self-assessment by the company, verified remotely by the Authorized Audit Firm |
| Customized Software | CCC | Self-assessment by the company, verified remotely by the Authorized Audit Firm |
| Network Connectivity | CCC+ | On-site assessment conducted by the Authorized Audit Firm |
| Critical Data Processor | CCC+ | On-site assessment conducted by the Authorized Audit Firm |
Start with your classification
Classification determines the certificate, the assessment approach and the control set. It is the right first conversation.
Aramco CCC FAQ
Find answers to common questions about our services