Secure Controls Framework
Download The SCF

Frequently Asked Questions (FAQ)

Everything you need to know about the Secure Controls Framework® (SCF), the Common Controls Framework™, from getting started and understanding the metaframework to SCF CAP certification, licensing, and implementation.

General

About the Secure Controls Framework®

Foundational questions about what the SCF is, why it exists, and what makes it different from other cybersecurity frameworks.

What Is The SCF?

The SCF stands for the Secure Controls Framework. It is more than just an assortment of cybersecurity and data privacy controls. It is focused on designing, implementing and maintaining secure, compliant, and resilient capabilities to address all applicable statutory, regulatory and contractual requirements that an organization faces.

Our belief is that if you scope your requirements with security in mind, compliance will generally be a natural byproduct of those secure and resilient actions. We want organizations to be secure, compliant and resilient, since it benefits all of modern society.

Why Does The SCF Say It Is The Common Controls Framework?

The use of Common Controls Framework™ is trademarked and the SCF has exclusive rights to use the term. The SCF is the Common Controls Framework™ (CCF) because in addition to providing a common set of controls that organizations use to satisfy multiple compliance obligations simultaneously through a single, unified control set, the SCF owns the domains commoncontrolsframework.com and common-controls-framework.com.

What Is A Metaframework?

A "metaframework" is a framework of frameworks. That is exactly what the SCF is. It is a framework made up of over 200 cybersecurity and data privacy laws, regulations and frameworks. Rather than implementing each framework separately, the SCF provides a single comprehensive control set that maps to all of them simultaneously.

How Is The SCF Different From NIST, ISO 27001, or CIS Controls?

NIST CSF, ISO 27001, and CIS Critical Security Controls are individual cybersecurity frameworks. The SCF is a metaframework that encompasses all of them, and over 200 others. When you implement the SCF, you are implementing the common controls that satisfy NIST, ISO, CIS, and many other frameworks simultaneously.

This eliminates the need to maintain separate control sets for each framework, regulation, or law your organization must comply with. The SCF’s Set Theory Relationship Mapping (STRM) methodology ensures these mappings are mathematically rigorous, not subjective crosswalks.

How Often Is The SCF Updated?

The general cadence for updates is one (1) update per quarter. There may be situations where out-of-cycle updates are released, but the goal is to publish updates on a quarterly basis. The SCF is a Living Control Set, meaning it is continuously maintained and updated to reflect changes in the regulatory landscape.

Does The SCF Cover Artificial Intelligence (AI)?

Yes. The SCF has had coverage for AI since 2024. The Artificial Intelligence & Autonomous Technologies (AAT) domain is one of thirty-three domains in the SCF. That domain has coverage for these AI-specific requirements:

  • ISO 42001
  • NIST AI Risk Management Framework
  • NIST 600-1 (Generative AI)
  • EU AI Act
Getting Started

How To Start Using The SCF

Practical questions about downloading, implementing, and operationalizing the SCF in your organization.

Where Do I Start?

The best place to begin is the Start Here page. It provides a guided introduction to the Secure Controls Framework, what it is, how it works, and how to begin using it in your organization. The page walks you through the SCF's structure, its 33 domains, the metaframework concept, and links to the key resources you'll need.

  1. Read the Start Here Guide: The SCF Recommended Practices (PDF) gives you a concise overview of how to get started.
  2. Understand the SCRMS: The Security, Compliance & Resilience Management System is the SCF's implementation methodology, your roadmap for building an SCF-based program.
  3. Download the SCF: Grab the free Excel, CSV, or NIST OSCAL JSON version from the SCF Download page and start tailoring controls to your needs.

How Do I Use The SCF?

Start by reading the "What Is The SCF" page, which includes a Start Here Guide for recommended practices.

To build an SCF-based cybersecurity program, begin with the Security, Compliance & Resilience Management System (SCRMS) and the SCRMS Prioritized Implementation Guide (SCRMS-PIG). These provide a "paint by numbers" approach to creating a tailored, prioritized set of controls.

Once ready to start working with the SCF, you can either:

  1. Download the Excel version from the SCF Download page and create your own control set; or
  2. Use a GRC platform like SCF Connect or others listed on the SCF Marketplace.

What Is The SCRMS And Why Does It Matter?

The Security, Compliance & Resilience Management System (SCRMS) is the SCF’s implementation methodology. It provides the structured approach for designing, building, and maintaining a cybersecurity program using the SCF. Think of it as the "how to" guide for turning SCF controls into an operational program.

The SCRMS covers the full lifecycle: scoping, tailoring controls, implementing, operating, and continuously improving your program across the People, Process, Technology, Data, and Facilities (PPTDF) dimensions.

What Does “Mechanisms Exist” Mean In SCF Controls?

The SCF controls are written to be flexible for organizations of any size or industry. The term "mechanism" can mean a manual process, technology solution, or anything in between. If you prefer different wording, you can replace "mechanism" with "solution," "processes," or another term that fits your organization’s context.

The key point is that a mechanism demonstrates that the control requirement is being addressed, whether through a documented procedure, an automated tool, or a combination of both.

What If I Get Stuck And Need Help?

If you need assistance with tailoring or operationalizing the SCF, there are several options:

Controls & Domains

SCF Controls, Domains & Structure

Questions about the SCF’s control structure, domain organization, risk model, maturity model, and how controls work in practice.

How Many Controls Does The SCF Have?

The SCF contains over 1,400 controls across 33 domains. These controls are mapped to over 200 cybersecurity and data privacy laws, regulations, and frameworks. The SCF is a comprehensive catalog. You are not expected to implement all 1,400+ controls. The tailoring process helps you select only the controls applicable to your organization.

What Are The 33 SCF Domains?

The SCF is organized into 33 control domains that cover every aspect of cybersecurity and data protection. These range from Governance (GOV) and Risk Management (RSK) to specialized domains like Artificial Intelligence & Autonomous Technologies (AAT), Supply Chain Risk Management (SCR), and Web Security (WEB). You can explore the full list on the SCF Domains & Principles page.

What Are Assessment Objectives (AOs)?

Assessment Objectives (AOs) are the specific, testable criteria used to evaluate whether a control is appropriately designed, properly implemented, and producing the desired security outcome. Each SCF control has one or more AOs that assessors use during SCF CAP conformity assessments.

AOs are defined in the Cybersecurity & Data Protection Assessment Standards (CDPAS), which is free to download.

What Is The SCF Risk Model (SCR-RMM)?

The Security, Compliance & Resilience Risk Management Model (SCR-RMM) is the SCF’s free, integrated risk model. It provides a structured approach to identifying, analyzing, and managing cybersecurity and data privacy risks at the control level. Rather than treating risk management as a separate exercise, the SCR-RMM embeds risk directly into the SCF’s control structure.

The SCR-RMM maps specific risks and threats to each SCF control, giving organizations a clear view of what could go wrong if a control is absent or inadequate. This enables risk-informed decision-making when tailoring and prioritizing controls. You can see exactly which risks you are accepting, mitigating, or transferring for every control in your program.

The SCR-RMM is available as a free download from the SCR-RMM page.

What Is The SCF Maturity Model (SCR-CMM)?

The Security, Compliance & Resilience Capability Maturity Model (SCR-CMM) is the SCF’s free maturity model that allows organizations to measure and benchmark the maturity of their cybersecurity and data privacy practices at the control level. It provides quantifiable maturity criteria for each SCF control across defined maturity levels.

The SCR-CMM helps organizations answer the question "how good are we?" by providing a consistent scale for evaluating People, Processes, and Technology (PPT) across every control. This supports capability gap analysis, investment prioritization, and board-level reporting on cybersecurity program maturity over time.

The SCR-CMM is available as a free download from the SCR-CMM page.

How Do You Define Cybersecurity Materiality?

Cybersecurity materiality is the concept of determining which cybersecurity and data privacy risks are significant enough to warrant attention, investment, and disclosure. Drawing from the financial auditing concept of materiality, it applies the same principle to cybersecurity: not every risk is equal, and organizations must determine which risks, if left unaddressed, could materially impact the business.

The SCF addresses cybersecurity materiality as a GRC Fundamentals topic. In practice, this means defining thresholds for what constitutes a "material" cybersecurity risk or deficiency in your organization, which informs control scoping, investment decisions, board reporting, and regulatory disclosure obligations (e.g., SEC cybersecurity incident disclosure rules).

Materiality is particularly relevant for organizations subject to regulatory disclosure requirements, public companies, and any organization communicating cybersecurity posture to stakeholders, investors, or regulators.

Metaframework & Mapping

Metaframework Methodology & STRM Mapping

How the SCF maps to 200+ laws, regulations, and frameworks using rigorous Set Theory Relationship Mapping.

How Does The SCF Map To 200+ Frameworks?

The SCF uses Set Theory Relationship Mapping (STRM), a mathematically rigorous methodology based on NIST IR 8477, to map controls to external frameworks, laws, and regulations. Unlike subjective crosswalks, STRM uses set theory to define the precise relationship between SCF controls and external requirements, producing mappings that are accurate, consistent, and defensible.

What Is STRM And Why Does It Matter?

Set Theory Relationship Mapping (STRM) is the gold standard for crosswalk mapping between cybersecurity and data privacy requirements. It replaces subjective "best guess" crosswalks with a mathematical model that precisely defines the relationship between controls and external requirements.

The SCF is a recognized NIST OLIR Program participant with accepted mappings between the SCF and NIST frameworks.

What Laws, Regulations & Frameworks Does The SCF Cover?

The SCF maps to over 200 laws, regulations, and frameworks including NIST CSF, NIST 800-53, NIST 800-171, ISO 27001/27002, CIS Controls, CMMC, HIPAA, GDPR, PCI DSS, SOC 2 TSC, CCPA/CPRA, NIS2, DORA, FedRAMP, SOX, GLBA, and many more. The complete list is available on the Included Laws, Regulations & Frameworks (LRF) page.

Licensing & Cost

Licensing, Cost & Usage Rights

Questions about why the SCF is free, what the Creative Commons license allows, and commercial licensing options.

Why Is The SCF Free To Use?

The SCF is free to help fix the broken nature of cybersecurity and data protection practices in many organizations. The quality of the SCF could easily justify a costly subscription service, but that would exclude most organizations and defeat the broader goal of improving cybersecurity and privacy practices on a macro scale.

The SCF’s contributors are volunteers, and the project relies on generous sponsors to maintain the framework.

Are There Restrictions On The Use Of The SCF?

The SCF is copyrighted material that uses the Creative Commons licensing model to keep it free for businesses to use. The Terms & Conditions page details the open license granted for organizational use. There are options for commercial licenses for companies that want to create derivative content based on the SCF.

Technical & Formats

SCF Conformity Assessment Program

Questions about SCF CAP certification for organizations, including assessment methodology, 3PAOs, and The CyberAB.

What Is The SCF CAP?

The SCF Conformity Assessment Program (SCF CAP) is the organization-level certification program that allows organizations to demonstrate conformity with SCF-based cybersecurity and data protection requirements. Assessments are conducted by accredited Third-Party Assessment Organizations (3PAOs) using the examine, interview, and test (EIT) methodology.

What Is The CyberAB?

The CyberAB is the official Accreditation Body (AB) for the SCF Conformity Assessment Program (SCF CAP). The CyberAB accredits 3PAOs, maintains the SCF Marketplace, and oversees the accreditation standards that ensure assessment quality and independence.

What Are SCF Assessment Guides?

SCF Assessment Guides are pre-built, ready-to-use assessment packages that define the specific set of controls an organization must implement and be assessed against for a particular compliance objective (e.g., NIST CSF 2.0, CMMC Level 1, HIPAA). Each guide maps to the relevant SCF controls and Assessment Objectives for that certification track.

Get Started With The SCF

SCF Training & Individual Certifications

Questions about the three SAICO individual certification tracks and how to get certified.

What Is SAICO?

SAICO is the SCF Assessor and Instructor Certification Organization. SAICO provides three Computer-Based Training (CBT) certification programs for individuals: SCF Practitioner (foundation), SCF Architect (design & implementation), and SCF Assessor (assessment & audit).

What Are The Three SAICO Certification Levels?

The three SAICO certification tracks are:

  1. SCF Practitioner: Foundation level. Implement and maintain SCF-based controls. No prerequisites.
  2. SCF Architect: Intermediate level. Design and architect SCF-based programs. Builds on Practitioner knowledge.
  3. SCF Assessor: Advanced level. Lead or participate in 3PAO assessment teams conducting SCF CAP conformity assessments.

All three are delivered via self-paced CBT through the SCF Training Platform.

Marketplace & Ecosystem

SCF Marketplace & Ecosystem Partners

Questions about the SCF partner ecosystem, marketplace participants, and how to find SCF expertise.

What Is The SCF Marketplace?

The SCF Marketplace connects organizations with SCF expertise. It includes six categories of ecosystem participants: 3PAOs (assessment organizations), ASPs (solution providers), RPOs (consulting providers), ACIs (control integrators), LTPs (training providers), and LCPs (content providers). The authoritative listing is maintained by The CyberAB.

What Is SCF Connect?

SCF Connect is the SCF-specific GRC platform built from the ground up to operationalize the Secure Controls Framework. It is the official Single Source of Truth (SSOT) for SCF CAP third-party conformity assessments. SCF Connect is priced at $200/month and provides an intuitive SaaS platform for implementing, managing, and reporting on SCF-based cybersecurity programs.

Contact Us

Download Formats & Technical Details

Questions about the SCF download formats, NIST OSCAL support, and technical integration options.

What Formats Is The SCF Available In?

The SCF is available for free download in multiple formats:

  • Microsoft Excel (.xlsx): The primary format for working with SCF controls, tailoring, and GRC import.
  • CSV (.csv): For programmatic import into GRC platforms and databases.
  • NIST OSCAL JSON: Machine-readable format following the NIST Open Security Controls Assessment Language standard for automated processing.

What Is NIST OSCAL And Why Does The SCF Support It?

NIST OSCAL (Open Security Controls Assessment Language) is a standardized, machine-readable format for representing cybersecurity controls, assessment results, and system security plans. The SCF supports OSCAL JSON to enable automated ingestion by GRC platforms, security tooling, and compliance automation systems, eliminating manual data entry and enabling continuous compliance monitoring.

What Free Content Does The SCF Provide Besides The Controls?

The SCF provides a comprehensive library of free content beyond the control catalog:

  • SCR-RMM: Security, Compliance & Resilience Risk Management Model
  • SCR-CMM: Security, Compliance & Resilience Capability Maturity Model
  • CDPAS : Cybersecurity & Data Protection Assessment Standards
  • ERL : Evidence Request List for assessments
  • USG : Unified Scoping Guide
  • DPMP : Data Privacy Management Principles
  • MA&D: Mergers, Acquisitions & Divestitures security guidance
Additional Questions

Additional Frequently Asked Questions (FAQs)

What is SOC 2?
SOC 2 is an AICPA attestation framework that evaluates service organization controls against the Trust Service Criteria and is issued by a licensed CPA firm.
What is the SCF's approach to NY DFS 23 NYCRR Part 500 compliance?
See how the SCF maps controls to NY DFS Part 500: penetration testing, MFA, encryption, CISO accountability, Class A rules and 2023 amendment compliance.
What are the penalties for non-compliance with NY DFS 23 NYCRR Part 500?
NY DFS Part 500 non-compliance brings significant civil fines, individual officer accountability under the 2023 amendments and public enforcement actions.
What does NY DFS Part 500 require for privileged accounts?
NY DFS Part 500 requires MFA, annual access reviews, least privilege and activity monitoring for privileged accounts, plus PAWs for Class A companies.
What is the annual certification requirement under NY DFS Part 500?
NY DFS Part 500 requires annual CEO or CISO certification of compliance filed with DFS by April 15. The 2023 amendments created individual accountability.
What is the NY DFS Part 500 exemption threshold?
NY DFS Part 500 exemptions cover entities under 10 employees, $5M in revenue or $10M in assets. Even exempt entities must still file a notice of exemption.
How does SCF align with NY DFS Part 500?
The SCF maps directly to NY DFS Part 500 across governance, risk assessment, MFA, access control, penetration testing, incident response and third-party risk.
What are NY DFS Part 500 third-party vendor management requirements?
NY DFS Part 500 requires written third-party security policies, vendor assessments, cybersecurity contract clauses, breach notice rights and access reviews.
What is a Class A company under NY DFS Part 500?
Class A companies under NY DFS Part 500 have 2,000+ employees or $1B+ revenue and face enhanced rules including independent audits and stricter access control.
Does NY DFS Part 500 require Multi-Factor Authentication?
The 2023 NY DFS Part 500 amendments require MFA for all remote access and all privileged accounts, with limited CISO-documented exceptions permitted.
What is the 72-hour reporting rule under NY DFS Part 500?
NY DFS Part 500's 72-hour rule requires covered entities to notify DFS within 72 hours of determining a cybersecurity event materially harmed operations.
What are the NY DFS Part 500 incident reporting requirements?
NY DFS Part 500 requires 72-hour notice for material cybersecurity events and 24-hour notice for ransom payments. Third-party events also require reporting.
What is a covered entity under NY DFS Part 500?
A NY DFS Part 500 covered entity is any DFS-licensed person or organization. Class A firms face enhanced rules; smaller entities may qualify for exemptions.
What are the NY DFS Part 500 penetration testing requirements?
NY DFS Part 500 requires annual penetration testing by qualified testers. Class A companies face enhanced methodology rules; document results and remediation.
What is the CISO role under NY DFS Part 500?
NY DFS Part 500 requires a qualified CISO to oversee the cybersecurity program and report annually to the board. The role can be outsourced, accountability not.
What changed in the 2023 NY DFS Part 500 amendments?
The 2023 NY DFS Part 500 amendments added senior executive certification, mandatory MFA, 72-hour event notice, 24-hour ransom notice and Class A requirements.
Who must comply with NY DFS Part 500?
NY DFS Part 500 applies to DFS-licensed entities: banks, lenders, insurers, money transmitters and foreign banking organizations operating in New York.
What is NY DFS 23 NYCRR Part 500?
NY DFS Part 500 is New York's cybersecurity regulation for DFS-licensed financial institutions, first effective in 2017 and significantly amended in 2023.
What is the difference between CCPA and GDPR?
Compare CCPA/CPRA and GDPR: scope, thresholds, legal basis vs. opt-out, consumer rights, and penalty structures. Which privacy law applies to your organization?
What is the SCF's Privacy Management domain for CCPA/CPRA compliance?
See how the SCF Privacy Management domain covers CCPA/CPRA: consumer rights, data mapping, consent controls and the Sensitive Personal Information rules.
What are CPRA civil penalties?
CPRA civil penalties reach $2,500 per unintentional violation and $7,500 per intentional violation, with enhanced penalties for children's data violations.
What is the CPRA right to opt out?
CPRA lets consumers opt out of the sale or sharing of personal information. Businesses must honor opt-outs in 15 business days and wait 12 months to re-ask.
How does SCF map to CCPA/CPRA controls?
SCF's Privacy domain maps to CCPA/CPRA requirements covering data subject rights, data inventory, consent management, vendor agreements, and data retention.
What is ADMT and how does CPRA regulate it?
CPRA's ADMT rules cover AI and algorithmic decisions about consumers. Draft rules add an opt-out right and pre-deployment assessments; verify CPPA rules.
What is a CPRA privacy risk assessment?
CPRA requires privacy risk assessments before high-risk processing, weighing benefits against consumer privacy risk and documenting the safeguards in place.
What are CPRA cybersecurity audit requirements?
CPRA requires annual cybersecurity audits for businesses posing significant privacy risk. Final CPPA rules set scope and reporting, so verify current text.
What does CPRA require for Sensitive Personal Information?
CPRA's Sensitive Personal Information covers geolocation, health, biometric and financial data. Consumers can limit its use and businesses reply in 15 days.
What is a Data Subject Access Request (DSAR)?
A DSAR is a formal consumer privacy rights request. Under CCPA/CPRA businesses must answer verified DSARs within 45 days, with one 45-day extension allowed.
What consumer rights does CCPA/CPRA provide?
CCPA/CPRA give California consumers rights to know, delete, correct and opt out of the sale or sharing of personal data, plus limits on sensitive data use.
Who must comply with CCPA and CPRA?
CCPA/CPRA applies to for-profit businesses meeting revenue, data volume, or data-sale revenue thresholds, regardless of where the business is headquartered.
What is the California Privacy Rights Act (CPRA)?
The CPRA expanded the CCPA with Sensitive Personal Information protections, the CPPA, cybersecurity audit requirements and new consumer rights from 2023.
What is the California Consumer Privacy Act (CCPA)?
The CCPA gives California consumers rights to know, delete, and opt out of the sale of their personal information. Learn which businesses must comply.
When do FIPS 140-2 validations expire and what happens after September 2026?
FIPS 140-2 validations move to Historical status on September 21, 2026. Learn what that means for federal and commercial organizations and the next steps.
What is FIPS 140-3 and how does it replace FIPS 140-2?
FIPS 140-3 replaced FIPS 140-2 for cryptographic module validation, and FIPS 140-2 validations move to Historical status on September 21, 2026. See the impact.
What is the SCF's Quantum Security (QTS) domain?
The SCF Quantum Security (QTS) domain provides controls for post-quantum readiness, FIPS 203/204/205 alignment, algorithm agility and PQC migration planning.
Does FIPS 140-3 cover post-quantum algorithms?
NIST was incorporating PQC algorithms into FIPS 140-3 CMVP validation as of mid-2025. Monitor NIST announcements for current validated PQC module availability.
What is the Q-Day concept in quantum security?
Q-Day is the hypothetical date quantum computers break current public-key cryptography. NSA and CISA advise starting PQC migration now, not waiting for it.
What is FIPS 203?
FIPS 203 is the NIST post-quantum standard for ML-KEM (CRYSTALS-KYBER), a key encapsulation mechanism with three security parameter sets finalized in 2024.
How does the SCF address quantum security?
The SCF's Cryptographic Management domain covers algorithm selection, key management and crypto-agility, the control foundation for PQC migration planning.
What sectors face the greatest quantum security risk?
Government, financial services, healthcare and critical infrastructure face the greatest quantum risk from long-lived data exposed to harvest-now-decrypt.
How do I inventory my cryptographic assets?
A cryptographic asset inventory documents every use of cryptography - algorithms, key lengths, certificates and dependencies - as the basis for PQC migration.
What is ML-KEM (formerly CRYSTALS-KYBER)?
ML-KEM (formerly CRYSTALS-KYBER) is NIST's FIPS 203 post-quantum key encapsulation mechanism, replacing RSA and Diffie-Hellman for key establishment.
When might quantum computers break RSA?
Estimates range from 10 to 30+ years, but NSA and CISA advise starting PQC migration now because infrastructure migrations take years whatever the timeline.
What is crypto-agility?
Crypto-agility is designing systems that can swap cryptographic algorithms without major rework, which makes post-quantum migration far more manageable.
How do I start a Post-Quantum Cryptography migration?
Start PQC migration with a cryptographic inventory, then assess data sensitivity and build a prioritized roadmap beginning with long-lived sensitive data.
What is a harvest-now-decrypt-later attack?
Harvest-now-decrypt-later attacks capture encrypted data today to decrypt it later with quantum computers. Long-lived sensitive data is the most at risk.
What NIST Post-Quantum Cryptography standards have been finalized?
NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) as Post-Quantum Cryptography standards in August 2024.
Which cryptographic algorithms are vulnerable to quantum attacks?
RSA and ECC-based algorithms are most vulnerable to quantum attacks. Symmetric AES-256 and SHA-256 are more resilient. Learn how to prioritize your migration.
What is Post-Quantum Cryptography?
Post-Quantum Cryptography refers to algorithms designed to resist quantum computer attacks, replacing RSA and ECC with quantum-resistant alternatives.
How do I build an AI governance program from scratch?
A step-by-step guide to building an AI governance program: AI system inventory, NIST AI RMF risk assessment, policy, bias testing and ongoing monitoring.