๐Ÿ“‹ Quick Answer

The Aramco CCC+ (Cybersecurity Compliance Certificate Plus) is the enhanced certification tier required for vendors classified as Network Connectivity or Critical Data Processors under SACS-210 โ€” Saudi Aramco’s updated Third-Party Cybersecurity Standard (February 2026). Unlike the standard CCC, CCC+ mandates a full on-site audit by an Aramco-authorized audit firm. Failure to hold a valid CCC+ blocks your company from the Aramco supplier portal, contract participation, and project onboarding โ€” with no grace period.

What Is the Aramco CCC+?

The Aramco CCC+ is the higher of two certification tiers in Saudi Aramco’s Cybersecurity Compliance Certificate (CCC) Program. It is issued exclusively by Aramco-authorized audit firms after a verified on-site assessment of your organization’s cybersecurity controls, infrastructure, and documentation.

The CCC+ applies to vendors whose services expose Aramco’s most sensitive assets โ€” its corporate network and critical data. For these organizations, a remote self-assessment is insufficient. Auditors physically visit your facilities to verify that controls are not just documented, but deployed, operational, and functioning as claimed.

The CCC+ is valid for two years from the issuance date, provided your vendor classification has not changed during that period.

โš ๏ธ
Commercial consequences are immediate

A vendor without a valid CCC+ cannot be registered in Aramco’s supplier portal, cannot bid on new contracts, and cannot continue existing contract activities once the certificate lapses. There is no grace period upon expiry. Contract suspension is automatic.

CCC vs CCC+: What’s the Difference?

CCC CCC+
Who it applies toGeneral vendors, outsourced infrastructure, customized softwareNetwork connectivity vendors, critical data processors
Audit methodRemote self-assessment, validated by authorized firmFull on-site inspection by authorized audit firm
Control scope33 General Requirements (SACS-210)General Requirements + classification-specific controls
Auditor accessReviews documentation package remotelyInspects live systems, real-time configurations, access controls
Supersedesโ€”Supersedes CCC; if both apply, only CCC+ is accepted
Validity2 years2 years
๐Ÿ’ก
Critical Rule

If your classification triggers both CCC and CCC+, you submit only the CCC+ application. The CCC+ is accepted in place of the standard CCC โ€” you do not need both certificates.

Who Needs CCC+ Under SACS-210?

Your organization requires CCC+ if it falls into either of these two SACS-210 classifications:

1. Network Connectivity

Your infrastructure has direct network links to the Saudi Aramco Corporate Network. This includes:

  • Leased-line connections to Aramco facilities
  • SSL VPN or site-to-site VPN tunnels into Aramco systems
  • Remote access services enabling staff to reach Aramco’s intranet
  • Any equipment bridging your network with Aramco’s operational or corporate network

2. Critical Data Processor

Your organization processes, stores, or transmits data that Aramco classifies as critical or sensitive. This includes:

  • Companies handling Aramco financial, operational, or project data
  • Cloud service providers hosting Aramco-scoped workloads
  • Data centers processing or co-locating Aramco information
  • Analytics, AI, or BI vendors working with Aramco datasets
โ„น๏ธ
How your classification is confirmed

New vendors establish classification during Aramco supplier portal registration. Existing vendors initiate a review with their Aramco department contact, completing the Third Party Classification Template and the Third Party Classification Confirmation Letter. Misclassification is the most common cause of compliance project failures โ€” never self-assign your classification.

SACS-210: What Changed from SACS-002?

SACS-210, released February 2026, is the successor to the SACS-002 standard. The transition window closes 26 August 2026 โ€” after which all renewals are assessed against SACS-210.

๐Ÿ—“๏ธ
SACS-210 Transition Deadline: 26 August 2026

Certificates issued under SACS-002 remain valid until renewal. At renewal, SACS-210 requirements apply in full. If your renewal window is approaching, preparation must begin immediately.

๐Ÿ“‹

Expanded General Requirements

SACS-002 contained 24 general controls. SACS-210 expands this to 33 controls (TPC1.1โ€“TPC1.33), reflecting stronger governance expectations and NCA alignment.

๐Ÿญ

Dedicated OT Security Section

A new standalone OT section introduces five OT-focused controls for vendors providing industrial automation, SCADA, or process control services.

๐Ÿ‡ธ๐Ÿ‡ฆ

Stronger NCA ECC Alignment

SACS-210 formally aligns with NCA ECC 2:2024 and PDPL. Compliance gaps tolerated under SACS-002 are now explicitly addressed and auditable.

๐Ÿ“‚

Higher Evidence Standards

Auditors apply stricter scrutiny to evidence quality. Policies that exist but are not operationally implemented will be flagged as non-compliant findings under SACS-210.

The 33 General Requirements Every Vendor Must Meet

All Aramco vendors โ€” including those requiring CCC+ โ€” must first satisfy the 33 General Requirements (TPC1.1โ€“TPC1.33). These form the mandatory baseline from which classification-specific controls are added for CCC+ vendors.

๐Ÿ›๏ธ

Governance & Risk Management (TPC1.1โ€“1.4)

Documented cybersecurity policy approved by senior management. Designated cybersecurity officer. Annual formal risk assessment process.

๐Ÿ—‚๏ธ

Asset Management (TPC1.5โ€“1.9)

Maintained inventory of all hardware, software, and data repositories in Aramco scope. Assets classified by sensitivity and business impact.

๐Ÿ”‘

Access Control & MFA (TPC1.10โ€“1.14)

MFA enforced on all systems handling Aramco data. RBAC with least-privilege enforcement. Immediate access revocation upon off-boarding.

๐Ÿ’ป

Endpoint Security (TPC1.15โ€“1.18)

EDR deployed on all devices in scope. AES-256 full-disk encryption. Centralized patch management with defined remediation SLAs.

๐ŸŒ

Network Security (TPC1.19โ€“1.22)

Firewall deployment and configuration on all endpoints. Network segmentation for Aramco-scoped systems. SPF, DKIM, DMARC on corporate email domains.

๐Ÿšจ

Incident Response (TPC1.23โ€“1.26)

Documented IR plan with defined escalation procedures. Mandatory Aramco notification within 24 hours of a confirmed incident affecting scoped systems.

๐Ÿ”’

Data Protection & Backup (TPC1.27โ€“1.30)

Encryption in transit (TLS, IPSec, FTPS, HTTPS). Offline or air-gapped backups tested at defined intervals with recovery verification.

๐Ÿ“Š

Audit Logging & Monitoring (TPC1.31โ€“1.33)

Centralized, tamper-protected logs covering auth events, privilege escalations, and system changes โ€” retained per Aramco minimum periods.

CCC+-Specific Controls: Network Connectivity & Critical Data

Beyond the 33 General Requirements, CCC+ vendors must implement controls specific to their classification. These go substantially further than the baseline.

๐Ÿ”— Network Connectivity Controls

NC1
Dedicated Network Segregation

Aramco-connected infrastructure must be logically or physically isolated from your general corporate network. Aramco-scoped traffic must never traverse non-scoped systems.

NC2
Encrypted Tunnels Only

All connectivity to the Aramco Corporate Network must use approved encrypted protocols (IPSec, SSL/TLS). Unencrypted connections are non-compliant and will be flagged on-site.

NC3
VPN Configuration Management

VPN gateways must be hardened, continuously monitored, and subject to formal change management. Live configurations must be reviewable by auditors during the on-site assessment.

NC4
Remote Access Session Logging

All remote sessions into Aramco environments must generate complete, tamper-proof session logs retained for the required minimum period.

NC5
Individual User Accounts with MFA

Where staff access Aramco systems remotely, individual user accounts with MFA are mandatory. Shared or generic accounts are immediate non-compliance findings.

๐Ÿ“ฆ Critical Data Processor Controls

CD1
Data Classification & Handling

All Aramco data must be classified and handled per Aramco’s policy. Storage locations, access paths, and transmission routes must be formally documented and evidenced.

CD2
Encryption at Rest

All Aramco-scoped data stored in your environment must be encrypted at rest using AES-256 minimum. Encryption must be verifiable by auditors inspecting live storage systems.

CD3
DDoS Protection

Systems hosting or processing Aramco data require documented DDoS mitigation capabilities, formally evidenced with configuration records and service agreements.

CD4
Data Residency

Aramco data must be stored within approved geographic boundaries unless explicitly approved by Aramco otherwise. Cloud region configuration must be verified on-site.

CD5
Secure Data Sanitization

Aramco data must be securely destroyed per NIST 800-88 standards upon contract end or data lifecycle completion. Sanitization records are required as audit evidence.

The CCC+ On-Site Audit: What Auditors Actually Check

This is the defining difference between CCC and CCC+. An authorized audit firm sends qualified assessors to your premises โ€” they do not review a documentation package remotely. Here is what they examine:

1
Live System Verification

Auditors request access to your Active Directory or identity management system to verify that MFA policies are enforced, user account lists match your access register, and all terminated employee accounts have been fully revoked.

2
Firewall & Network Configuration Review

Assessors review firewall rule sets, routing tables, and VLAN configurations to confirm that network segmentation between your Aramco-scoped and non-scoped environments is implemented โ€” not just documented.

3
Endpoint Inspection

A sample of endpoints will be checked for EDR deployment, encryption status, patch levels, and local firewall enablement. Random sampling means every device in scope must be compliant.

4
Log Infrastructure Walkthrough

Auditors verify that centralized logging is operational, that log retention periods are correctly configured, and that log files are protected against tampering or unauthorized deletion.

5
Policy & Procedure Interview

Assessors interview IT staff and the designated cybersecurity officer to verify that documented policies are understood and practiced โ€” not just filed. A policy no one can explain is a finding.

6
VPN & Connectivity Verification

For Network Connectivity vendors, auditors validate VPN configurations, confirm encryption is active on all tunnels, and check whether remote access session logging is generating records in real time.

7
Evidence Cross-Validation

Every claim in your self-assessment report is cross-checked against what auditors observe on-site. Inconsistencies between documented controls and live configurations result in non-compliance findings that must be remediated before the certificate is issued.

Common Reasons CCC+ Audits Fail

Based on GHS’s experience preparing Aramco vendors for CCC+ assessments, these are the most frequent causes of audit failure at the CCC+ tier:

1
Network Segmentation Exists on Paper Only

The most critical CCC+ finding. Documentation shows a segmented network; the live configuration shows flat routing between Aramco-scoped and general systems. Auditors check the routing table, not the diagram.

2
MFA Available But Not Enforced at Policy Level

MFA is deployed but users can bypass it. Auditors check enforcement settings in your identity management platform, not whether MFA is available as an option.

3
Generic or Shared VPN Accounts

A single VPN account shared by multiple engineers, or a service account used for remote access, is an immediate non-compliance finding. Every remote user must have an individual, MFA-protected account.

4
No Active Session Logging

VPN or remote access session logging is documented as a control but not operationally generating logs โ€” or logs are not being retained for the required minimum period. Auditors verify logs are real, current, and tamper-protected.

5
Unrevoked Access for Departed Staff

Auditors routinely compare HR records of terminated employees against active user accounts. Residual accounts are a consistent finding โ€” and one that is entirely preventable.

6
Cloud Environments Without Approved Controls

Vendors using public cloud for Aramco-scoped workloads without completing cloud-specific control requirements โ€” tenant isolation, sovereign controls, access governance โ€” consistently fail CCC+.

7
Policies Employees Cannot Explain

When auditors interview IT staff, they ask how controls are implemented day-to-day. Staff who cannot describe the incident response process or MFA enrollment procedure signal a policy created for the audit, not one that is operationalized.

CCC+ Timeline: How Long Does It Take?

PhaseActivityTypical Duration
1Classification Confirmation โ€” Complete Third Party Classification Template with Aramco department1โ€“3 weeks
2Gap Assessment โ€” GHS assesses all applicable CCC+ controls against your live environment1โ€“2 weeks
3Technical Remediation โ€” Implement missing controls, harden systems, produce documentation6โ€“14 weeks
4Audit Firm Engagement โ€” Select authorized firm, sign contract, schedule on-site assessment2โ€“4 weeks
5On-Site Assessment โ€” Authorized firm conducts full on-site inspection2โ€“5 days
6Findings Remediation โ€” Close any non-compliance findings raised by the auditor2โ€“6 weeks
7Certificate Issuance โ€” Authorized firm issues CCC+ once all controls are verified1โ€“2 weeks

Total estimated time: 4 to 7 months from gap assessment to certificate issuance, assuming structured preparation. Organizations with no prior compliance baseline should plan toward the upper range.

How GHS Prepares You for CCC+ Certification

Gray Hat Security โ€” CCC+ Engagement Model

GHS is a Saudi cybersecurity consulting firm headquartered in Riyadh, specializing in Aramco CCC and CCC+ compliance for vendors across all classification tiers.

๐Ÿ”
Classification & Scoping

We work with your Aramco department contact to complete the Third Party Classification Template accurately โ€” preventing the misclassification that cascades into failed audits.

๐Ÿ“Š
CCC+ Gap Assessment

We assess all 33 General Requirements plus every applicable Specific Requirement for your classification. You receive a prioritized findings report with clear remediation actions.

โš™๏ธ
Technical Remediation

Our engineers implement the technical controls you are missing: network segmentation, MFA enforcement, VPN hardening, EDR, log infrastructure, and encryption. We implement โ€” not just advise.

๐Ÿ“„
Policy & Evidence Package

We produce the complete SACS-210-aligned documentation set: cybersecurity policy, AUP, asset inventory, risk register, incident response plan, and all supporting forms.

๐Ÿงช
Pre-Audit Simulation

Before the authorized firm arrives, GHS conducts a full pre-audit simulation โ€” testing live systems against every control auditors will check, and briefing your IT staff on interview responses.

๐Ÿค
Post-Audit Findings Closure

If the authorized firm raises findings, GHS manages the full remediation cycle โ€” implementing fixes, updating evidence, and coordinating resubmission to close your certificate.

Frequently Asked Questions

What is the Aramco CCC+?
The Aramco CCC+ (Cybersecurity Compliance Certificate Plus) is the higher-tier certification required for vendors classified as Network Connectivity providers or Critical Data Processors under Saudi Aramco’s SACS-210 Third-Party Cybersecurity Standard. Unlike the standard CCC, it requires a full on-site audit by an Aramco-authorized audit firm and is valid for two years from issuance.
Who needs CCC+ instead of the standard CCC?
Vendors who have direct network connectivity to the Saudi Aramco Corporate Network (via VPN, leased line, or remote access infrastructure) or who process, store, or transmit data Aramco classifies as critical. If your classification triggers CCC+, the standard CCC is not accepted as a substitute โ€” only the CCC+ application is processed.
What does the on-site CCC+ audit involve?
An authorized audit firm sends qualified assessors to your premises to inspect live system configurations, verify access controls in real time, review firewall and VPN settings, check endpoint security across a sample of devices, validate logging infrastructure, and interview your IT staff. Everything in your self-assessment report is cross-verified against what auditors observe in your actual environment โ€” not just your documents.
How is SACS-210 different from SACS-002 for CCC+ vendors?
SACS-210 expands the General Requirements from 24 to 33 controls (TPC1.1โ€“TPC1.33), adds a dedicated OT section with five OT-focused controls, strengthens alignment with NCA ECC 2:2024, and raises evidence quality expectations. Vendors renewing under SACS-210 should not assume their SACS-002 control set is sufficient โ€” a formal gap assessment against SACS-210 is required.
When does SACS-210 apply?
The transition window closes 26 August 2026. Existing certificates issued under SACS-002 remain valid until their renewal date; at renewal, SACS-210 requirements apply in full. New certifications from 2026 onward are assessed against SACS-210.
Can a company hold both CCC and CCC+?
No. If your classification requires CCC+, only the CCC+ application is submitted and accepted. The CCC+ supersedes and replaces the standard CCC for your organization โ€” you do not need both certificates, and Aramco will not process a standard CCC application where CCC+ applies.
What happens if we fail the CCC+ on-site audit?
The authorized audit firm issues a non-compliance report detailing what must be remediated. You remediate the findings within the prescribed window and submit updated evidence. Depending on the severity of findings, a follow-up on-site inspection may be required before the certificate is issued. GHS manages findings remediation for our clients end-to-end.
How long does CCC+ certification take?
For most vendors, four to seven months from gap assessment to certificate issuance, assuming structured preparation. Organizations without prior compliance work in place should plan toward the upper range, particularly given the SACS-210 transition deadline of 26 August 2026.
Which authorized audit firms conduct CCC+ assessments?
Aramco publishes the list of authorized audit firms on its official website. Firms that commonly appear on the list include KPMG, Deloitte & Touche Middle East, Crowe LLP, and BDO. Aramco states it has no preference among authorized firms โ€” you are free to select any firm from the published list.
Does GHS conduct the CCC+ audit?
No โ€” only Aramco-authorized audit firms can issue the CCC+ certificate. GHS prepares your organization for the audit: gap assessment, technical remediation, documentation production, and pre-audit simulation. We coordinate with your chosen authorized firm but do not conduct the certification assessment itself.
Gray Hat Security (GHS) is a Saudi cybersecurity consulting firm headquartered in Riyadh. GHS specializes in Aramco CCC and CCC+ compliance, NCA ECC, SAMA CSF, and PDPL for Saudi organizations. All content is for informational purposes only. Saudi Aramco trademarks and program names are the property of Saudi Aramco. GHS is an independent firm and is not affiliated with Saudi Aramco.