The Cybersecurity Compliance Certificate (Aramco) or the SAMA Cybersecurity Framework are two very different cybersecurity certifications that are likely to be referenced if you work in Saudi Arabia. Companies frequently confuse the two, which makes sense given that both are required, originate from influential authorities, and centre on controls that sound similar. However, applying for the incorrect one wastes months of audit preparation because they oversee entirely different industries. We've shown how to determine which of the two procedures applies to you after guiding financial industry clients and vendors around the GCC through both.
Any vendor, contractor, or service provider that wishes to do business with Saudi Aramco must have the Aramco cybersecurity compliance certificate. It verifies that your company complies with the cybersecurity guidelines outlined in Aramco's Third-Party Cybersecurity Standard. Vendors are categorised according to the kind of access they will have (generic vendors, network-connectivity providers, or key data processors), and this categorisation dictates whether a more stringent on-site audit (CCC+) or a remote assessment (CCC) is necessary.
In practical terms, this entails filling out a compliance report, creating an evidence base consisting of asset inventories, access review records, and incident-response documentation, and having it verified by an audit company authorised by Aramco prior to the certificate being granted via the Aramco e-Marketplace. Regardless of how compelling your commercial proposal is, your company simply cannot be onboarded as an Aramco supplier without it. As long as your vendor categorisation doesn't change during that time, the certificate is normally good for two years.
Banks, insurance and reinsurance firms, finance firms, payment service providers, fintechs, digital banks, and capital market institutions that are subject to SAMA regulation are all covered by the SAMA Cybersecurity Framework (CSF), which is published by the Saudi Central Bank. Unlike Aramco's CCC, SAMA CSF is a sector-wide regulatory requirement that all SAMA-regulated entities must implement, self-evaluate against, and report on on a regular basis.
According to SAMA's six-level maturity model, regulated businesses must achieve at least Level 3, which denotes standardised, documented controls for operations, governance, and third-party risk. Additionally, compliance is not a one-time audit event; it necessitates annual penetration testing, quarterly vulnerability assessments on vital systems, mandated staff training, and continuous self-evaluations that SAMA directly reviews. In addition to losing a contract, noncompliance may result in financial penalties and supervisory action.
One question usually determines the difference: who are you attempting to do business with, and in what capacity?
The Aramco Cybersecurity Compliance Certificate, not SAMA CSF, is required if you are bidding for or currently have contracts with Saudi Aramco as a supplier, contractor, or IT/OT service provider having access to Aramco's systems.
SAMA CSF directly affects banks, insurers, payment processors, fintech companies, and any other organisation subject to Saudi Central Bank regulation. It is a requirement of your regulatory license and is not optional nor contract-dependent.
You might have to meet the criteria of both frameworks at the same time, each with its own audit trail and evidence requirements, if your company serves both markets, such as an IT provider working with Aramco and managing systems for a finance customer subject to SAMA regulation.
Fortunately, one framework's foundation is rarely wasted on another. The cornerstones of both regimes include asset inventories, access control, incident response planning, and employee security training. Because the proof is already being produced as part of regular operations, organisations that approach cybersecurity compliance as a continuing operational discipline rather than a one-time audit sprint typically advance through either certification more quickly.
The good news is that groundwork for one framework rarely goes to waste for the other. Access management, incident response planning, asset inventories, and staff security training are foundational to both regimes. Organizations that treat cybersecurity compliance as an ongoing operational discipline — not a one-off audit sprint tend to move through either certification faster, because the evidence is already being generated as part of normal operations.
If you already hold an Aramco Cybersecurity Compliance Certificate, there's a change underway that's easy to miss until it directly affects your renewal. Aramco has rolled out SACS-210, an updated Third-Party Cybersecurity Standard that replaces the older SACS-002 framework your certificate may currently be assessed against. It isn't a minor revision SACS-210 restructures the requirements into 33 mandatory controls (referenced as TPC1.1 through TPC1.33), covering governance, access management, data protection, and incident response in far more depth than the previous standard.
Existing SACS-002 certificates remain valid until their original expiry date, so there's no need to panic if yours was recently issued. But here's the part vendors tend to overlook: any new contract, or any renewal processed after 26 August 2026, must be assessed against SACS-210, not the older standard. That distinction matters because the new control set brings a noticeably heavier evidence burden expanded data-protection requirements, defined incident-response service-level timelines, and stricter access-management documentation than SACS-002 asked for.
For vendors still operating under SACS-002, the practical takeaway is to stop treating this as a distant deadline. Gap analysis alone mapping your current policies and evidence against all 33 SACS-210 controls takes real time, and that's before you've addressed any shortfalls or gathered fresh documentation. Businesses that start the gap assessment now, well ahead of their renewal window, avoid the scramble that comes with discovering missing controls a few weeks before a contract lapses.
If you're unsure whether your current certificate falls under SACS-002 or SACS-210, or when your specific renewal cycle will require the switch, that's worth confirming directly with your Authorized Audit Firm or a compliance partner before it becomes a deadline-driven problem rather than a planned one.
One of the most frequent causes of audit delays or failures for firms is misjudging which framework applies (or underestimating the proof each require). Friday Infotech's compliance team works with companies throughout Bahrain and Saudi Arabia to get this right from the first submission, whether you're getting ready for an Aramco vendor registration, assessing whether SAMA CSF affects your operations, or need assistance creating the documentation trail either one requires.
FIT Solutions is a software development company, renowned for delivering innovative and customized technology solutions.