What Is An SCA Architect?
Software architects are expected to employ cyber resiliency constructs, including goals, objectives, techniques, approaches and design principles, as well as the analytic and lifecycle processes, and to tailor them to the technical, operational and threat environments for which their systems need to be engineered.
Individuals who earn a Certified SCA Architect (CSCAA) certification demonstrate a level of competence necessary to ensure that the security of an organization's applications, services and processes are assessed throughout their operational life to reduce risks to the organization and its clients. Where the practitioner-level CSCAP evidences day-to-day secure development, the CSCAA evidences the strategic and architectural decisions that shape it.
Certified SCA Architect (CSCAA)

The CSCAA is the architect-level Secure Code Alliance certification for software architects who employ cyber resiliency constructs and tailor analytic and lifecycle processes to the technical, operational and threat environments their systems must be engineered for. It demonstrates the competence needed to ensure that the security of an organization's applications, services and processes is assessed throughout their operational life.
Ideal for: software architects, security architects and technical leads who set system-level security direction in organizations that must evidence Secure Software Development Practices.
- The SCA Body of Knowledge (SCA-BoK)
- NIST SP 800-218 and NIST SP 800-160
- Executive Order 14028 software security requirements
- The OWASP Top Ten
- Cyber resiliency constructs: goals, objectives, techniques, approaches and design principles
What An SCA Architect Does
The SCA defines six areas of responsibility that distinguish the architect role from the practitioner role.
Define Security Objectives
Work with stakeholders to ensure that security objectives, protection needs and concerns, security requirements, and associated validation methods are defined.
Develop Security Views
Develop security views and viewpoints of the system architecture and design, covering protection, performance and behavioral characteristics.
Identify And Assess Vulnerabilities
Identify and assess susceptibilities and vulnerabilities to lifecycle hazards and adversities. Design proactive and reactive features to control asset loss.
Inform Engineering Trades
Perform system security analyses and interpret results in support of decision-making for engineering trades and risk management.
Evaluate Security Costs
Identify, quantify and evaluate the costs and benefits of security features and functions to inform engineering and business decisions.
Apply Across The SDLC
Apply lifecycle processes recursively, iteratively, concurrently, sequentially or in parallel, to any system regardless of its size, complexity, purpose, scope or environment.
Open Book, Online, Proctored
The open book format reflects the reality of architectural work: software is rarely developed in a vacuum, and architects need to reference industry-recognized resources. Training and certification are delivered through a Learning Management System, and upon passing the exam the CSCAA certificate is issued by Accredible.
All-In Certification Cost
$500 USD. There is no travel cost, since the training and testing are entirely computer-based.
Certification Validity
Three (3) years from the date the certificate is issued.
Minimum Passing Grade
70%, which demonstrates a satisfactory understanding of the core concepts while maintaining a higher standard for academic performance.
Training Delivery
100% computer-based and self-paced. The course is fully online with no face-to-face class meetings, and includes one attempt at the knowledge exam.
Study Materials
The exam draws on the SCA Body of Knowledge (SCA-BoK) plus its referenced standards, including NIST SP 800-218, NIST SP 800-160, EO 14028 and the OWASP Top Ten.
Next Steps In The SCA Certification Path
The CSCAA is the architect-level credential in the SCA scheme. Developers applying secure development practices day to day take the CSCAP instead, and organizations demonstrate governance of secure development through the SDO designation and CODE certification.
SCA Practitioner
Practitioner Level. Apply Secure Development Lifecycle processes to new systems, upgrades and systems being repurposed.
Secure Development Organization
Organization Level. Demonstrate organizational commitment to secure development through SCA-certified headcount, across three designation levels.
CODE Certification
Organization Level. Third-party conformity assessment against the CISA SSDAF or NIST SP 800-218, accredited by The Cyber AB and run through the SCF CAP.
.png)
%20(white).png)