Skip to content
Nour Solutions — homeNour Solutions
Consulting Services

Saudi Aramco CCC & CCC+ Compliance Services

Build SACS-210 Readiness. Strengthen Your Security. Prepare for Assessment.

Overview

Aramco Cybersecurity
Readiness.

Nour Solutions helps Saudi Aramco vendors, contractors and other applicable third parties prepare for the Cybersecurity Compliance Certificate (CCC) and CCC+ requirements under Aramco's current Third Party Cybersecurity Standard, SACS-210.

We support the preparation journey from scope and gap assessment through risk treatment, policies, technical controls, evidence, internal readiness reviews and assessment coordination. The formal assessment and certificate issuance are performed by an Aramco-authorized audit firm.

CCC preparation usually arrives with supplier work attached. Where Aramco onboarding is still in progress, vendor registration and prequalification covers that side, and an ISO/IEC 27001 information security management system carries much of the same evidence in a form other buyers also recognise.

A cybersecurity review in a boardroom above the Riyadh skyline
Aramco CCC & CCC+ Compliance

What Is Saudi Aramco CCC?

A consultant talking a control-process diagram through with a client team

Saudi Aramco's Cybersecurity Compliance Certificate (CCC) program is designed to verify the cybersecurity compliance of applicable third parties against SACS-210. Aramco's current process requires third parties to register through the applicable supplier process, complete the relevant classification steps, implement the controls that apply to their scope, and complete the required assessment through an authorized audit firm.

For businesses working with Saudi Aramco or an Aramco Group company, CCC preparation is therefore closely connected to supplier readiness, cybersecurity governance and the ability to demonstrate implemented controls and supporting evidence.

The SACS-210 Controls

SACS-210 sets out 33 cybersecurity controls for applicable third parties, covering areas such as governance and policy, asset and access management, network and endpoint security, secure configuration, logging and monitoring, vulnerability and patch management, backup and recovery, incident response, and third-party and personnel security.

Not every control carries the same weight for every supplier. The applicable set, and the depth of evidence expected against it, follow from the Third Party Classification agreed with Aramco — which is why we recommend confirming classification before remediation begins. Aramco maintains the standard and can revise it, so the control set in scope should always be confirmed against the current revision of SACS-210 rather than against a previous one.

The certificate itself is issued following assessment by an Aramco-approved audit firm. Nour Solutions prepares the organization for that assessment and does not perform it.

Aramco CCC & CCC+ Compliance

Aramco CCC vs. CCC+

AreaCCCCCC+
Assessment modelSelf-assessment followed by remote verification by an Aramco-authorized audit firm.On-site assessment by an Aramco-authorized audit firm.
ApplicabilityApplicable classifications that do not fall under the current CCC+ classifications.Aramco currently identifies Network Connectivity and Critical Data Processor classifications for CCC+.
Preparation needsScoped SACS-210 controls, evidence and assessment readiness.Higher-assurance preparation for the applicable SACS-210 scope and on-site assessment.

The exact certificate type depends on your current Aramco classification and scope. We recommend confirming classification before starting remediation.

Aramco CCC & CCC+ Compliance

Our Aramco CCC & CCC+ Compliance Services

  1. SACS-210 Scope & Readiness Assessment

    We review your business relationship, systems, data handling, connectivity and current cybersecurity controls to establish the applicable scope and starting point.

    • Scope and requirement review
    • Cybersecurity maturity review
    • Control readiness assessment
    • Initial gap identification
  2. SACS-210 Gap Assessment

    We map the relevant SACS-210 requirements against your current policies, processes and technical controls, then prioritize the gaps that require remediation.

    • Governance and policies
    • Identity and access management
    • Network and endpoint security
    • Logging and monitoring
    • Vulnerability and patch management
    • Incident response
    • Third-party security
    • Evidence readiness
  3. Cybersecurity Risk Assessment & Treatment

    We assess cybersecurity risks, document impact and likelihood, assign ownership and build a practical risk-treatment plan tied to remediation priorities.

    • Asset and threat identification
    • Vulnerability and risk analysis
    • Risk scoring
    • Business impact assessment
    • Risk treatment planning
    • Risk ownership and tracking
  4. Policies, Procedures & GRC Documentation

    We develop or improve the governance and documentation needed to support an effective SACS-210 compliance program.

    • Information Security Policy
    • Access Control and IAM procedures
    • Incident Response and Reporting
    • Data Protection and Classification
    • Backup, Recovery and Business Continuity
    • Third-Party Security
    • Asset, Vulnerability and Patch Management
  5. Technical Security Controls & Remediation

    Where technical gaps are identified, we support the implementation or improvement of appropriate controls.

    • Firewall and network security
    • Network segmentation and hardening
    • Endpoint protection and EDR
    • Multi-factor authentication
    • Secure access controls
    • SIEM and centralized logging
    • Vulnerability scanning
    • Backup and recovery controls
  6. Evidence & Compliance Report Preparation

    A compliant control also needs to be demonstrable. We organize clear, current and traceable evidence so your team can show how controls are implemented and maintained.

    • Policies and procedures
    • Configuration and system evidence
    • Logs and monitoring reports
    • Risk registers
    • Training records
    • Access reviews
    • Vulnerability and backup reports
    • Control-to-evidence mapping
  7. Internal Readiness Review / Mock Assessment

    Before the formal assessment, we review documentation, controls, evidence and team readiness to identify remaining gaps and reduce avoidable rework.

    • Control-by-control review
    • Evidence validation
    • Documentation review
    • Technical control checks
    • Interview preparation
    • Potential finding identification
  8. Audit Coordination & Finding Closure

    We support communication and preparation around the formal assessment and help analyze findings, define corrective actions and organize evidence for closure.

    The formal CCC/CCC+ assessment and certificate issuance remain the responsibility of the applicable Aramco-authorized audit firm.

Aramco CCC & CCC+ Compliance

Our SACS-210 Compliance Approach

  1. Understand — Define the Aramco relationship, classification, scope, systems and current security posture.
  2. Assess — Review the applicable SACS-210 requirements and identify gaps.
  3. Plan — Prioritize risks, assign ownership and establish the remediation roadmap.
  4. Implement — Strengthen policies, processes and technical controls.
  5. Evidence — Organize supporting records and map evidence to the applicable controls.
  6. Validate — Conduct an internal readiness review and prepare the team for assessment.
  7. Assess & Remediate — Support the formal assessment process and address applicable findings.
  8. Maintain — Keep controls, documentation and evidence current after certification.
Aramco CCC & CCC+ Compliance

Understanding the Aramco CCC Process

Aramco's current published process includes several steps before the assessment itself. The applicable third party registers through the relevant supplier process, works with the Aramco department or proponent to complete the Third Party Classification Template, confirms the classification, implements the applicable SACS-210 controls, and then completes the required compliance assessment package with an Authorized Audit Firm.

The CCC Portal is the designated channel for requesting a CCC certificate and can also be used for communication with an Authorized Audit Firm and applicable threat-management unblocking requests.

Aramco currently states that the CCC certificate is valid for two years from issuance provided the third-party classification has not changed. A new contract within the same classification does not automatically require a new certificate; changes in classification can require an additional assessment.

Aramco CCC & CCC+ Compliance

Common SACS-210 Readiness Gaps

  • Policies exist but are not consistently implemented.
  • Controls are implemented but evidence is incomplete or difficult to trace.
  • User access and privileged access are not regularly reviewed.
  • Vulnerability and patch management is inconsistent.
  • Logging and monitoring are not centrally managed.
  • Incident response procedures have not been tested.
  • Third-party security responsibilities are unclear.
  • Risk registers and treatment plans are incomplete.
  • Technical controls do not match the documented security requirements.
Aramco CCC & CCC+ Compliance

Who We Support

  • Saudi Aramco vendors and contractors
  • Engineering, EPC and industrial service companies
  • IT, software and managed-service providers
  • Cloud and technology providers
  • Manufacturers and industrial suppliers
  • Organizations preparing for Aramco cybersecurity assessment
  • Companies responding to an Aramco cybersecurity or compliance requirement
Aramco CCC & CCC+ Compliance

Why Choose Nour Solutions?

  • Saudi-focused cybersecurity and compliance support.
  • Compliance and technical capability under one service relationship.
  • Evidence-driven preparation rather than documentation alone.
  • Practical remediation based on your actual environment.
  • Structured assessment-readiness approach.
  • Ongoing support after the initial assessment when required.
Aramco CCC & CCC+ Compliance

What Nour Solutions Does — and Does Not — Certify

Nour Solutions provides cybersecurity consultancy, readiness assessment, implementation support, remediation, documentation and assessment preparation. We do not issue the Aramco CCC or CCC+ certificate.

The formal assessment and certificate issuance are handled by an Aramco-authorized audit firm. This separation keeps the consulting scope and independent assessment process clear.

A team working through a cybersecurity readiness checklist on a laptop
Aramco CCC & CCC+ Compliance

Aramco CCC Compliance Cost

There is no single fixed consultancy fee because the effort depends on your current cybersecurity maturity, Aramco classification, number of systems and sites, scope of the environment, documentation maturity and technical remediation required.

  • Current security and compliance maturity
  • Number of locations, systems and users
  • Applicable SACS-210 scope and classification
  • Existing policies and evidence
  • Technical remediation requirements
  • Need for additional security technologies
  • Assessment-firm fees, which are separate from Nour Solutions' services

A readiness assessment is the best starting point for defining scope and preparing a clear proposal.

Aramco CCC & CCC+ Compliance

Preparing for Aramco CCC or CCC+?

Start with a clear view of your scope, current controls and priority gaps. Nour Solutions can help you build an evidence-based roadmap toward SACS-210 assessment readiness.

Questions about this service?

Speak with a consultant about your requirement.

Expertise You Can Trust

Frequently Asked
Questions.

What is Aramco CCC?

The Cybersecurity Compliance Certificate is Aramco's program for assessing applicable third parties against the Third Party Cybersecurity Standard, SACS-210.

What is SACS-210?

SACS-210 is Saudi Aramco's Third Party Cybersecurity Standard that defines cybersecurity requirements applicable to third parties within the program.

What is the difference between CCC and CCC+?

CCC uses a self-assessment followed by remote verification by an Aramco-authorized audit firm for applicable classifications. CCC+ requires an on-site assessment by an authorized audit firm and currently applies to specified higher-assurance classifications such as Network Connectivity and Critical Data Processor.

Does Nour Solutions issue the Aramco CCC certificate?

No. Nour Solutions prepares organizations for assessment. The formal assessment and certificate issuance are handled by an Aramco-authorized audit firm.

How long is an Aramco CCC certificate valid?

Aramco currently states a two-year validity period, provided the third-party classification has not changed.

Do I need a new CCC for every Aramco contract?

Not necessarily. Aramco states that a new contract within the same classification does not require a new certificate. A change in classification can require an additional assessment.

Can you help if we have already received audit findings?

Yes. We can help analyze observations, define corrective actions, implement remediation and organize evidence for the applicable follow-up process.

Can you help with Aramco threat-management unblocking?

We can support the cybersecurity remediation and documentation work associated with the process. Requests through the CCC Portal remain subject to Aramco's process and requirements.

Chat with us on WhatsApp (opens in a new tab)