Secure Controls Framework
Download The SCF

SCR Assessor

The advanced SAICO certification for information security professionals who participate in and/or lead SCR 3PAO assessment teams. SCR Assessors conduct independent conformity assessments, evaluating controls against Assessment Objectives (AOs) to determine whether organizations meet SCR CAP certification requirements.

Certification Details

What Is an SCR Assessor?

SCR Assessors are SAICO-certified individuals qualified to participate in and/or lead SCR Third-Party Assessment Organization (3PAO) assessment teams, conducting SCR CAP conformity assessments that evaluate an organization’s cybersecurity and data protection controls against defined Assessment Objectives (AOs).

Design & Implementation · SCR Certification
SCR Assessor
SCF Assessor thumbnail
The SCR Assessor is the advanced certification for professionals who conduct conformity assessments using the SCF methodology and the SCR CAP assessment process. This is the required credential for individuals performing SCR CAP assessments as part of an authorized 3PAO.
Ideal for: Information security assessors, auditors, consultants, and compliance professionals who conduct third-party assessments and need to demonstrate proficiency in SCR CAP assessment methodology.
What Does This Certification Cover?
  • SCR CAP assessment methodology and process
  • Examine, interview, and test (EIT) assessment techniques
  • Evidence collection, evaluation, and documentation
  • Assessment Objective (AO) evaluation procedures
  • SCR CAP report writing and findings documentation
  • Roles and responsibilities within the SCR CAP Ecosystem
Curriculum & Learning Objectives

What the SCR Assessor Certification Covers

The SCR Assessor curriculum is built around the SCR CAP assessment methodology, the examine, interview, and test (EIT) approach that assessors use to evaluate whether organizations have properly implemented the controls required for their selected SCR CAP certification.

SCR CAP Assessment Methodology

The examine, interview, and test (EIT) methodology that underpins all SCR CAP conformity assessments. Covers how to plan, scope, execute, and document assessments in accordance with SCR CAP requirements.

Assessment Objective (AO) Evaluation

How to evaluate each Assessment Objective to determine whether the control is appropriately designed, properly implemented, and producing the desired security outcome. Covers conformity vs. non-conformity determinations.

Evidence Collection & Evaluation

Techniques for collecting, reviewing, and evaluating evidence during SCR CAP assessments. Covers what constitutes acceptable evidence, how to evaluate documentation quality, and how to conduct interviews and tests.

Assessment Reporting & Findings

How to document assessment findings, write conformity/non-conformity determinations, and produce SCR CAP assessment reports that meet program requirements.

3PAO Roles & Responsibilities

Roles and responsibilities of SCR Assessors within a 3PAO team, including team lead vs. team member responsibilities, conflict of interest requirements, and the relationship to the Cyber AB accreditation body.

SCR CAP Program Requirements

The complete SCR CAP program structure, including how to select applicable Minimum Security Requirements (MSR) for each certification track, how to interpret assessment guides, and how risk tolerance affects assessment scoping.

SCR CAP Ecosystem

The SCR Assessor Role in the CAP Ecosystem

The SCR Assessor is the evaluation layer of the SCR CAP Ecosystem. Assessors perform the independent, third-party conformity assessments that produce the SCR Certified™ designation. They operate within authorized 3PAOs and are directly accountable to The Cyber AB’s accreditation standards.

Unlike Practitioners (who implement) and Architects (who design), Assessors must maintain independence from the organizations they assess. This independence is a core requirement of the SCR CAP program and is enforced through 3PAO accreditation standards.

SCF CAP Ecosystem Flow diagram
SAICO Certification Path

The Complete SAICO Certification Path

The SCR Assessor is the advanced and final track in the three-level SAICO certification path. It requires the foundational and intermediate knowledge built through the Practitioner and Architect tracks.

SCR Practitioner

Foundation: Step 1. Implement and maintain SCF controls. Foundation understanding of SCF structure, domains, and the SCF.

SCR Architect

Intermediate: Step 2. Design and architect SCF-based programs. Control selection, SCRMS implementation, and strategic alignment.

SCR Assessor

Advanced: Current. Lead SCR CAP assessment teams within a 3PAO. Evaluate controls against AOs. Conduct independent conformity assessments.