Secure Controls Framework
Download The SCF

Secure Code Alliance (SCA)

The Secure Code Alliance was formed to address the need organizations have to ensure their developers are aware of, and implement, Secure Software Development Practices (SSDP), in order to minimize the threat posed by malicious actors against the organization's applications, services and processes.

Role Definition

What Is The Secure Code Alliance?

The SCA addresses two interconnected needs: ensuring software developers possess the technical skills to write secure code, and providing organizations with the means to demonstrate governance over secure development practices. Through individual certifications and organizational designations, it provides a framework that aligns with Executive Order 14028 requirements and NIST SP 800-218 best practices.

Technical competence and organizational due diligence are treated as separate problems with separate evidence. An individual earns a credential. An organization earns a designation. Neither substitutes for the other.

Where The SCA Meets The SCF

The SCA appointed The Cyber AB to serve as the Accreditation Body for its organization-level certification scheme, and CODE conformity assessments are conducted using the methodology and infrastructure of the SCF Conformity Assessment Program (SCF CAP).

Individual Certifications

Two Paths For Individuals

Software developers and architects each face distinct challenges in secure development. The SCA offers two certifications, each tailored to the role and its responsibilities.

Certified SCA Practitioner (CSCAP)

For software developers who use Secure Development Lifecycle (SDL) processes for new systems, system upgrades, or systems that are being repurposed. Demonstrates technical competence in implementing SSDP day to day.

Certified SCA Architect (CSCAA)

For software architects who employ cyber resiliency constructs and tailor analytic and lifecycle processes to their environment. Demonstrates strategic and architectural security competence.

Organizational Designations

Govern Secure Development At Organizational Scale

There is a growing need for organizations to demonstrate that, at the organization level, they govern secure development practices. The SCA offers two paths, and an organization can pursue both.

Secure Development Organization (SDO)

Three levels of designation, where the level depends on the number of SCA Practitioners and SCA Architects employed by the organization.

Certified Organization for Development Excellence (CODE)

Two levels of third-party conformity assessment: CODE 1 against the CISA SSDAF, and CODE 2 against NIST SP 800-218.

Federal Alignment

Built For EO 14028 And The SSDF

Executive Order 14028, Improving the Nation's Cybersecurity, directs the National Institute of Standards and Technology to publish guidance on practices that enhance the security of the software supply chain. The SCA framework is designed to give organizations and individuals concrete, defensible evidence of those practices.

EO 14028

Improving the Nation's Cybersecurity. Directs NIST to publish guidance on practices that enhance the security of the software supply chain.

NIST SP 800-218

The Secure Software Development Framework (SSDF). The best-practices reference for SSDP, and the basis for CODE 2 conformity.

CISA SSDAF

The Secure Software Development Attestation Form, addressing EO 14028 requirements, and the basis for CODE 1 conformity.