All services

Aramco CCC and CCC+ Readiness

A valid Cybersecurity Compliance Certificate is a precondition for doing business with Saudi Aramco. We prepare suppliers to reach it, and the Authorized Audit Firm issues it.

What the CCC is, and where we fit

The Cybersecurity Compliance Certificate confirms that an Aramco third party meets the requirements of Aramco's Third Party Cybersecurity Standard. Aramco's own Third Party Manual sets out the route: the supplier establishes its classification, implements the applicable controls, and then works with an Aramco Authorized Audit Firm, which verifies the result and issues the certificate.

Allo works on the supplier's side of that line. We prepare you for the assessment: confirming classification, closing control gaps, and assembling evidence in the form the audit firm expects. The certificate itself is issued by an Authorized Audit Firm selected from Aramco's published list, not by us.

Aramco currently refers to the standard as SACS-210. Its Third Party Manual, dated July 2021, refers throughout to SACS-002, and both designations remain in circulation. Confirm which applies to your engagement against Aramco's current supplier documentation before scoping work.

What we deliver

Preparation for the assessment. The certificate is issued by an Authorized Audit Firm.

Classification review

Establish which of the five classifications apply across every Aramco proponent organisation you work with, and what that combination requires.

Gap assessment

Assess current controls against the applicable requirements and produce a risk-rated remediation plan.

Control implementation

Close the gaps: technical controls, policy, and the operational practices behind them.

Evidence pack

Assemble evidence to the criteria Aramco states: clear, readable, time stamped, provably related to your organisation, and highlighted within screenshots.

Compliance report preparation

Prepare the Third Party Cybersecurity Compliance Report so the audit firm's verification is a check rather than a discovery exercise.

Audit support

Support through verification, including remediation and resubmission where noncompliant controls come back.

The certification route

1

Classification

Suppliers registering with Aramco comply with the General Requirements section. Suppliers with an active procurement agreement ask each Aramco proponent organisation to complete the Third Party Classification Template, plus a Classification Confirmation Letter. Where more than one classification applies, all the controls under each of them are required, and where both CCC and CCC+ apply, only CCC+ is accepted.

2

Control implementation

Implement every control applicable to the confirmed classifications. This is the bulk of the effort and the point at which most timelines slip.

3

Self-compliance assessment

For CCC, the supplier completes the Third Party Cybersecurity Compliance Report itself. Evidence must be clear, readable and time stamped, show its relation to the supplier, and be highlighted within screenshots. CCC+ suppliers skip this step, because the audit firm performs the assessment on site.

4

Select an Authorized Audit Firm

Choose a firm from Aramco's Authorized Audit Firms list and contract with it before verification begins.

5

Verification and issuance

The certificate is issued only where the supplier is fully compliant against all applicable requirements. Where it is not, the audit firm returns the noncompliant controls for implementation and re-verification.

6

Submission, validity and renewal

The issued certificate and compliance report are submitted to Aramco through the e-marketplace System. The certificate is valid for two years, and a new contract carrying a classification the certificate does not cover requires a new one.

Which certificate applies to you

Certificate type follows from classification, and the assessment approach differs materially between the two. Source: Aramco CCC Third Party Manual.

Company classificationCertificateAssessment approach
General RequirementsCCCSelf-assessment by the company, verified remotely by the Authorized Audit Firm
Outsourced InfrastructureCCCSelf-assessment by the company, verified remotely by the Authorized Audit Firm
Customized SoftwareCCCSelf-assessment by the company, verified remotely by the Authorized Audit Firm
Network ConnectivityCCC+On-site assessment conducted by the Authorized Audit Firm
Critical Data ProcessorCCC+On-site assessment conducted by the Authorized Audit Firm

Start with your classification

Classification determines the certificate, the assessment approach and the control set. It is the right first conversation.

Related services

NCA ECC 2:2024 Compliance

The national controls for government and CNI.

Explore

NCA CCC Cloud Compliance

A different CCC: the NCA's Cloud Cybersecurity Controls, not the Aramco certificate.

Explore

Cybersecurity Audit

Maturity audits and risk-rated remediation.

Explore

Aramco CCC FAQ

Find answers to common questions about our services