Secure Controls Framework
Download The SCF

Compensating Controls

When a primary SCF control cannot be implemented, a compensating control can hold the risk at an acceptable level until it can be. The SCF now publishes possible compensating controls for every eligible control, along with the justification for each, so organizations and assessors start from a common reference rather than inventing one.

What They Are

What Is A Compensating Control?

A compensating control is an alternative control an organization puts in place when the primary control cannot be implemented as written. It does not replace the intent of the primary control. It addresses the same underlying risk objective through a different mechanism, and it holds residual risk at an acceptable level until the primary control can be implemented.

SCF 2026.2 introduced a dedicated Compensating Controls tab in the SCF workbook. For every SCF control it records the risk of leaving the primary control unimplemented. Where a compensating control is permitted, it lists two possible compensating controls drawn from elsewhere in the SCF, each with a written justification.

Same Risk Objective

A compensating control targets the risk the primary control was meant to address, rather than a loosely related one.

Drawn From The SCF

Every suggested compensating control is an existing SCF control, so it carries its own mapping to the laws, regulations and frameworks in scope.

Managed, Not Permanent

A compensating control holds residual risk at an acceptable level until the primary control can be implemented. The lifespan may be short, or it may run to the next hardware refresh years away, but it is managed either way.

A Starting Point, Not A Decision

The SCF publishes possible compensating controls. Whether a given compensating control is adequate for your environment, and whether an assessor or regulator will accept it, remains an organizational decision that has to be argued on the facts of your environment.

Why It Matters

Why The SCF Publishes Compensating Controls

Most control frameworks acknowledge that compensating controls exist but leave organizations to invent them. That produces two common failures. Organizations either claim a compensating control that does not address the original risk, or they avoid the conversation entirely and carry an unmanaged gap.

Publishing the options alongside the controls changes the starting position. The organization does not have to argue from a blank page, and the assessor is not evaluating a control pairing nobody has seen before.

Faster Gap Remediation

When a control cannot be implemented on the current timeline, there is a documented alternative to evaluate rather than a blank field in the plan of action.

A Shared Vocabulary

The organization and the assessor refer to the same control identifiers and the same justification language.

Traceable Coverage

Because every suggested compensating control is itself an SCF control, it inherits the SCF mapping to the laws, regulations and frameworks in scope.

A Defensible Record Of Risk

The tab states the risk of leaving each primary control unimplemented, which keeps the trade-off visible rather than buried.

When One Applies

When A Compensating Control Applies

A compensating control is part of a deliberate, defensible risk treatment methodology, used when a primary control cannot be implemented as prescribed and focused on matching that control's objective and outcome. It applies where implementation of the primary control is technically infeasible, operationally impractical, cost-prohibitive, or temporarily unavailable during a phased implementation.

Where It Is Acceptable

Legacy systems that cannot support modern controls such as antimalware or file integrity monitoring. Regulatory conflicts, for example over cryptographic module requirements. Technology limitations such as embedded software that cannot be patched. Interim risk treatment while remediation is underway.

Where It Is Not

Avoiding cost or effort without a justification that would withstand outside scrutiny. Risk acceptance below the management level required, in a way that violates the organization's risk appetite. An alternative control that does not actually provide equivalent or comparable risk mitigation.

Technical limitations are the common case: a specialized system that cannot have antimalware or a host-based firewall installed, an unsupported system that can no longer be patched, or a patch not yet certified for an operating environment. Business limitations count too, such as a contract that blocks changes to an environment without partner approval, service level agreements that prevent patching on the normal cadence, or a remote workforce that puts physical controls out of reach.

Common Misuse

What Compensating Controls Are Not

Most laws, regulations and frameworks allow compensating controls but give no guidance on selecting or operationalizing them. That gap is where the misuse happens, and the misuse creates legal exposure.

1

Not a shortcut: A compensating control is not a way to bypass an unmet requirement. Treating the published options as "if you cannot do this control, here are the alternatives" is a dangerous mindset.

2

Not a control enhancement: A compensating control is an ALTERNATIVE implementation that achieves equivalent protection. A control enhancement is an ADDITIONAL safeguard beyond the baseline. Blurring the two is how organizations end up claiming coverage they do not have.

3

Not risk acceptance: Accepting the risk of an unimplemented control is a leadership decision, not a compensating control. Recording an acceptance in place of a control is not the same as putting an alternative control in place.

The Documentation That Has To Exist

Every proposed compensating control is assessed for applicability, risk mitigation and sustainability, and evaluated by leadership rather than by the control owner. The record should capture the alternatives considered, the justification for the one selected, and where applicable the follow-up steps to validate that it works.

Eligibility

Not Every Control Is Eligible

Throughout the Compensating Controls tab, you will notice that there are a number of controls that are marked as not eligible for a compensating control. These are material controls, carrying a control weighting of 10 out of 10. The SCF's position is that a deficiency in, or the absence of, a material control is a material weakness to the organization's Security, Compliance & Resilience Program (SCRP), and that no alternative control offsets that.

Below are some examples of controls that are listed as material and are ineligible for compensating controls:

GOV-02

Publishing Security, Compliance & Resilience Documentation

Mechanisms exist to establish, maintain and disseminate policies, standards and procedures necessary for secure, compliant and resilient capabilities.

GOV-13

State-Sponsored Espionage

Mechanisms exist to constrain the host government's ability to leverage the organization's Technology Assets, Applications and/or Services (TAAS) for economic or political espionage and/or cyberwarfare activities.

CFG-03

Secure Baseline Configurations

Mechanisms exist to develop, document and maintain secure baseline configurations for Technology Assets, Applications and/or Services (TAAS) that are consistent with industry-accepted system hardening standards.

IAC-07

User Provisioning & De-Provisioning

Mechanisms exist to utilize a formal user registration and de-registration process that governs the assignment of access rights.

The remaining controls each carry two possible compensating controls, so roughly nine in ten SCF controls have documented options.

Materiality is what decides this. The SCF Council defines the materiality threshold for an organization's security, compliance and resilience program as a deficiency, or combination of deficiencies, in its cybersecurity or data protection controls across its supply chain where it is probable that reasonable threats will not be prevented or detected in a timely manner in a way that affects assurance the organization can adhere to its stated risk tolerance. Defining materiality is an executive leadership determination rather than a cybersecurity one. Where the deficiency or absence of a specific control would have material impact, that control is designated material, and a material control is not capable of having compensating controls.

Material Controls

Where a control is marked not eligible, the correct response is to implement it, not to look for a substitute. Treating a material control as satisfied by a compensating control misrepresents the organization's risk position.

Using The Tab

How To Use Compensating Controls

The tab is a reference, not an approval. Working through it in order keeps the decision defensible.

1

Confirm the primary control genuinely cannot be implemented: A compensating control is for a control the organization cannot implement, not one that is inconvenient or has simply not been scheduled yet.

2

Check eligibility: Look the control up in the Compensating Controls tab. If the fields read N/A, it is a material control and no compensating control applies.

3

Read the risk statement: The tab states what the organization is exposed to without the primary control. That statement is what the compensating control has to address.

4

Evaluate both options against your environment: Two possible compensating controls are listed and neither is automatically correct. Select the one your environment can actually support, or determine that neither is sufficient.

5

Document the decision: Record which compensating control was selected, how it addresses the stated risk, and when the primary control is expected to be implemented.

Worked Example

Real Example Of Compensating Controls

For this, we will be utilizing control IAC-06, Multi-Factor Authoentication (MFA), as an example.

SCF #
SCF Control Name
SCF Control Description
IAC-06
Multi-Factor Authentication (MFA)
Automated mechanisms exist to enforce Multi-Factor Authentication (MFA) for:
  • Remote network access;
  • Third-party Technology Assets, Applications and/or Services (TAAS); and/ or
  • Non-console access to critical TAAS that store, transmit and/or process sensitive and/or regulated data.

For this control, the risk if the primary control (IAC-06) is not implemented is, "Without Multi-Factor Authentication (MFA), unauthorized users may gain access to systems or data, increasing risk of data breaches and insider threats." Below are the compensating controls associated with this control.

NET-03

Boundary Protection

Monitors and controls communications at the external network boundary and at key internal boundaries, limiting how far a compromised credential can reach and how easily an attacker moves laterally.

MON-16

Anomalous Behavior

Uses user and entity behavior analytics or user activity monitoring to identify unauthorized or anomalous activity that the primary control would have prevented.

Neither option restores what MFA does. Boundary Protection narrows where a stolen credential can be used, and Anomalous Behavior shortens the time before misuse is noticed. That gap is the trade-off the organization has to document and the assessor has to weigh.

Where To Find Them

Where Compensating Controls Live

Compensating controls are published inside the SCF workbook itself, in a tab named Compensating Controls followed by the release version. There is no separate download and no additional license.

Each row carries the SCF control name and number, the control description, and the risk if the primary control is not implemented. Two blocks of compensating control detail follow, each giving the control number, name, description and the justification for treating it as a compensating control.

The tab is reviewed and updated on the same quarterly cadence as the rest of the SCF, so the version in the workbook you downloaded is the version to reference.