Secure Controls Framework
Download The SCF

Frequently Asked Questions (FAQ)

Everything you need to know about the Secure Controls Framework® (SCF), the Common Controls Framework™, from getting started and understanding the metaframework to SCF CAP certification, licensing, and implementation.

General

About the Secure Controls Framework®

Foundational questions about what the SCF is, why it exists, and what makes it different from other cybersecurity frameworks.

What Is The SCF?

The SCF stands for the Secure Controls Framework. It is more than just an assortment of cybersecurity and data privacy controls. It is focused on designing, implementing and maintaining secure, compliant, and resilient capabilities to address all applicable statutory, regulatory and contractual requirements that an organization faces.

Our belief is that if you scope your requirements with security in mind, compliance will generally be a natural byproduct of those secure and resilient actions. We want organizations to be secure, compliant and resilient, since it benefits all of modern society.

Why Does The SCF Say It Is The Common Controls Framework?

The use of Common Controls Framework™ is trademarked and the SCF has exclusive rights to use the term. The SCF is the Common Controls Framework™ (CCF) because in addition to providing a common set of controls that organizations use to satisfy multiple compliance obligations simultaneously through a single, unified control set, the SCF owns the domains commoncontrolsframework.com and common-controls-framework.com.

What Is A Metaframework?

A "metaframework" is a framework of frameworks. That is exactly what the SCF is. It is a framework made up of over 200 cybersecurity and data privacy laws, regulations and frameworks. Rather than implementing each framework separately, the SCF provides a single comprehensive control set that maps to all of them simultaneously.

How Is The SCF Different From NIST, ISO 27001, or CIS Controls?

NIST CSF, ISO 27001, and CIS Critical Security Controls are individual cybersecurity frameworks. The SCF is a metaframework that encompasses all of them, and over 200 others. When you implement the SCF, you are implementing the common controls that satisfy NIST, ISO, CIS, and many other frameworks simultaneously.

This eliminates the need to maintain separate control sets for each framework, regulation, or law your organization must comply with. The SCF’s Set Theory Relationship Mapping (STRM) methodology ensures these mappings are mathematically rigorous, not subjective crosswalks.

How Often Is The SCF Updated?

The general cadence for updates is one (1) update per quarter. There may be situations where out-of-cycle updates are released, but the goal is to publish updates on a quarterly basis. The SCF is a Living Control Set, meaning it is continuously maintained and updated to reflect changes in the regulatory landscape.

Does The SCF Cover Artificial Intelligence (AI)?

Yes. The SCF has had coverage for AI since 2024. The Artificial Intelligence & Autonomous Technologies (AAT) domain is one of thirty-three domains in the SCF. That domain has coverage for these AI-specific requirements:

  • ISO 42001
  • NIST AI Risk Management Framework
  • NIST 600-1 (Generative AI)
  • EU AI Act
Getting Started

How To Start Using The SCF

Practical questions about downloading, implementing, and operationalizing the SCF in your organization.

Where Do I Start?

The best place to begin is the Start Here page. It provides a guided introduction to the Secure Controls Framework, what it is, how it works, and how to begin using it in your organization. The page walks you through the SCF's structure, its 33 domains, the metaframework concept, and links to the key resources you'll need.

  1. Read the Start Here Guide: The SCF Recommended Practices (PDF) gives you a concise overview of how to get started.
  2. Understand the SCRMS: The Security, Compliance & Resilience Management System is the SCF's implementation methodology, your roadmap for building an SCF-based program.
  3. Download the SCF: Grab the free Excel, CSV, or NIST OSCAL JSON version from the SCF Download page and start tailoring controls to your needs.

How Do I Use The SCF?

Start by reading the "What Is The SCF" page, which includes a Start Here Guide for recommended practices.

To build an SCF-based cybersecurity program, begin with the Security, Compliance & Resilience Management System (SCRMS) and the SCRMS Prioritized Implementation Guide (SCRMS-PIG). These provide a "paint by numbers" approach to creating a tailored, prioritized set of controls.

Once ready to start working with the SCF, you can either:

  1. Download the Excel version from the SCF Download page and create your own control set; or
  2. Use a GRC platform like SCF Connect or others listed on the SCF Marketplace.

What Is The SCRMS And Why Does It Matter?

The Security, Compliance & Resilience Management System (SCRMS) is the SCF’s implementation methodology. It provides the structured approach for designing, building, and maintaining a cybersecurity program using the SCF. Think of it as the "how to" guide for turning SCF controls into an operational program.

The SCRMS covers the full lifecycle: scoping, tailoring controls, implementing, operating, and continuously improving your program across the People, Process, Technology, Data, and Facilities (PPTDF) dimensions.

What Does “Mechanisms Exist” Mean In SCF Controls?

The SCF controls are written to be flexible for organizations of any size or industry. The term "mechanism" can mean a manual process, technology solution, or anything in between. If you prefer different wording, you can replace "mechanism" with "solution," "processes," or another term that fits your organization’s context.

The key point is that a mechanism demonstrates that the control requirement is being addressed, whether through a documented procedure, an automated tool, or a combination of both.

What If I Get Stuck And Need Help?

If you need assistance with tailoring or operationalizing the SCF, there are several options:

Controls & Domains

SCF Controls, Domains & Structure

Questions about the SCF’s control structure, domain organization, risk model, maturity model, and how controls work in practice.

How Many Controls Does The SCF Have?

The SCF contains over 1,400 controls across 33 domains. These controls are mapped to over 200 cybersecurity and data privacy laws, regulations, and frameworks. The SCF is a comprehensive catalog. You are not expected to implement all 1,400+ controls. The tailoring process helps you select only the controls applicable to your organization.

What Are The 33 SCF Domains?

The SCF is organized into 33 control domains that cover every aspect of cybersecurity and data protection. These range from Governance (GOV) and Risk Management (RSK) to specialized domains like Artificial Intelligence & Autonomous Technologies (AAT), Supply Chain Risk Management (SCR), and Web Security (WEB). You can explore the full list on the SCF Domains & Principles page.

What Are Assessment Objectives (AOs)?

Assessment Objectives (AOs) are the specific, testable criteria used to evaluate whether a control is appropriately designed, properly implemented, and producing the desired security outcome. Each SCF control has one or more AOs that assessors use during SCF CAP conformity assessments.

AOs are defined in the Cybersecurity & Data Protection Assessment Standards (CDPAS), which is free to download.

What Is The SCF Risk Model (SCR-RMM)?

The Security, Compliance & Resilience Risk Management Model (SCR-RMM) is the SCF’s free, integrated risk model. It provides a structured approach to identifying, analyzing, and managing cybersecurity and data privacy risks at the control level. Rather than treating risk management as a separate exercise, the SCR-RMM embeds risk directly into the SCF’s control structure.

The SCR-RMM maps specific risks and threats to each SCF control, giving organizations a clear view of what could go wrong if a control is absent or inadequate. This enables risk-informed decision-making when tailoring and prioritizing controls. You can see exactly which risks you are accepting, mitigating, or transferring for every control in your program.

The SCR-RMM is available as a free download from the SCR-RMM page.

What Is The SCF Maturity Model (SCR-CMM)?

The Security, Compliance & Resilience Capability Maturity Model (SCR-CMM) is the SCF’s free maturity model that allows organizations to measure and benchmark the maturity of their cybersecurity and data privacy practices at the control level. It provides quantifiable maturity criteria for each SCF control across defined maturity levels.

The SCR-CMM helps organizations answer the question "how good are we?" by providing a consistent scale for evaluating People, Processes, and Technology (PPT) across every control. This supports capability gap analysis, investment prioritization, and board-level reporting on cybersecurity program maturity over time.

The SCR-CMM is available as a free download from the SCR-CMM page.

How Do You Define Cybersecurity Materiality?

Cybersecurity materiality is the concept of determining which cybersecurity and data privacy risks are significant enough to warrant attention, investment, and disclosure. Drawing from the financial auditing concept of materiality, it applies the same principle to cybersecurity: not every risk is equal, and organizations must determine which risks, if left unaddressed, could materially impact the business.

The SCF addresses cybersecurity materiality as a GRC Fundamentals topic. In practice, this means defining thresholds for what constitutes a "material" cybersecurity risk or deficiency in your organization, which informs control scoping, investment decisions, board reporting, and regulatory disclosure obligations (e.g., SEC cybersecurity incident disclosure rules).

Materiality is particularly relevant for organizations subject to regulatory disclosure requirements, public companies, and any organization communicating cybersecurity posture to stakeholders, investors, or regulators.

Metaframework & Mapping

Metaframework Methodology & STRM Mapping

How the SCF maps to 200+ laws, regulations, and frameworks using rigorous Set Theory Relationship Mapping.

How Does The SCF Map To 200+ Frameworks?

The SCF uses Set Theory Relationship Mapping (STRM), a mathematically rigorous methodology based on NIST IR 8477, to map controls to external frameworks, laws, and regulations. Unlike subjective crosswalks, STRM uses set theory to define the precise relationship between SCF controls and external requirements, producing mappings that are accurate, consistent, and defensible.

What Is STRM And Why Does It Matter?

Set Theory Relationship Mapping (STRM) is the gold standard for crosswalk mapping between cybersecurity and data privacy requirements. It replaces subjective "best guess" crosswalks with a mathematical model that precisely defines the relationship between controls and external requirements.

The SCF is a recognized NIST OLIR Program participant with accepted mappings between the SCF and NIST frameworks.

What Laws, Regulations & Frameworks Does The SCF Cover?

The SCF maps to over 200 laws, regulations, and frameworks including NIST CSF, NIST 800-53, NIST 800-171, ISO 27001/27002, CIS Controls, CMMC, HIPAA, GDPR, PCI DSS, SOC 2 TSC, CCPA/CPRA, NIS2, DORA, FedRAMP, SOX, GLBA, and many more. The complete list is available on the Included Laws, Regulations & Frameworks (LRF) page.

Licensing & Cost

Licensing, Cost & Usage Rights

Questions about why the SCF is free, what the Creative Commons license allows, and commercial licensing options.

Why Is The SCF Free To Use?

The SCF is free to help fix the broken nature of cybersecurity and data protection practices in many organizations. The quality of the SCF could easily justify a costly subscription service, but that would exclude most organizations and defeat the broader goal of improving cybersecurity and privacy practices on a macro scale.

The SCF’s contributors are volunteers, and the project relies on generous sponsors to maintain the framework.

Are There Restrictions On The Use Of The SCF?

The SCF is copyrighted material that uses the Creative Commons licensing model to keep it free for businesses to use. The Terms & Conditions page details the open license granted for organizational use. There are options for commercial licenses for companies that want to create derivative content based on the SCF.

Technical & Formats

SCF Conformity Assessment Program

Questions about SCF CAP certification for organizations, including assessment methodology, 3PAOs, and The CyberAB.

What Is The SCF CAP?

The SCF Conformity Assessment Program (SCF CAP) is the organization-level certification program that allows organizations to demonstrate conformity with SCF-based cybersecurity and data protection requirements. Assessments are conducted by accredited Third-Party Assessment Organizations (3PAOs) using the examine, interview, and test (EIT) methodology.

What Is The CyberAB?

The CyberAB is the official Accreditation Body (AB) for the SCF Conformity Assessment Program (SCF CAP). The CyberAB accredits 3PAOs, maintains the SCF Marketplace, and oversees the accreditation standards that ensure assessment quality and independence.

What Are SCF Assessment Guides?

SCF Assessment Guides are pre-built, ready-to-use assessment packages that define the specific set of controls an organization must implement and be assessed against for a particular compliance objective (e.g., NIST CSF 2.0, CMMC Level 1, HIPAA). Each guide maps to the relevant SCF controls and Assessment Objectives for that certification track.

Get Started With The SCF

SCF Training & Individual Certifications

Questions about the three SAICO individual certification tracks and how to get certified.

What Is SAICO?

SAICO is the SCF Assessor and Instructor Certification Organization. SAICO provides three Computer-Based Training (CBT) certification programs for individuals: SCF Practitioner (foundation), SCF Architect (design & implementation), and SCF Assessor (assessment & audit).

What Are The Three SAICO Certification Levels?

The three SAICO certification tracks are:

  1. SCF Practitioner: Foundation level. Implement and maintain SCF-based controls. No prerequisites.
  2. SCF Architect: Intermediate level. Design and architect SCF-based programs. Builds on Practitioner knowledge.
  3. SCF Assessor: Advanced level. Lead or participate in 3PAO assessment teams conducting SCF CAP conformity assessments.

All three are delivered via self-paced CBT through the SCF Training Platform.

Marketplace & Ecosystem

SCF Marketplace & Ecosystem Partners

Questions about the SCF partner ecosystem, marketplace participants, and how to find SCF expertise.

What Is The SCF Marketplace?

The SCF Marketplace connects organizations with SCF expertise. It includes six categories of ecosystem participants: 3PAOs (assessment organizations), ASPs (solution providers), RPOs (consulting providers), ACIs (control integrators), LTPs (training providers), and LCPs (content providers). The authoritative listing is maintained by The CyberAB.

What Is SCF Connect?

SCF Connect is the SCF-specific GRC platform built from the ground up to operationalize the Secure Controls Framework. It is the official Single Source of Truth (SSOT) for SCF CAP third-party conformity assessments. SCF Connect is priced at $200/month and provides an intuitive SaaS platform for implementing, managing, and reporting on SCF-based cybersecurity programs.

Contact Us

Download Formats & Technical Details

Questions about the SCF download formats, NIST OSCAL support, and technical integration options.

What Formats Is The SCF Available In?

The SCF is available for free download in multiple formats:

  • Microsoft Excel (.xlsx): The primary format for working with SCF controls, tailoring, and GRC import.
  • CSV (.csv): For programmatic import into GRC platforms and databases.
  • NIST OSCAL JSON: Machine-readable format following the NIST Open Security Controls Assessment Language standard for automated processing.

What Is NIST OSCAL And Why Does The SCF Support It?

NIST OSCAL (Open Security Controls Assessment Language) is a standardized, machine-readable format for representing cybersecurity controls, assessment results, and system security plans. The SCF supports OSCAL JSON to enable automated ingestion by GRC platforms, security tooling, and compliance automation systems, eliminating manual data entry and enabling continuous compliance monitoring.

What Free Content Does The SCF Provide Besides The Controls?

The SCF provides a comprehensive library of free content beyond the control catalog:

  • SCR-RMM: Security, Compliance & Resilience Risk Management Model
  • SCR-CMM: Security, Compliance & Resilience Capability Maturity Model
  • CDPAS : Cybersecurity & Data Protection Assessment Standards
  • ERL : Evidence Request List for assessments
  • USG : Unified Scoping Guide
  • DPMP : Data Privacy Management Principles
  • MA&D: Mergers, Acquisitions & Divestitures security guidance
Additional Questions

Additional Frequently Asked Questions (FAQs)

What is OSCAL and which frameworks support it?
The Secure Controls Framework supports OSCAL, the Open Security Controls Assessment Language. Each SCF download ships Excel plus OSCAL-ready JSON versions.
What is the difference between Third-Party Risk Management (TPRM) and C-SCRM?
TPRM covers all third-party risk: financial, operational and cyber. C-SCRM narrows to cybersecurity in tech supply chains, software integrity and hardware.
What is the SCF's Supply Chain Risk Management (SCRM) domain?
The SCF SCRM domain covers vendor risk assessments, SBOM management, software supply chain security, and NIST SP 800-161 Rev. 1 alignment for C-SCRM programs.
What is supply chain due diligence?
Supply chain due diligence verifies supplier certifications, financial health, regulatory compliance and concentration risk before and during the relationship.
What is a vendor risk questionnaire?
A vendor risk questionnaire assesses third-party security practices. SIG and CSA CAIQ are common formats; validate answers with evidence for high-risk firms.
What supply chain security guidance does CISA provide?
CISA publishes supply chain security guidance covering ICT risk evaluation, software supply chain recommendations and sector-specific advice at cisa.gov.
How does SCF address Supply Chain Risk Management?
The SCF's SCRM domain maps to NIST SP 800-161, CMMC SR and ISO 27001 supplier controls, covering the C-SCRM lifecycle from governance to incident response.
What is supply chain transparency?
Supply chain transparency means visibility into supplier identities, data handling and risk flow, achieved through disclosure rules, SBOMs and supply maps.
What is fourth-party risk?
Fourth-party risk comes from your vendors' vendors. A sub-processor breach can hit you with no direct relationship, so sub-processor visibility is essential.
How does NIST CSF address Supply Chain Risk Management?
NIST CSF 2.0 elevated Supply Chain Risk Management by including C-SCRM in the Govern function and supply chain risk assessment in the Identify function.
What is a Software Bill of Materials (SBOM)?
An SBOM is a formal inventory of software components and dependencies, letting you quickly identify affected systems when a component vulnerability appears.
What are common supply chain attack vectors?
Supply chain attack vectors include malicious software updates, compromised hardware, stolen supplier credentials, counterfeit parts and social engineering.
How do I create an Authorized Supplier List?
An Authorized Supplier List is a controlled vendor registry. Build one by setting approval criteria, assessing vendors, documenting approvals and reviewing.
How does supply chain risk relate to CMMC compliance?
CMMC extends CUI protection through the supply chain. Primes must flow requirements down to subcontractors handling CUI. The SCF maps to CMMC's SR domain.
What is a supplier risk assessment?
A supplier risk assessment reviews a vendor's security controls, data access, financial stability and compliance. Depth should match supplier criticality.
What does NIST SP 800-161 cover?
NIST SP 800-161 Rev. 1 covers C-SCRM program setup, supplier risk assessments, software supply chain security and 800-53 overlays for supply chain risk.
What is Cyber Supply Chain Risk Management (C-SCRM)?
C-SCRM manages cybersecurity risk in supply chains: malicious code, compromised supplier access and third-party component flaws. NIST SP 800-161 guides it.
What is Supply Chain Risk Management (SCRM)?
SCRM identifies, assesses and controls risk from suppliers and vendors, including disruption, counterfeit parts, compromised software and concentration risk.
What is the SCF's mapping to ISO 27001:2022?
See how the SCF maps to ISO 27001:2022's 93 controls and 11 new requirements, streamlining certification preparation and cross-framework compliance work.
Is ISO 27001 required by law?
ISO 27001 is voluntary in most jurisdictions, but government contracts and enterprise buyers often make it functionally mandatory. See when it is required.
What is a corrective action under ISO 27001?
An ISO 27001 corrective action is a documented response to a nonconformity requiring root cause analysis, action to prevent recurrence and verified results.
What new controls were added in ISO 27001:2022?
ISO 27001:2022 added 11 new controls covering threat intelligence, cloud security, configuration management, data masking, leak prevention and secure coding.
How does SCF map to ISO 27001?
The SCF maps directly to ISO 27001:2022 Annex A, so you can build one unified control set that satisfies ISO 27001 and other frameworks without duplication.
Can small organizations achieve ISO 27001 certification?
ISO 27001 has no minimum size requirement. Small organizations can narrow ISMS scope to specific services and pick certification bodies that scale fees.
What is ISO 27002?
ISO 27002 is the companion guidance to ISO 27001, giving implementation detail for Annex A controls. It is a reference document, not a certifiable standard.
How do I select an ISO 27001 certification body?
Pick an ISO 27001 certification body on accreditation (ANAB/UKAS), industry experience, pricing and references. Switching bodies means a new full audit.
How does ISO 27001 relate to SOC 2?
ISO 27001 gives international ISMS recognition while SOC 2 satisfies US enterprise buyers. Many organizations pursue both given the large control overlap.
What are ISO 27001 surveillance audit requirements?
ISO 27001 requires annual surveillance audits after certification and full recertification every three years, plus internal audits between external ones.
What is the ISO 27001 risk assessment process?
ISO 27001 risk assessment identifies threats, vulnerabilities, likelihood and impact, then feeds a treatment plan that selects Annex A controls per risk.
What is a Statement of Applicability (SoA) in ISO 27001?
An ISO 27001 Statement of Applicability lists every Annex A control with applicability and justification. Exclusions must be risk-based, not convenience.
How long does ISO 27001 certification take?
ISO 27001 certification usually takes 6 to 18 months from initial scoping, followed by annual surveillance audits and full recertification every three years.
What are the ISO 27001 Annex A control themes?
ISO 27001:2022 Annex A organizes 93 controls into four themes: Organizational (37), People (8), Physical (14), and Technological (34).
How does ISO 27001:2022 differ from ISO 27001:2013?
ISO 27001:2022 restructured Annex A from 114 controls in 14 domains to 93 in 4 themes and added 11 controls covering cloud, threat intel and data masking.
What is an Information Security Management System (ISMS)?
An ISMS is a systematic framework for managing information security risk. ISO 27001 sets its requirements: scope, risk assessment, treatment and controls.
What is ISO 27001?
ISO/IEC 27001 is the international standard for information security management systems, covering how to establish, run and continually improve an ISMS.
What is the difference between SOC 1 and SOC 2?
SOC 1 covers internal control over financial reporting. SOC 2 covers security, availability, processing integrity, confidentiality and privacy. Compare both.
How much does a SOC 2 audit cost?
SOC 2 audit cost depends on organization size, audit firm, Type I vs Type II and the Trust Service Criteria in scope. See the drivers and how to cut prep.
What is a SOC 2 readiness assessment?
A SOC 2 readiness assessment tests controls against the Trust Service Criteria before the formal audit, finding gaps and prioritizing remediation early.
How does SCF support SOC 2 compliance?
The SCF maps directly to the SOC 2 Trust Service Criteria, supplying control documentation for audit evidence while advancing ISO 27001 and NIST CSF work.
Do I need SOC 2 to sell to enterprise customers?
SOC 2 is not a legal requirement but is the de facto standard for B2B software. Enterprise buyers in finance, healthcare and tech routinely require Type II.
What is the SOC 2 Availability Trust Service Criteria?
The SOC 2 Availability criteria apply when you make uptime commitments, covering fault tolerance, backup and recovery, monitoring and disaster recovery.
How does SOC 2 relate to NIST CSF?
SOC 2 Trust Service Criteria and NIST CSF overlap significantly. SCF provides cross-framework mappings between SOC 2 TSC categories and NIST CSF subcategories.
How is SOC 2 audit scope determined?
SOC 2 scope comes from your service commitments and the systems delivering them. The system description captures infrastructure, software, people and data.
Who performs SOC 2 audits?
Only a licensed CPA firm can issue a SOC 2 attestation report. Readiness assessments can be run internally or by consultants, but the report needs a CPA.
What is a SOC 2 bridge letter?
A SOC 2 bridge letter confirms no material control changes since the report period ended, giving customers interim assurance while the next audit runs.
What SOC 2 controls cover system monitoring?
SOC 2 CC7 (System Operations) covers security event monitoring, log management, incident detection and response, and vulnerability management processes.
What does SOC 2 CC6 require?
SOC 2 CC6 requires least-privilege access, authentication, encryption in transit and at rest, physical access controls and prompt removal of stale access.
How long does a SOC 2 audit take?
SOC 2 Type I takes about 2-6 months. Type II takes 9-15 months due to the 6-month observation window. Readiness work adds 1-3 months before the audit.
What is the difference between SOC 2 Type I and Type II?
SOC 2 Type I assesses control design at a point in time. Type II assesses design and operating effectiveness over 6-12 months, which enterprises expect.
What are the SOC 2 Trust Service Criteria?
The SOC 2 Trust Service Criteria include mandatory Security (CC1-CC9) plus optional Availability, Processing Integrity, Confidentiality and Privacy sets.