ISO 9001 is the baseline for every major buyer in Saudi Arabia. Aramco, SABIC, government entities on Etimad, the Royal Commission in Jubail and Yanbu, and the Vision 2030 mega-project developers all treat it as a starting condition rather than a differentiator. ISO 45001 follows if your people work on someone else’s site. ISO 14001 follows if you handle anything with an environmental footprint. After that, each buyer diverges sharply in its coding systems, document requirements and rejection triggers, and that is where most applications fail.
This guide covers all five buyer ecosystems in one place: what each requires, where their requirements overlap, and the conditions that apply everywhere regardless of which platform you are submitting to.
Which ISO Standards Does Each Saudi Buyer Require?
Contents
- 1 Which ISO Standards Does Each Saudi Buyer Require?
- 2 Saudi Aramco Vendor Registration
- 3 SABIC Vendor Registration
- 4 Etimad and Government Tenders
- 5 RCJY Contractor Registration in Jubail and Yanbu
- 6 Vision 2030 Mega-Project Suppliers
- 7 Requirements That Apply Everywhere
- 8 Which Standard Should You Start With?
- 9 What It Costs and How Long It Takes
- 10 Common Rejection Reasons Across All Platforms
- 11 Frequently Asked Questions
- 11.1 Is ISO certification legally mandatory for vendor registration in Saudi Arabia?
- 11.2 Does approval with Aramco help with SABIC registration?
- 11.3 Which ISO standard should a Saudi company get first?
- 11.4 Can I register as a vendor before getting certified?
- 11.5 What is the difference between a vendor code and a 9COM number?
- 11.6 Is an integrated management system better than separate certificates?
- 12 Get Registration-Ready with Intellitech
| Saudi Aramco | SABIC | Etimad (Government) | RCJY (Jubail/Yanbu) | Mega-Projects | |
|---|---|---|---|---|---|
| Platform | e-Marketplace, built on SAP Ariba | SABIC Supplier Portal, also SAP Ariba based | portal.etimad.sa | Royal Commission system | Each developer runs its own |
| Scope | Materials, EPC, services, technology across the oil and gas chain | Chemicals, industrial materials, maintenance, specialist technical | All ministries, municipalities and agencies | Contractors and manufacturers inside the industrial cities | NEOM, Red Sea Global, Diriyah Gate, Qiddiya, AMAALA |
| ISO 9001 | Baseline. Required before technical assessment is scheduled | Baseline for most categories | Scored in technical evaluation | Expected for classification | Standard prequalification item |
| ISO 45001 | Required for on-site service and EPC categories | Verified in prequalification | Scored in construction, healthcare, logistics, services | Expected for site work | Standard for contractors |
| ISO 14001 | Hazardous materials, chemical processing, environmentally sensitive work | Emphasised under updated sustainability requirements | Scored in relevant sectors | Expected for industrial operations | Standard |
| Sector-specific | ISO 29001 for petroleum suppliers. Cybersecurity Compliance Certificate for IT vendors | Category-dependent technical certifications | Varies by tender | Varies by activity | ISO 19650 increasingly required above SAR 100 million under MOMRAH guidelines |
| Category coding | 9COM commodity number and 9CAT category code | Portal category selection | CR activity codes | Contractor classification | Project-specific |
| Timeline | Vendor code 14 to 30 business days. 9COM qualification 3 to 6 months | 2 to 6 weeks with correct documents | Varies by entity | Varies | Varies |
| Top rejection cause | Wrong 9CAT code, entity name mismatch, unrecognised certification body | Incomplete documents, unaudited accounts | Lapsed CR, ZATCA liabilities, Saudisation non-compliance | Activity mismatch against classification | Missing sector certification |
| Registration fee | None | None | None | Varies | Varies |
Three patterns are worth pulling out of that table.
The certification requirement is remarkably consistent, and the process requirement is not. Every buyer wants ISO 9001. Almost every buyer wants 45001 for site work and 14001 for anything with an environmental dimension. Where they differ is in coding, document formats and evaluation mechanics, and that is where the months get lost. A company that holds all three certificates can still spend six months failing to register with Aramco because it selected the wrong 9CAT code.
Certification is a precondition, not a bonus. This is a shift from how ISO was treated in Saudi Arabia a decade ago. For Aramco’s in-Kingdom manufacturer approval, the quality management system should already be certified before a technical assessment is even scheduled. On Etimad, certification affects technical scoring directly, which means the absence of a certificate does not disqualify you outright but does put you behind competitors who have one before evaluation begins.
Nobody accepts a certificate at face value. Each buyer has its own view on what constitutes a valid certificate, and general accreditation is not automatically sufficient. More on this below, because it is the single most expensive mistake in this entire process.
Saudi Aramco Vendor Registration
Aramco procurement runs through its e-Marketplace platform, which is built on SAP Ariba. Suppliers create an Ariba Network account, link it to Aramco’s registration questionnaire, and submit legal, financial and technical documentation for evaluation.
The structural point that catches most suppliers is that a vendor code and a 9COM number are two different things. A vendor code means Aramco has accepted your company as a registered entity. A 9COM number qualifies you to supply a specific commodity. Companies that already hold a vendor code still need separate 9COM qualification to access commodity-based procurement, and the two run on very different timelines. The vendor code typically arrives in 14 to 30 business days. The 9COM qualification takes three to six months.
ISO 9001 sits at the front of that second process rather than inside it. For in-Kingdom manufacturers going through technical and quality approval, the quality management system should be certified to the current ISO 9001 requirements before the assessment is scheduled. The assessment then scores your facility against controls including design control, purchasing control of raw materials, receiving inspection, and identification and traceability, all of which assume a functioning quality management system already exists.
For petroleum sector suppliers specifically, ISO 29001 is the sector-adapted version of ISO 9001 and adds the supply chain risk and defect prevention requirements Aramco assessors examine most closely. Service and EPC contractors working on Aramco sites generally need ISO 45001 alongside 9001, since workforce competency evidence sits beside a certified occupational health and safety system rather than replacing it. IT and technology vendors face a Cybersecurity Compliance Certificate requirement on top of the quality certification.
Two detailed guides cover this in depth: Aramco’s ISO certification requirements and recognised certification bodies, and the 9COM documentation checklist for SAP Ariba submission.
SABIC Vendor Registration
SABIC operates its own supplier portal, also built on SAP Ariba, but with qualification criteria, category definitions and evaluation processes entirely separate from Aramco’s. Approval with one gives you nothing with the other.
The baseline requirements are broadly familiar: a legal entity registered in the Kingdom, valid Commercial Registration, industrial licence for manufacturers, VAT registration, GOSI registration, a bank letter describing your banking relationship, a company ownership profile with supporting identity documents, and an authorised signatory letter naming the employees who will deal with SABIC. Acknowledgement of SABIC’s Supplier Code of Conduct is mandatory.
ISO 9001 is effectively a baseline expectation across most SABIC categories, with additional technical certifications required depending on the product or service. What has changed more recently is emphasis. SABIC’s registration requirements have been strengthened around sustainability reporting, ethical supply chain practices and digital compliance. Suppliers whose documentation addresses only quality and financial criteria, without touching environmental and social commitments, encounter delays even when the core credentials are solid. ISO 14001 is doing real work in this context rather than sitting on a wall.
Prequalification for SABIC, like Aramco, includes verification of quality, health and safety, and environmental management systems. SABIC auditors check the level of compliance rather than the existence of a certificate, which brings us back to the recurring theme of this guide: records matter more than documents.
Timeline is usually two to six weeks where documentation is correct on first submission.
Etimad and Government Tenders
Etimad is the Ministry of Finance’s unified procurement platform, launched in 2018, and it is the gateway to every public sector contract in Saudi Arabia. Ministries, municipalities and government agencies all publish through it. Without an active Etimad registration a company cannot bid for government work regardless of its capability.
ISO certification functions differently here than with Aramco or SABIC. Rather than acting as a gate you must pass before evaluation, it feeds into the technical evaluation score. Certification appears in evaluation criteria across construction and engineering, oil and gas services, healthcare and pharmaceutical supply, food manufacturing and distribution, logistics and transport, and IT and cybersecurity. Missing the relevant certificate does not always disqualify a bid outright, but it lowers the technical score, and in competitive tenders that is functionally the same outcome.
The registration requirements themselves are less about certification and more about compliance standing. A valid Commercial Registration, ZATCA registration in good standing, Chamber of Commerce membership, and GOSI registration confirming Saudisation compliance are the core items. Companies with outstanding ZATCA liabilities, lapsed CRs or Nitaqat problems are blocked before they reach the certification question at all. Nitaqat Green or Platinum status is typically expected for tender eligibility. Foreign-owned companies additionally need a valid MISA investment licence.
One practical detail that catches international bidders: while parts of the Etimad interface are available in English, the terms and specifications booklets, technical specifications and contracts are issued in Arabic only. Any team bidding through Etimad needs Arabic legal and technical capability, not just Arabic-speaking sales staff.
Our guide to ISO certification for Saudi government tenders covers the evaluation mechanics in more detail.
RCJY Contractor Registration in Jubail and Yanbu
The Royal Commission for Jubail and Yanbu operates the two industrial cities that house most of Saudi Arabia’s petrochemical and heavy industrial capacity. Companies operating inside those cities, or supplying the operators inside them, work within an ecosystem where Aramco, SABIC, Sadara, Marafiq and dozens of EPC contractors all impose overlapping requirements.
For contractors and manufacturers based in the industrial cities, certification requirements tend to stack rather than substitute. A contractor working on a Sadara facility inside Jubail Industrial City may simultaneously need to satisfy RCJY classification requirements, the site operator’s contractor safety requirements, and its own client’s quality expectations. ISO 9001 and ISO 45001 together are the practical minimum for most site-based work, with ISO 14001 added for anything touching emissions, effluent or waste handling.
The commercial argument for an integrated management system is strongest here. Certifying 9001, 45001 and 14001 separately means three sets of documentation, three audit cycles and three surveillance schedules. An integrated system covers the same ground with one set of documentation and one coordinated audit programme, which matters when your client base includes several buyers each running their own prequalification audit.
This is also the geography where local presence changes economics. A consultant based in Al Jubail can attend a site for a gap analysis, a documentation review and an internal audit without three rounds of travel from Riyadh.
Vision 2030 Mega-Project Suppliers
NEOM, Red Sea Global, Diriyah Gate, Qiddiya and AMAALA each run their own procurement processes with their own supplier qualification criteria. Those criteria typically draw on Commercial Registration, existing Aramco or SABIC approval where relevant, and project-specific requirements layered on top.
ISO 9001, 45001 and 14001 appear consistently across prequalification requirements for these projects. The newer development is ISO 19650, the standard for information management using building information modelling. For firms working on projects above SAR 100 million, ISO 19650 is increasingly appearing as a mandatory technical requirement under MOMRAH guidelines rather than a preferred qualification.
Contractors holding integrated management system certification report stronger prequalification scores and shorter tender evaluation cycles, which is consistent with what these developers are actually screening for. They are not assessing whether you have quality procedures. They are assessing whether your management systems are mature enough to operate at the scale and pace the project demands.
Semi-government entities including Saudi Electricity Company, stc, Saudi Post and the National Water Company operate additional vendor enrolment systems relevant to suppliers in their sectors. Our Vision 2030 mega-projects certification guide covers the developer-by-developer picture.
Requirements That Apply Everywhere
These conditions cut across all five ecosystems above. Each one is a genuine rejection cause, and collectively they account for more failed applications than any technical or capability shortfall.
Audited financials, prepared correctly
Financial statements must be prepared under IFRS as adopted in Saudi Arabia and signed by a SOCPA-registered auditor. Unaudited management accounts do not satisfy the financial requirements for Aramco, SABIC or major government procurement, regardless of how healthy the numbers look. Two to three years is the usual expectation. Companies that have been trading profitably but informally often discover this requirement at the worst possible moment, since producing audited accounts retrospectively takes months.
Legal entity name consistency
The certified entity name on your ISO certificate must match your Commercial Registration exactly. Differences that look trivial cause automatic rejection: an English transliteration variant, a missing or added legal suffix, a trading name used instead of the registered name. The correction is straightforward but requires reissuing the certificate and resubmitting the application, which restarts the review clock.
Check this before the certification body issues the final certificate rather than after.
CR activities must cover what you are selling
Your registered business activities have to align with the commodity or service category you are applying under. Aramco’s 9COM and 9CAT selections are evaluated against your CR. No amount of demonstrated technical capability compensates for a CR that does not list the activity. If the activity is missing, amend the CR before you begin the registration, not during it.
Certification body recognition
This is the most expensive mistake available in this process, because it invalidates work already paid for.
Accreditation and recognition are different things. A certification body may hold full accreditation from the Saudi Accreditation Center or an IAF MLA signatory, and its certificates may be entirely legitimate, while still not appearing on a specific buyer’s internal list of recognised bodies. Aramco maintains exactly such a list. A certificate from a body outside it is rejected at prequalification regardless of accreditation validity.
The sequencing matters enormously. Confirm which certification bodies your target buyer recognises for your category before the certification engagement begins. Companies that appoint a body first and check recognition afterwards frequently discover the mismatch only when their application bounces, at which point they must recertify entirely.
Document expiry alignment
CR, VAT, Zakat, GOSI, insurance certificates and ISO certificates all run on different renewal cycles. In a document pack of twenty five or thirty items, one expired certificate holds the entire submission. Build a single expiry calendar covering everything, and align renewals where you can.
ISO certificates run three-year cycles with annual surveillance audits. Missing a surveillance audit suspends the certificate, which in turn suspends your vendor status with any buyer relying on it.
Saudisation and compliance standing
Nitaqat status affects government tender eligibility directly, with Green or Platinum typically expected. ZATCA standing must be clear. These are not certification issues, but they block registration before certification is ever assessed, so they belong on the same checklist.
Language
Etimad terms booklets, technical specifications and contracts are Arabic only. Foreign entities also need a MISA investment licence before most registration paths open at all.
Which Standard Should You Start With?
The answer depends less on your industry than on who you are trying to sell to and whether your people work on someone else’s premises.
Manufacturers and product suppliers start with ISO 9001. If your output goes into the oil and gas supply chain, consider ISO 29001 instead, since it covers the same ground plus the sector requirements Aramco assessors examine. Add product-specific certifications according to your commodity category. See our manufacturing sector guide.
EPC and construction contractors need 9001 and 45001 together, effectively as a pair, because site access requirements make safety certification non-negotiable. Add 14001 for most industrial work, and consider integrating all three. Add ISO 19650 if you are bidding on large mega-project packages. See our construction sector guide.
Oil, gas and petrochemical service providers should look at ISO 29001 plus 45001 as the core pair, with 14001 close behind. Our oil and gas guide covers the sector specifics.
IT and technology vendors need 9001 as the baseline, ISO 27001 for information security, and a Cybersecurity Compliance Certificate for Aramco categories touching its systems.
Food, pharmaceutical and medical suppliers work to sector standards alongside 9001: HACCP and ISO 22000 for food, ISO 13485 for medical devices, with SFDA requirements layered on top.
Companies selling to several of these buyers at once should seriously evaluate an integrated management system rather than sequential single-standard certifications. The documentation overlap between 9001, 45001 and 14001 is substantial, and integrating them reduces audit burden across multiple prequalification cycles.
What It Costs and How Long It Takes
| Scope | Typical SAR range | Typical timeline |
|---|---|---|
| Single standard, small to mid-size company | 8,000 to 35,000 | 30 to 60 days |
| Integrated system, two or more standards | 35,000 to 100,000+ | 4 to 9 months |
| Specialised standards (27001, 13485, 42001) | 15,000 to 90,000 | 3 to 9 months |
| Document translation and authentication for submission | 2,000 to 8,000 | 1 to 3 weeks |
Registration itself is generally free. Aramco charges no fee for e-Marketplace registration or prequalification, and neither do SABIC or Etimad. The cost sits in certification, documentation, translation and authentication.
Plan the sequence realistically. A company starting from zero, with no certification and no registration, should budget five to eight months to a live vendor status with a major buyer, not the three months the certification timeline alone suggests. Our full cost breakdown by standard has the detail.
Common Rejection Reasons Across All Platforms
| Reason | Fix |
|---|---|
| Entity name mismatch between ISO certificate and CR | Verify before certificate issuance, not after |
| CR activities do not cover the applied category | Amend the CR first |
| Wrong commodity or category code selected | Confirm the code against your CR activities before applying |
| Certification body not recognised by the buyer | Confirm recognition before appointing the body |
| Unaudited or incorrectly prepared financials | IFRS as adopted in KSA, SOCPA-registered auditor |
| Expired supporting certificate anywhere in the pack | Single expiry calendar across all documents |
| Procedures submitted where records were requested | Provide completed records, not just the procedure |
| ZATCA liabilities or Nitaqat non-compliance | Clear before applying, these block registration entirely |
| Missing Arabic documentation | Translate and authenticate ahead of submission |
The seventh row deserves emphasis because it is the one most within your control. Buyers routinely ask for a nonconformity control procedure and samples of completed nonconformity reports. Submitting the procedure alone proves you wrote a document. Submitting three closed reports with root cause analysis, corrective action and verification proves the system operates. That distinction decides more quality assessments than any other single factor.
Frequently Asked Questions
Is ISO certification legally mandatory for vendor registration in Saudi Arabia?
No. There is no law requiring ISO certification. In practice it functions as a requirement because Aramco, SABIC and most government tender evaluations either require it as a precondition or score it directly, which means companies without it are either blocked or outcompeted.
Does approval with Aramco help with SABIC registration?
Not directly. Both use SAP Ariba as the underlying platform, but qualification criteria, category definitions and evaluation processes are specific to each. You register separately with each. Existing approval with one does signal maturity, and mega-project developers sometimes reference Aramco or SABIC approval in their own criteria.
Which ISO standard should a Saudi company get first?
ISO 9001, in almost every case. It applies across all sectors, appears most frequently in tender and prequalification requirements, and forms the documentation foundation that other standards build on.
Can I register as a vendor before getting certified?
ou can usually create an account and begin a profile, but the technical and quality review will not progress without the certificate. Most companies waste time by starting registration first. Certification is the longer lead item and should start first.
What is the difference between a vendor code and a 9COM number?
A vendor code registers your company with Aramco as an entity. A 9COM number qualifies you to supply a specific commodity. Companies with a vendor code still need separate 9COM qualification for commodity-based procurement.
Is an integrated management system better than separate certificates?
For companies selling to several buyers with overlapping prequalification audits, usually yes. Documentation overlaps substantially across 9001, 45001 and 14001, and one coordinated audit programme costs less in time and money than three separate cycles.
Get Registration-Ready with Intellitech
Intellitech is an ISO certification consultancy headquartered in Al Jubail, inside the Eastern Province supplier base that feeds Aramco, SABIC, Sadara and Marafiq. Over seven years we have supported more than 200 organisations through certification, and a large share of those were preparing for exactly the registrations covered above.
Our gap analysis for vendor-registration-bound companies checks three things before touching the management system itself: whether your CR activities match the category you intend to apply under, whether your intended certification body is recognised by your target buyer, and whether your quality system is producing records or only procedures. Those three checks account for most of the rejections we see.
Fixed-price quote after the gap analysis, with a number that holds. Call +966 59 731 4200, or book a free gap analysis.



