From SACS-002 to SACS-210
In February 2026 Saudi Aramco replaced SACS-002 with the Third-Party Cybersecurity Standard SACS-210. New certificates and renewals are now issued under SACS-210. We move your company to the new standard — from the gap review to the issued certificate.
One Standard for Every Aramco Third Party
SACS-210 is Saudi Aramco's Third-Party Cybersecurity Standard, released in February 2026. It applies to every third party that processes Aramco information, has access to its endpoints or network, or supplies it with technology products and services.
The standard is built around a classification model. Every third party must meet the General Requirements — 33 controls numbered TPC-1.1 to TPC-1.33. Third parties in specific classes (for example network connectivity, cloud computing or operational technology) have additional requirements on top.
Our service covers the General Requirements, which is what the Cybersecurity Compliance Certificate (CCC) for most contractors is based on.
Controls Auditors Look At Closely
Examples from the General Requirements, as published in the standard.
Multi-factor authentication
MFA on remote access, cloud services, company email on web and mobile, internet-facing applications and privileged accounts (TPC-1.12).
Company email domain
A private email domain is required — generic public domains such as Gmail and Hotmail must not be used (TPC-1.23), with SPF, DKIM and DMARC configured (TPC-1.20).
Encryption
Data encrypted at rest and in transit, in line with the Saudi National Cryptographic Standards NCS-1:2020 (TPC-1.18).
Endpoint protection
Firewall enabled on every endpoint, up-to-date anti-malware, macros from external files blocked and external storage media restricted (TPC-1.19, 1.24, 1.27, 1.29).
Logging and time sync
Audit logs enabled and protected, and all assets synchronized with an authorized time source such as NTP (TPC-1.25, 1.26, 1.31).
Incident notification
Aramco must be notified within 24 hours of discovering a cybersecurity incident (TPC-1.32).
Your Path to SACS-210
Questionnaire
You receive our SACS-210 questionnaire and tell us about your users, devices, email and current controls.
Gap review
We compare your current setup with TPC-1.1 – TPC-1.33 and define exactly what needs to be done.
Implementation
We apply the missing controls on your devices and systems and update your policies.
Evidence & audit
We prepare the screenshot evidence report, submit it and attend the live audit session.
SACS-210 certificate
On a pass, your certificate is issued under SACS-210, valid for 24 months.
Questions Clients Ask
You May Also Need
SACS-210 Certificate — Full Guide
The 33 requirements, the certification process, the audit session and validity.
Learn more →SACS-210 Certificate Renewal
We update your controls, rebuild the evidence report and attend the audit before your certificate expires.
Learn more →Cybersecurity Requirements for New Aramco Vendors
New to Aramco? What the standard asks for and how to get your first certificate.
Learn more →IT Maintenance Contracts
Computers, networks, updates and user support under one contract — remote and on-site.
Learn more →Move to SACS-210 With a Team That Does It Every Week
Send your request and the SACS-210 questionnaire reaches your inbox immediately.