Secure Controls Framework
Download The SCF

SCA Architect

The architect-level Secure Code Alliance certification for software architects who shape system-level security decisions. The Certified SCA Architect (CSCAA) gives objective evidence of Secure Software Development Practices competence to employers, clients and other stakeholders who rely on that work to architect and maintain secure applications and systems.

Certification Overview

What Is An SCA Architect?

Software architects are expected to employ cyber resiliency constructs, including goals, objectives, techniques, approaches and design principles, as well as the analytic and lifecycle processes, and to tailor them to the technical, operational and threat environments for which their systems need to be engineered.

Individuals who earn a Certified SCA Architect (CSCAA) certification demonstrate a level of competence necessary to ensure that the security of an organization's applications, services and processes are assessed throughout their operational life to reduce risks to the organization and its clients. Where the practitioner-level CSCAP evidences day-to-day secure development, the CSCAA evidences the strategic and architectural decisions that shape it.

Certified SCA Architect (CSCAA)

Certified SCA Architect (CSCAA) certification badge

The CSCAA is the architect-level Secure Code Alliance certification for software architects who employ cyber resiliency constructs and tailor analytic and lifecycle processes to the technical, operational and threat environments their systems must be engineered for. It demonstrates the competence needed to ensure that the security of an organization's applications, services and processes is assessed throughout their operational life.

Ideal for: software architects, security architects and technical leads who set system-level security direction in organizations that must evidence Secure Software Development Practices.

What Does This Certification Cover?
  • The SCA Body of Knowledge (SCA-BoK)
  • NIST SP 800-218 and NIST SP 800-160
  • Executive Order 14028 software security requirements
  • The OWASP Top Ten
  • Cyber resiliency constructs: goals, objectives, techniques, approaches and design principles
Role Definition

What An SCA Architect Does

The SCA defines six areas of responsibility that distinguish the architect role from the practitioner role.

Define Security Objectives

Work with stakeholders to ensure that security objectives, protection needs and concerns, security requirements, and associated validation methods are defined.

Develop Security Views

Develop security views and viewpoints of the system architecture and design, covering protection, performance and behavioral characteristics.

Identify And Assess Vulnerabilities

Identify and assess susceptibilities and vulnerabilities to lifecycle hazards and adversities. Design proactive and reactive features to control asset loss.

Inform Engineering Trades

Perform system security analyses and interpret results in support of decision-making for engineering trades and risk management.

Evaluate Security Costs

Identify, quantify and evaluate the costs and benefits of security features and functions to inform engineering and business decisions.

Apply Across The SDLC

Apply lifecycle processes recursively, iteratively, concurrently, sequentially or in parallel, to any system regardless of its size, complexity, purpose, scope or environment.

Knowledge Exam

Open Book, Online, Proctored

The open book format reflects the reality of architectural work: software is rarely developed in a vacuum, and architects need to reference industry-recognized resources. Training and certification are delivered through a Learning Management System, and upon passing the exam the CSCAA certificate is issued by Accredible.

All-In Certification Cost

$500 USD. There is no travel cost, since the training and testing are entirely computer-based.

Certification Validity

Three (3) years from the date the certificate is issued.

Minimum Passing Grade

70%, which demonstrates a satisfactory understanding of the core concepts while maintaining a higher standard for academic performance.

Training Delivery

100% computer-based and self-paced. The course is fully online with no face-to-face class meetings, and includes one attempt at the knowledge exam.

Study Materials

The exam draws on the SCA Body of Knowledge (SCA-BoK) plus its referenced standards, including NIST SP 800-218, NIST SP 800-160, EO 14028 and the OWASP Top Ten.

Continue Your SCA Journey

Next Steps In The SCA Certification Path

The CSCAA is the architect-level credential in the SCA scheme. Developers applying secure development practices day to day take the CSCAP instead, and organizations demonstrate governance of secure development through the SDO designation and CODE certification.

SCA Practitioner

Practitioner Level. Apply Secure Development Lifecycle processes to new systems, upgrades and systems being repurposed.

Secure Development Organization

Organization Level. Demonstrate organizational commitment to secure development through SCA-certified headcount, across three designation levels.

CODE Certification

Organization Level. Third-party conformity assessment against the CISA SSDAF or NIST SP 800-218, accredited by The Cyber AB and run through the SCF CAP.