Secure Controls Framework
Download The SCF
Everything Free · Creative Commons · No Registration

Free Cybersecurity & GRC Content

Free? Yes! The resources in this section are 100% free to use. It is all released under Creative Commons licensing by the SCF Council. Download the full Common Controls Framework™ (CCF), maturity models, risk frameworks, evidence templates, and more. No registration. No paywall. No catch.

8+
Free Resources
1,400+
Controls
200+
Frameworks Mapped
FREE
Forever
CORE FRAMEWORK

The SCF: Download the Common Controls Framework™

The primary SCF download contains the full 1,400+ control catalog with all 200+ framework mappings, maturity criteria, control weightings, risk catalog, threat catalog, and assessment guidance. Available in multiple formats including Excel (CSV) and NIST OSCAL JSON.

Full Control Catalog: 1,400+ Controls

The SCF control catalog spans all 33 cybersecurity and data privacy domains, from Governance and Asset Management through Cloud Security and Privacy. Each control includes a unique SCF identifier, control objective, capability maturity criteria at each SCR-CMM level (1–5), proposed weighting, and threat/risk catalog crosswalks.

200+ Framework Mappings via STRM

Every SCF control is mapped to all applicable laws, regulations, and frameworks using the NIST IR 8477 Set Theory Relationship Mapping (STRM) methodology. Mappings include NIST SP 800-53, NIST CSF 2.0, ISO 27001/2, CIS Controls v8, HIPAA, PCI DSS v4, SOC 2, CMMC 2.0, GDPR, CCPA/CPRA, DORA, NIS2, FedRAMP, and 185+ more.

NIST OSCAL JSON Export

The SCF’s NIST OSCAL JSON export enables machine-readable exchange of control catalogs and profiles. It supports native import into FedRAMP automation pipelines, automated compliance workflows, interoperability with OSCAL-compatible GRC tools, and machine-readable crosswalk data for automated gap analysis.

We do ask for your name and email, mainly so that we can alert you to changes that are pertinent as a SCF user. We release quarterly updates and send out a newsletter to announce those releases.

SECURE, COMPLIANT & RESILIENT (SCR)

SCR Models: Free Maturity & Risk Frameworks

The Secure, Compliant & Resilient (SCF) resouces give the SCF depth beyond basic controls. The maturity models and risk management frameworks integrate directly with the SCF control catalog.

SCR Capability Maturity Model (SCR-CMM)

The SCR-CMM defines six (6) maturity levels for every SCF control, from "Ad Hoc" (Level 1) through "Optimized" (Level 5). It gives organizations a precise benchmark for where their controls stand and what "right" looks like at each stage of program maturity.

The SCR-CMM is the only free, openly-licensed cybersecurity maturity model directly integrated with a 1,400+ control catalog. It enables organizations to produce board-level maturity scorecards without expensive consulting engagements.

Level 0: Not Performed
Level 1: Performed Informally
Level 2: Planned & Tracked
Level 3: Well-Defined
Level 4: Quantitatively Controlled
Level 5: Continuously Improving

SCR Risk Management Model (SCR-RMM)

The SCR-RMM describes how policies, standards, procedures, metrics, threats, and risks all connect through SCF controls as the central nexus. It is a structured risk management model that integrates directly with the SCF control catalog for risk-informed decision making.

The SCR-RMM enables organizations to move from checkbox compliance to genuine risk management. It helps you understand not just which controls are required, but which threats they address and what residual risk remains when controls are missing or immature.

Risk Catalog
Threat Catalog
Control Weighting

The SCR models are a free differentiator unique to the SCF. No other free metaframework includes integrated capability maturity criteria and a risk management model covering 1,400+ controls.

ASSESSMENT & TEMPLATES

Free Assessment Tools & Templates

Beyond the core control catalog, the SCF Council publishes specialized tools that support every phase of a cybersecurity program. All are free under Creative Commons licensing.

Cybersecurity & Data Privacy Assessment Standards (CDPAS)

The CDPAS provides standardized assessment criteria for evaluating cybersecurity and data privacy programs against the SCF control catalog. Used by internal audit teams and third-party assessors to produce consistent, repeatable assessment results.

The CDPAS enables organizations to self-assess against the SCF using a structured observation-based methodology, producing defensible evidence of control effectiveness for regulators, insurers, and board audiences.

PDF
Self-Assessment
Third-Party Ready

Evidence Request List (ERL)

The ERL is a pre-built, comprehensive list of audit evidence items mapped to every SCF control. It tells auditors, assessors, and compliance teams exactly what documentation, configurations, and artifacts are needed to demonstrate control effectiveness.

The ERL eliminates the "what do you want to see?" ambiguity in audits. Both the assessed organization and the assessor start from the same, standardized evidence baseline, dramatically reducing audit preparation time and rework.

Excel
Audit-Ready
TPRM

Unified Scoping Guide (USG)

The USG provides structured guidance for defining assessment scope, which is the critical first step in any audit or compliance assessment. Proper scoping determines which systems, data flows, and processes are in-scope for each applicable law or framework.

The USG prevents both over-scoping (wasting resources assessing out-of-scope systems) and under-scoping (missing critical systems and creating audit exposure). It is essential for FedRAMP, PCI DSS, HIPAA, and SOC 2 engagements.

PDF
Scoping
Risk-Based
SPECIALIZED CONTENT

Specialized GRC Tools & Guidance

Domain-specific tools for organizations with unique compliance challenges, including M&A transactions, data privacy programs, and more.

Mergers, Acquisitions & Divestitures (MA&D)

The SCF MA&D toolkit provides specialized cybersecurity due diligence guidance for M&A transactions. It identifies the cybersecurity controls, data privacy obligations, and inherited risks that must be evaluated during any acquisition, merger, or divestiture process.

M&A transactions routinely expose acquiring organizations to inherited cybersecurity liabilities such as undisclosed breaches, non-compliant data practices, and technical debt. The SCF MA&D framework provides a structured methodology for evaluating and managing these risks before closing.

PDF
Excel
Due Diligence
Deal Risk

Data Privacy Management Principles (DPMP)

The DPMP provides structured guidance for building and operating a data privacy management program aligned with the SCF’s Privacy (PRI) domain. It covers GDPR, CCPA/CPRA, PIPEDA, and global privacy regulations through the lens of SCF controls.

The DPMP implements Privacy by Design (PbD) principles, helping organizations embed privacy requirements into systems, processes, and products from inception rather than retrofitting compliance after the fact. Covers DSARs, consent management, PIAs, DPIAs, and data retention.

PDF
Excel
GDPR
CCPA
Privacy by Design
LICENSING & RIGHTS

Creative Commons Licensed. Free. Always.

We are committed to keeping the SCF a free resource for organizations to use. Therefore, we are using the Creative Commons Attribution-NoDerivatives 4.0 International Public License to help maintain the integrity of the SCF.

Attribution — You must give appropriate credit, provide a link to the license and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use. Providing attribution is as simple as stating SCF controls are used in the solution, such as a GRC platform that includes SCF content is required to provide attribution that SCF controls are used.

NoDerivatives — If you remix, transform, or build upon the material, you may not distribute the modified material. For example, you are prohibited from leveraging SCF material to create a derivative solution (e.g., SCF 2.0). This prohibition on creating derivative works includes utilizing Artificial Intelligence (AI) (or similar technologies) to leverage SCF content to generate policies, standards, procedures, metrics, risks, threats or other derivative content. An organization needs to purchase a commercial license to offer derivative SCF content.

ALWAYS CURRENT

The SCF Is A Living Control Set (LCS)

Unlike static frameworks that fall behind as laws change, the SCF is continuously updated. It is a true Living Control Set that evolves with the regulatory landscape.

Updated with Every New Law & Regulation

When a new law is enacted, such as DORA, NIS2, state privacy laws, or sector-specific rules, the SCF is updated to map the new requirements to existing controls. Your organization's compliance coverage updates without rework.

Proactive
Regular Updates

Updated with Framework Revisions

When NIST releases CSF 2.0, ISO updates 27001, or CIS publishes new Controls, the SCF mappings are updated to reflect the new version. Never maintain separate crosswalk spreadsheets again.

NIST CSF 2.0
ISO 27001:2022
NIST 800-161 Rev 1
NIST 800-171 Rev 3

Updated with Emerging Threats

New attack techniques, vulnerabilities, and threat patterns drive new control requirements. The SCF LCS incorporates these changes as expert volunteers identify gaps, ensuring controls stay relevant against real-world threats.

Threat-Informed
Business-Relevant
EXPLORE FURTHER

Put The SCF To Work

Downloaded the SCF? Here's what to do next, from implementation guidance to certification pathways.

Start Here: What Is The SCF?

New to the SCF? Start with the overview to understand what the Common Controls Framework™ is, why it exists, and how to use it effectively.

SCRMS Implementation Guide

The SCRMS is the step-by-step guide for implementing the SCF in your organization using the Plan-Do-Check-Act (PDCA) management cycle.

SCF Certification Programs

Get your organization or team certified against the SCF through the Conformity Assessment Program (CAP) or individual certification paths.