Secure Controls Framework
Download The SCF
SCF Marketplace

SCF Third-Party Assessment Organizations (3PAOs)

SCF 3PAOs are entities accredited by The CyberAB to conduct SCF-related Third-Party Assessment, Attestation, and Certification (3PAAC) services for Organizations Seeking Assessment (OSA) under the SCF CAP.

Role Definition

What Is an SCF 3PAO?

SCF 3PAOs are entities accredited by The CyberAB to conduct SCF-related Third-Party Assessment, Attestation, and Certification (3PAAC) services for Organizations Seeking Assessment (OSA) under the SCF CAP.

SCF 3PAOs provide objective, consistent, thorough, and reliable assessments of an OSA’s implementation of the SCF, ensuring conformance with specified cybersecurity and/or data protection requirements. These organizations play a critical role in maintaining the integrity and credibility of SCF certifications through rigorous and impartial assessments.

Accredited by The CyberAB

SCF 3PAOs must be accredited by The CyberAB, the official Accreditation Body for the SCF CAP, before conducting any 3PAAC services. This accreditation ensures assessors meet the qualifications and independence standards required for credible SCF certifications.

Objective Assessments

Conduct objective, consistent, and impartial assessments of an OSA’s SCF implementation.

Certification Support

Provide Third-Party Assessment, Attestation, and Certification (3PAAC) services under the SCF CAP.

Program Integrity

Maintain the integrity and credibility of SCF certifications through rigorous, impartial assessment.

3PAAC Services

Third-Party Assessment, Attestation, and Certification (3PAAC) services include assessment of an organization’s implementation of the SCF, attestation of conformance with specific cybersecurity and/or data protection requirements, and supporting the issuance of SCF CAP certifications.

Find a 3PAO

CyberAB Marketplace

The CyberAB is the official Accreditation Body (AB) for the SCF’s Conformity Assessment Program (SCF CAP). The CyberAB runs the SCF Marketplace where all accredited 3PAOs are listed.

Organizations seeking an accredited 3PAO to conduct their SCF CAP assessment should visit the CyberAB Marketplace to find qualified assessment organizations with the expertise relevant to their specific compliance requirements. You can learn more about becoming a SCF 3PAO and sign up through the CyberAB’s website.

CyberAB SCF Marketplace

The CyberAB is the official Accreditation Body for the SCF CAP. All accredited SCF 3PAOs are listed in the CyberAB Marketplace, ensuring organizations can find qualified assessors for their SCF CAP engagements.

View the SCF Marketplace at CyberAB.org
SCF CAP Ecosystem

SCF 3PAOs in the Broader Ecosystem

SCF 3PAOs are the cornerstone of the SCF CAP, providing the independent, accredited assessments that underpin SCF certifications for Organizations Seeking Assessment.

SCF CAP Ecosystem Participants

SCF (Framework), CyberAB (Accreditation Body), 3PAO (Assessment Org, You Are Here), RPO (Provider Org), LCP (Content Provider), ASP (Solution Provider), OSA (Org Seeking Assessment).

SCF CAP Ecosystem Flow diagram
Find a 3PAO

CyberAB Marketplace

The CyberAB is the official Accreditation Body (AB) for the SCF’s Conformity Assessment Program (SCF CAP). The CyberAB runs the SCF Marketplace where all accredited 3PAOs are listed.

Organizations seeking an accredited 3PAO to conduct their SCF CAP assessment should visit the CyberAB Marketplace to find qualified assessment organizations with the expertise relevant to their specific compliance requirements. You can learn more about becoming a SCF 3PAO and sign up through the CyberAB’s website.

CyberAB SCF Marketplace

CyberAB SCF Marketplace: The CyberAB is the official Accreditation Body for the SCF CAP. All accredited SCF 3PAOs are listed in the CyberAB Marketplace, ensuring organizations can find qualified assessors for their SCF CAP engagements.

View the SCF Marketplace at CyberAB.org

Find or Become an SCF 3PAO

Connect with accredited SCF 3PAOs through the CyberAB Marketplace, or apply to become a Third-Party Assessment Organization and join the SCF Ecosystem.

SCF CAP Ecosystem

SCF 3PAOs in the Broader Ecosystem

SCF 3PAOs are the cornerstone of the SCF CAP, providing the independent, accredited assessments that underpin SCF certifications for Organizations Seeking Assessment.

SCF CAP Ecosystem Participants

SCF (Framework), CYBER-AB (Accreditation Body), 3PAO (Assessment Org, You Are Here), RPO (Provider Org), LCP (Content Provider), ASP (Solution Provider), OSA (Org Seeking Assessment).

Flowchart of Secure Controls Framework Conformity Assessment Program ecosystem showing connections between Cyber AB, SAICO, SCF Connect, licensed content providers, third-party assessment organizations, certification organizations, training providers, individual certifications, and authorized platform partners.
Download SCF CAP Ecosystem Overview (PDF)
Role Definition

What Is an SCF 3PAO?

SCF 3PAOs are entities accredited by The CyberAB to conduct SCF-related Third-Party Assessment, Attestation, and Certification (3PAAC) services for Organizations Seeking Assessment (OSA) under the SCF CAP.

SCF 3PAOs provide objective, consistent, thorough, and reliable assessments of an OSA’s implementation of the SCF, ensuring conformance with specified cybersecurity and/or data protection requirements. These organizations play a critical role in maintaining the integrity and credibility of SCF certifications through rigorous and impartial assessments.

Accredited by The CyberAB

SCF 3PAOs must be accredited by The CyberAB, the official Accreditation Body for the SCF CAP, before conducting any 3PAAC services. This accreditation ensures assessors meet the qualifications and independence standards required for credible SCF certifications.

Objective Assessments

Conduct objective, consistent, and impartial assessments of an OSA’s SCF implementation.

Certification Support

Provide Third-Party Assessment, Attestation, and Certification (3PAAC) services under the SCF CAP.

Program Integrity

Maintain the integrity and credibility of SCF certifications through rigorous, impartial assessment.

3PAAC Services

Third-Party Assessment, Attestation, and Certification (3PAAC) services include assessment of an organization’s implementation of the SCF, attestation of conformance with specific cybersecurity and/or data protection requirements, and supporting the issuance of SCF CAP certifications.

SCF Marketplace

SCF Third-Party Assessment Organizations (3PAOs)

SCF 3PAOs are entities accredited by The CyberAB to conduct SCF-related Third-Party Assessment, Attestation, and Certification (3PAAC) services for Organizations Seeking Assessment (OSA) under the SCF CAP.