What Is The SCR-CMM?
The Secure, Compliant & Resilient Capability Maturity Model (SCR-CMM) is the maturity model of the Secure Controls Framework (SCF). It defines six levels, from Level 0 (Not Performed) to Level 5 (Continuously Improving), and the SCF workbook includes maturity criteria for every SCF control.
The SCR-CMM "is meant to solve the problem of objectivity in both establishing and evaluating cybersecurity and data privacy controls." It is free to use, and it adds control-level criteria to the high-level structure of the Systems Security Engineering Capability Maturity Model v2.0 (SSE-CMM).
Not Just Another Maturity Model
Rather than reinvent the wheel, the SCF chose the SSE-CMM as the best model to demonstrate varying levels of maturity for people, processes and technology at a control level. The SSE-CMM is community-owned, free to use and also referenced by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) as ISO/IEC 21827:2008.
Who Is The SCR-CMM For?
The SCR-CMM is written for cybersecurity and data privacy practitioners. Its four objectives, each with a defined use case, show who uses it.
Use Case 1
Objective Criteria To Build A Cybersecurity Program
Gives Chief Information Security Officers (CISOs), Chief Information Officers (CIOs) and Chief Privacy Officers (CPOs) objective criteria for setting program expectations. Maturity goals define what right looks like, so expectations do not become moving targets.
Use Case 2
Assist Project Teams To Plan & Budget
Gives project teams objective criteria so that secure, compliant and resilient practices are planned and budgeted for before go-live.
Use Case 3
Evaluate External Service Provider Practices
Gives organizations objective criteria to evaluate External Service Providers (ESPs), which are commonly considered the soft underbelly of a security program.
Use Case 4
Due Diligence In Mergers, Acquisitions & Divestitures
Supports Mergers, Acquisitions & Divestitures (MA&D) due diligence. Deficiencies found in a maturity-based gap assessment can be costed to adjust valuations.
How Is The SCR-CMM Organized?
The SCR-CMM has an Executive Summary, the SCR-CMM Overview, the Defined Maturity Levels, a section on choosing a maturity "sweet spot" and four use cases. Each level builds on the one before it: Levels 0 and 1 are generally considered negligent, and Levels 2 to 5 are generally considered audit ready.
How Do Organizations Use The SCR-CMM?
The SCR-CMM has no numbered steps; organizations generally apply it in five phases.
Scope The Applicable Controls
Maturity targets apply to controls an organization actually needs. The SCF is first pared down to the controls that apply, based on priorities, resourcing and statutory, regulatory and contractual obligations.
Choose A Target Range
For most organizations, the sweet spot for maturity targets is between Level 2 and Level 4. The negligence threshold sits between Level 1 and Level 2, and noticeable risk reductions are harder to attain above Level 3.
Set And Assign Targets
Technologists and business stakeholders set a target for each SCF domain, then for each control in those domains. Control targets are assigned to managers and Individual Contributors (ICs), and progress is ideally reviewed every quarter.
Assess Current Maturity
Each control's current level is judged against its criteria, which describe what would reasonably exist at each level rather than serving as a checklist. Consciously designating a higher level than is justified should be considered fraud.
Extend To Projects, ESPs And MA&D
Projects ideally inherit the organization's targets, usually limited to Level 2 to Level 3 for planning. ESPs answer from Level 0 to Level 5 instead of yes or no, and the same maturity-based approach supports MA&D due diligence.
The level definitions, sweet spot considerations and all four use cases are covered in full in the SCR-CMM.
What Each Level Looks Like In Practice
Each level is built upon its predecessor. The SCR-CMM also notes what each level often looks like in smaller and larger organizations.

Level 0
Not Performed
Smaller organizations often have only break/fix Information Technology (IT) support, while larger ones have IT or cybersecurity staff but governance is functionally non-existent.
Level 1
Performed Informally
IT support or staff exist, but the support contract is limited in scope or management does not focus time or resources on the control.
Level 2
Planned & Tracked
IT staff have clear compliance requirements; a dedicated cybersecurity role is unlikely in smaller organizations and likely in larger ones.
Level 3
Well Defined
A very competent leader, such as a security manager or a CISO, has the authority to direct resources to enact secure practices across the organization.
Level 4
Quantitatively Controlled
Unrealistic for smaller organizations; in larger ones, detailed metrics keep business stakeholders aware of the program's status, for example through quarterly business reviews.
Level 5
Continuously Improving
Unrealistic for small and medium-sized organizations; large ones have an industry-leading business model and invest heavily in Artificial Intelligence and Machine Learning for near real-time improvements.
Internal vs. External Maturity
Levels 0 to 3 are internal maturity levels, involving almost entirely IT, cybersecurity and data privacy. Levels 4 and 5 are external, with true business stakeholder involvement in oversight and process improvement.
Maturity (Governance) Is Not Assurance (Security)
Higher maturity and higher assurance are not mutually inclusive. Maturity measures the governance activities around a control, not the strength and depth of the control. Increased rigor in control testing is what leads to increased assurance.
The SCR-CMM recognizes three levels of rigor to assess a control.
Standard Rigor (Minimum Assurance): Determines whether the applicable controls are implemented and free of obvious errors.
Enhanced Rigor (Moderate Assurance): Also provides increased grounds for confidence that the controls are implemented correctly and operating as intended.
Comprehensive Rigor (High Assurance): Also provides further increased grounds for confidence that the controls operate as intended on an ongoing and consistent basis, with support for continuous improvement.
Assessors and auditors use three assessment methods to verify that an organization meets the intent of its applicable controls: examine, interview and test.
The SCR-CMM Works With The SCRMS And The SCF
The SCR-CMM draws on other free SCF content.
SCRMS
Defining target maturity is Principle 3 (Define Maturity Expectations) of the Secure, Compliant & Resilient Management System (SCRMS), which helps establish the prerequisites for setting targets.
SCF Workbook
The SCF workbook holds the maturity criteria for every SCF control, one column per level, along with the SCF domains and the SCF CORE MA&D control set.
.png)

%20(white).png)