11 August 2026
Aramco SACS 210 vs SACS 002: Key Changes
Aramco's SACS 210 and SACS 002 set cybersecurity expectations for vendors. Here's what changed and how to prepare for assessments.
Aramco SACS 210 vs SACS 002: Key Changes
If your organization supplies products or services to Saudi Aramco, understanding the transition from SACS 002 to SACS 210 is essential. While both standards are designed to establish cybersecurity expectations for suppliers, SACS 210 introduces a revised framework that better reflects today's technology landscape, including cloud services, operational technology (OT), secure software development, and third-party risk management.
Suppliers preparing for a Cybersecurity Compliance Certificate (CCC) assessment, should review their existing cybersecurity program against SACS 210 to identify any new or revised requirements before their next assessment.
Purpose : SACS 210
Cyber threats have evolved significantly since SACS 002 was introduced. Organizations increasingly rely on cloud platforms, remote connectivity, software-as-a-service, industrial control systems, and complex supply chains. SACS 210 updates the supplier cybersecurity framework to better address these realities while aligning more closely with internationally recognized cybersecurity practices.
Although many of the core security principles remain unchanged, suppliers should expect more structured governance, clearer requirements for specialized technologies, and greater emphasis on demonstrating that controls are operating effectively.
SACS 210 vs SACS 002 – At a Glance

General Requirements: Stronger Cybersecurity Governance
The General Requirements apply to organizations within the scope of the SACS program regardless of the services they provide.
Compared to SACS 002, SACS 210 places greater emphasis on establishing an organized cybersecurity management program rather than implementing isolated technical controls.
Organizations should be prepared to demonstrate:
- Documented cybersecurity policies and procedures
- Clearly defined security roles and responsibilities
- Periodic cybersecurity risk assessments
- Risk treatment and remediation processes
- Ongoing management oversight of cybersecurity activities
Rather than creating documentation only for an assessment, suppliers should ensure these processes become part of normal business operations.
More Focus on Risk Management
Risk management receives greater attention under SACS 210.
Organizations should identify cybersecurity risks, assess their business impact, define appropriate mitigation measures, and periodically review those risks as technologies and business processes evolve.
This encourages suppliers to adopt a continuous risk management approach instead of treating compliance as a one-time exercise.
Third-Party and Supply Chain Security
Modern organizations rarely operate in isolation.
Many suppliers depend on subcontractors, managed service providers, cloud vendors, and software suppliers to deliver services.
SACS 210 places greater emphasis on understanding and managing cybersecurity risks associated with these third parties. Organizations should have appropriate processes for evaluating supplier risks and ensuring external providers do not introduce unacceptable cybersecurity exposure.
Specialized Requirements for Technology Providers
One of the most significant enhancements in SACS 210 is the inclusion of specialized requirements for suppliers providing specific technologies or services.
Not every supplier will need to comply with every specialized requirement. The applicable controls depend on the nature of the products and services being provided to Aramco.
Operational Technology (OT)
Organizations involved in industrial control systems, operational technology, automation, or engineering environments should expect cybersecurity requirements that reflect established OT security practices.
Depending on the services provided, suppliers may also need to demonstrate alignment with recognized industrial cybersecurity standards such as ISA/IEC 62443 where applicable.
Cloud Services
Cloud providers and organizations hosting Aramco-related workloads should demonstrate appropriate cloud security governance.
Typical focus areas include:
- Identity and access management
- Encryption
- Logging and monitoring
- Data protection
- Security responsibilities between customer and provider
Organizations already aligned with recognized cloud security standards may find many of these requirements familiar.
Secure Software Development
Organizations developing software, applications, or digital platforms should maintain a secure software development lifecycle (Secure SDLC).
This generally includes:
- Secure development practices
- Security testing
- Vulnerability management
- Patch management
- Procedures for addressing software security issues throughout the product lifecycle
Greater Importance of Assessment Evidence
One practical difference suppliers often notice during assessments is the increased importance of implementation evidence.
Having a documented policy alone is generally insufficient.
Assessors are likely to expect objective evidence that required controls are operating effectively.
Examples include:
- Risk assessment reports
- Asset inventories
- Security policies
- Vulnerability assessment reports
- Patch management records
- Access review records
- Security awareness training records
- Incident response documentation
- Monitoring and audit logs where applicable
Organizations that maintain this evidence throughout the year are generally better prepared for assessments than those attempting to collect it shortly before an audit.
Practical Comparison
The following table summarizes the practical differences suppliers are most likely to experience.

How Suppliers Should Prepare
Organizations transitioning to SACS 210 should consider the following steps:
- Review the SACS 210 requirements applicable to your organization.
- Identify any specialized requirements relevant to the services you provide.
- Perform a formal gap assessment against your existing cybersecurity program.
- Update governance processes, policies, and technical controls where necessary.
- Collect implementation evidence as controls are operated rather than waiting until the assessment.
- Conduct an internal readiness review before the official Cybersecurity Compliance Certificate (CCC) assessment.
Final Thoughts
SACS 210 represents the evolution of Aramco's supplier cybersecurity expectations rather than a complete departure from SACS 002. The framework continues to emphasize sound cybersecurity fundamentals while introducing more structured governance, enhanced requirements for specialized technologies, and greater focus on demonstrating that controls are effectively implemented.
Organizations that begin reviewing their compliance posture early will be better positioned for a smoother Cybersecurity Compliance Certificate (CCC) assessment and can reduce the effort required during formal audits.
If your organization is preparing for a SACS 210 assessment, AxpertCyber can help you perform a gap assessment, identify compliance gaps, and develop a practical roadmap toward successful certification.