What Is The Secure Code Alliance?
The SCA addresses two interconnected needs: ensuring software developers possess the technical skills to write secure code, and providing organizations with the means to demonstrate governance over secure development practices. Through individual certifications and organizational designations, it provides a framework that aligns with Executive Order 14028 requirements and NIST SP 800-218 best practices.
Technical competence and organizational due diligence are treated as separate problems with separate evidence. An individual earns a credential. An organization earns a designation. Neither substitutes for the other.
Where The SCA Meets The SCF
The SCA appointed The Cyber AB to serve as the Accreditation Body for its organization-level certification scheme, and CODE conformity assessments are conducted using the methodology and infrastructure of the SCF Conformity Assessment Program (SCF CAP).
Two Paths For Individuals
Software developers and architects each face distinct challenges in secure development. The SCA offers two certifications, each tailored to the role and its responsibilities.
Certified SCA Practitioner (CSCAP)
For software developers who use Secure Development Lifecycle (SDL) processes for new systems, system upgrades, or systems that are being repurposed. Demonstrates technical competence in implementing SSDP day to day.
Certified SCA Architect (CSCAA)
For software architects who employ cyber resiliency constructs and tailor analytic and lifecycle processes to their environment. Demonstrates strategic and architectural security competence.
Govern Secure Development At Organizational Scale
There is a growing need for organizations to demonstrate that, at the organization level, they govern secure development practices. The SCA offers two paths, and an organization can pursue both.
Secure Development Organization (SDO)
Three levels of designation, where the level depends on the number of SCA Practitioners and SCA Architects employed by the organization.
Certified Organization for Development Excellence (CODE)
Two levels of third-party conformity assessment: CODE 1 against the CISA SSDAF, and CODE 2 against NIST SP 800-218.
Built For EO 14028 And The SSDF
Executive Order 14028, Improving the Nation's Cybersecurity, directs the National Institute of Standards and Technology to publish guidance on practices that enhance the security of the software supply chain. The SCA framework is designed to give organizations and individuals concrete, defensible evidence of those practices.
EO 14028
Improving the Nation's Cybersecurity. Directs NIST to publish guidance on practices that enhance the security of the software supply chain.
NIST SP 800-218
The Secure Software Development Framework (SSDF). The best-practices reference for SSDP, and the basis for CODE 2 conformity.
CISA SSDAF
The Secure Software Development Attestation Form, addressing EO 14028 requirements, and the basis for CODE 1 conformity.
.png)
%20(white).png)