Saudi Aramco SACS-210
Saudi Aramco's third-party cybersecurity standard, which suppliers must satisfy to work with Aramco and its affiliates.
NUEXUS delivers readiness, gap assessment, implementation support and evidence preparation. NUEXUS is not an accredited certification body and not an auditor, and cannot certify you, issue an attestation, or sign off on a result.
How it is organised
A supply-chain requirement, so commercial rather than regulatory
This is not a law and not a voluntary framework. It is a contractual condition, which means the consequence of a gap is commercial: delayed onboarding, a failed assessment, or exclusion from a bid.
Scope follows the connection
What applies depends on how you connect to and handle Aramco data and systems. A supplier with no connectivity faces a different set of expectations from one operating inside the environment, and mis-scoping in either direction is expensive.
Evidence, on their timeline
Assessment happens on the contracting schedule, not yours. Suppliers most often fail not because their security is poor but because the evidence was not assembled before the window opened.
What an assessor will ask to see
- A defined scope of the systems and data touched by the engagement
- Control evidence in the form and language the assessment expects
- Network and connectivity documentation for any integration
- Incident response and notification arrangements covering the contract
- Subcontractor arrangements where the obligation passes further down
Where it usually goes wrong
- Scope defined by the supplier's convenience rather than by the actual connection
- Readiness work started after the contract clock has already begun
- Evidence that exists internally but not in an assessable form
- Subcontractors never assessed, so the gap surfaces during review
