What Is An SCA Practitioner?
Software developers, referred to as practitioners, are expected to use Secure Development Lifecycle (SDL) processes for new systems, system upgrades, or systems that are being repurposed. Individuals who earn a Certified SCA Practitioner (CSCAP) certification demonstrate a level of competence necessary to ensure that the security of an organization's applications, services and processes are assessed throughout their operational life to reduce risks to the organization and its clients.
The CSCAP certification leverages an online platform to test applicants on subject matter expertise, awarding the certification upon successfully passing a knowledge exam. It is curated towards software providers that need a practical approach to demonstrate two things: that their personnel are appropriately addressing security threats, and that the organization invests in a culture of cybersecurity and privacy.
Certified SCA Practitioner (CSCAP)

The CSCAP is the entry-point Secure Code Alliance certification for software developers who use Secure Development Lifecycle (SDL) processes for new systems, system upgrades, or systems that are being repurposed. It demonstrates the competence needed to ensure that the security of an organization's applications, services and processes is assessed throughout their operational life.
Ideal for: software developers, application engineers and DevSecOps practitioners who write, review or maintain code in organizations that must evidence Secure Software Development Practices.
- The SCA Body of Knowledge (SCA-BoK)
- NIST SP 800-218, the Secure Software Development Framework (SSDF)
- Executive Order 14028 software security requirements
- The OWASP Top Ten
- Secure Development Lifecycle (SDL) processes for new, upgraded and repurposed systems
Open Book, Online, Proctored
The CSCAP knowledge exam is administered through an online platform in a proctored format. The open book format reflects the reality of development work: software is rarely developed in a vacuum, and practitioners need to reference industry-recognized resources. Training and certification are delivered through a Learning Management System, and upon passing the exam the CSCAP certificate is issued by Accredible.
All-In Certification Cost
$350 USD. There is no travel cost, since the training and testing are entirely computer-based.
Certification Validity
Three (3) years from the date the certificate is issued.
Minimum Passing Grade
70%, which demonstrates a satisfactory understanding of the core concepts while maintaining a higher standard for academic performance.
Training Delivery
100% computer-based and self-paced. The course is fully online with no face-to-face class meetings, and includes one attempt at the knowledge exam.
Study Materials
The exam draws on the SCA Body of Knowledge (SCA-BoK) plus its referenced standards, including NIST SP 800-218, EO 14028 and the OWASP Top Ten.
Who Should Pursue The CSCAP
There are no formal educational or certification prerequisites to become a CSCAP. The experience below is recommended rather than required, and helps candidates pass the knowledge exam and perform the duties of a CSCAP once certified.
Practical Experience
Six (6) months or more of practical experience with Secure Development Practices (SDP).
Framework Familiarity
Familiarity with NIST SP 800-218, EO 14028 and the OWASP Top Ten.
Toolchain Knowledge
Working knowledge of at least one modern development language and its toolchain.
Next Steps In The SCA Certification Path
The CSCAP is the practitioner-level credential in the SCA scheme. Architects who shape system-level security decisions take the CSCAA instead, and organizations demonstrate governance of secure development through the SDO designation and CODE certification.
SCA Architect
Next Step: Architecture & Design. Employ cyber resiliency constructs and tailor analytic and lifecycle processes to the technical, operational and threat environment.
Secure Development Organization
Organization Level. Demonstrate organizational commitment to secure development through SCA-certified headcount, across three designation levels.
CODE Certification
Organization Level. Third-party conformity assessment against the CISA SSDAF or NIST SP 800-218, accredited by The Cyber AB and run through the SCF CAP.
.png)
%20(white).png)