What Is CODE?
In addition to the organization-wide SDO designation, an organization can earn the designation of Certified Organization for Development Excellence (CODE). The concept of the CODE certification is to use a third-party conformity assessment of secure development practices rather than a count of certified personnel.
CODE certification is exclusive of an SDO designation. An organization does not have to be an SDO to seek or obtain CODE certification, and the two can be held together.
Certified Organization for Development Excellence (CODE)

CODE is the Secure Code Alliance's third-party conformity assessment of secure development practices. Where the SDO designation measures organizational commitment through certified headcount, CODE assesses the practices themselves against an external authority, and an organization can hold both.
Ideal for: software producers that must provide customers or federal buyers with independently assessed evidence of conformity rather than self-attestation alone.
- Third-party conformity assessment of secure development practices
- CODE 1: conformity with the CISA Secure Software Development Attestation Form (SSDAF)
- CODE 2: conformity with NIST SP 800-218, the Secure Software Development Framework
- The Cyber AB as the Accreditation Body for the SCA's organization-level scheme
- The SCF Conformity Assessment Program (SCF CAP) as the assessment methodology
Two Levels Of Conformity Assessment
CODE has two levels. Each corresponds to a different authoritative source that the organization demonstrates conformity with.
CODE 1 – CISA SSDAF Conformity
The organization successfully demonstrates conformity with the Cybersecurity and Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF), addressing Executive Order 14028 requirements.
CODE 2 – NIST SP 800-218 Conformity
The organization successfully demonstrates conformity with NIST Special Publication 800-218, the Secure Software Development Framework (SSDF).
How Conformity Is Assessed
CODE does not run its own assessment infrastructure. The SCA made two appointments that place the certification inside the same ecosystem the SCF already uses.
The Cyber AB As Accreditation Body
The SCA appointed The Cyber AB to serve as the Accreditation Body for the SCA's organization-level certification scheme.
The SCF CAP As Methodology
CODE leverages the Secure Controls Framework Conformity Assessment Program (SCF CAP) for the methodology and infrastructure used to conduct the conformity assessment.
Next Steps In The SCA Certification Path
CODE is one of two organization-level paths, and can be held alongside an SDO designation. The individual credentials that sit beneath both are the CSCAP and the CSCAA.
Secure Development Organization
Organizational commitment measured through SCA-certified headcount, across three designation levels.
SCA Practitioner
Practitioner Level. The CSCAP credential for developers applying Secure Development Lifecycle processes.
SCA Architect
Architecture & Design. The CSCAA credential for architects shaping system-level security decisions.
.png)
%20(white).png)