ar en
HomeServicesSACS-210Siraj AICase StudiesResourcesBlogAboutContact Request a Quote →
SACS-002 cancelled · SACS-210 in force since February 2026
Standard Transition

From SACS-002 to SACS-210

In February 2026 Saudi Aramco replaced SACS-002 with the Third-Party Cybersecurity Standard SACS-210. New certificates and renewals are now issued under SACS-210. We move your company to the new standard — from the gap review to the issued certificate.

Request Your Transition → Talk to us on WhatsApp
300+
Certificates delivered
33
General Requirements
2–4
Weeks
98%
First-time pass rate
What changed

One Standard for Every Aramco Third Party

SACS-210 is Saudi Aramco's Third-Party Cybersecurity Standard, released in February 2026. It applies to every third party that processes Aramco information, has access to its endpoints or network, or supplies it with technology products and services.

The standard is built around a classification model. Every third party must meet the General Requirements — 33 controls numbered TPC-1.1 to TPC-1.33. Third parties in specific classes (for example network connectivity, cloud computing or operational technology) have additional requirements on top.

Our service covers the General Requirements, which is what the Cybersecurity Compliance Certificate (CCC) for most contractors is based on.

Request Your Transition → See all 33 requirements
SACS-210 structure
Govern
Regulatory compliance, policies, onboarding/offboarding, CCC (TPC-1.1 – 1.7)
Identify
Inventory of information and technology assets (TPC-1.8)
Protect
Identity & access, data security, email and platform security (TPC-1.9 – 1.30)
Detect
Audit and cybersecurity event logging (TPC-1.31)
Respond
Notifying Aramco of incidents within 24 hours, and when staff no longer need access (TPC-1.32 – 1.33)
What SACS-210 expects

Controls Auditors Look At Closely

Examples from the General Requirements, as published in the standard.

Multi-factor authentication

MFA on remote access, cloud services, company email on web and mobile, internet-facing applications and privileged accounts (TPC-1.12).

Company email domain

A private email domain is required — generic public domains such as Gmail and Hotmail must not be used (TPC-1.23), with SPF, DKIM and DMARC configured (TPC-1.20).

Encryption

Data encrypted at rest and in transit, in line with the Saudi National Cryptographic Standards NCS-1:2020 (TPC-1.18).

Endpoint protection

Firewall enabled on every endpoint, up-to-date anti-malware, macros from external files blocked and external storage media restricted (TPC-1.19, 1.24, 1.27, 1.29).

Logging and time sync

Audit logs enabled and protected, and all assets synchronized with an authorized time source such as NTP (TPC-1.25, 1.26, 1.31).

Incident notification

Aramco must be notified within 24 hours of discovering a cybersecurity incident (TPC-1.32).

How we move you

Your Path to SACS-210

STEP 1

Questionnaire

You receive our SACS-210 questionnaire and tell us about your users, devices, email and current controls.

STEP 2

Gap review

We compare your current setup with TPC-1.1 – TPC-1.33 and define exactly what needs to be done.

STEP 3

Implementation

We apply the missing controls on your devices and systems and update your policies.

STEP 4

Evidence & audit

We prepare the screenshot evidence report, submit it and attend the live audit session.

STEP 5

SACS-210 certificate

On a pass, your certificate is issued under SACS-210, valid for 24 months.

FAQ

Questions Clients Ask

No. SACS-002 was cancelled in February 2026 and replaced by SACS-210. New certificates and renewals are issued under SACS-210.
No. Controls you already have in place — MFA, anti-virus, email security, policies — still count. We review them against SACS-210 and implement only what is missing.
The General Requirements, which apply to every third party, contain 33 controls (TPC-1.1 to TPC-1.33). Specific classes have additional requirements.
Our service covers the General Requirements TPC-1.1 – TPC-1.33. If your company falls under a specific class, tell us and we will explain what we can cover.
Usually 2–4 weeks from kickoff to issued certificate, depending on the number of devices and how many controls are already in place.

All frequently asked questions →

Related Services

You May Also Need

Move to SACS-210 With a Team That Does It Every Week

Send your request and the SACS-210 questionnaire reaches your inbox immediately.

Request Your Transition → +966 54 048 1582
Book Free Consultation → 💬
💬
👋

Need Cybersecurity Help?

Chat with our Saudi-based experts on WhatsApp — get answers in minutes, not hours.

💬 Chat on WhatsApp
🛡️
Siraj Assistant
Online · Replies instantly