What Is A Secure Development Organization?
There is a growing need for organizations to be able to demonstrate that, at the organization level, they govern secure development practices. Individual certifications evidence what a person knows. The Secure Development Organization (SDO) designation evidences what the organization as a whole has committed to.
The SDO designation was developed as a way for organizations to clearly identify a commitment to secure development practices, through adherence to the respective requirements and constructs of the SCA framework, and through employing SCA-certified individuals to operationalize those practices.
Secure Development Organization (SDO)

The SDO designation is how an organization evidences, at the organization level, that it governs secure development practices rather than leaving them to individual discipline. There are three levels, and the level an organization holds depends on the number of SCA Practitioners and SCA Architects it employs.
Ideal for: software producers, product companies and service providers that need to show customers and regulators a durable organizational commitment to Secure Software Development Practices.
- Adherence to the requirements and constructs of the SCA framework
- Employment of SCA-certified individuals to operationalize secure development practices
- Three designation levels based on CSCAP and CSCAA headcount
- Independent of CODE: an organization does not have to be an SDO to seek CODE certification
Three Levels Of Organizational Commitment
There are three (3) different levels of SDO. The level depends on the number of SCA Practitioners and SCA Architects employed by the organization.
SDO 1 – Foundational
Entry-level designation indicating an organization's foundational commitment to secure development practices and SCA-certified personnel.
SDO 2 – Intermediate
Demonstrated investment in SCA-certified personnel. Minimum staffing of CSCAPs and CSCAAs reflects organizational maturity.
SDO 3 – Advanced
Highest SDO designation. Significant SCA Practitioner and Architect headcount reflects deep, sustained organizational commitment.
How Organizations Qualify
An SDO designation rests on two things, held together. Neither on its own is sufficient.
Framework Adherence
Adherence to the respective requirements and constructs of the SCA framework.
Certified Personnel
Employing SCA-certified individuals, the CSCAPs and CSCAAs who operationalize secure development practices day to day.
Next Steps In The SCA Certification Path
The SDO designation is one of two organization-level paths. Organizations seeking third-party conformity assessment against the CISA SSDAF or NIST SP 800-218 pursue CODE, and the individual credentials that underpin an SDO level are the CSCAP and CSCAA.
CODE Certification
Third-party conformity assessment of secure development practices, accredited by The Cyber AB and assessed through the SCF CAP.
SCA Practitioner
Practitioner Level. The CSCAP credential held by the developers whose headcount contributes to an SDO level.
SCA Architect
Architecture & Design. The CSCAA credential held by the architects whose headcount contributes to an SDO level.
.png)
%20(white).png)