Secure Controls Framework
Download The SCF

SCR Conformity Assessment Program (CAP)

The SCR CAP is an organization-level conformity assessment designed to utilize tailored cybersecurity and privacy controls that specifically address the applicable statutory, regulatory, and contractual obligations an Organization Seeking Assessment (OSA) is required to comply with. By using the metaframework nature of the SCF, an OSA is able to perform conformity assessments that span multiple cybersecurity and privacy-specific laws, regulations, and frameworks.

Third-Party Validated Certification

What Is the SCR CAP?

The SCR CAP exists to leverage SCF content to provide a company-level certification through a conformity assessment process. Earning a SCR Certified™ conformity designation is meant to signify a real accomplishment, not a “participation ribbon” that has little practical value for the OSA’s stakeholders to understand its overall security posture.

The SCF Council established the SCR CAP as a structure to conduct security, compliance, and resilience-related Third-Party Assessment, Attestation, and Certification (3PAAC) Services. While the SCR CAP shares similarities with single-focused certifications (e.g., ISO 27001, CMMC, FedRAMP), it is unique in its metaframework approach to covering multiple laws, regulations, and frameworks simultaneously.

The SCR CAP is designed to produce a deliverable Report on Conformity (ROC) with a designation that summarizes the organization’s overall security, compliance, and resilience program. It leverages concepts established in the Cybersecurity & Data Protection Assessment Standards (CDPAS).

Assessment Methodology: Examine, Interview & Test

The SCR CAP utilizes an examine, interview, and test assessment methodology to demonstrate conformity with multiple requirements simultaneously. This approach allows the SCR CAP to scale. For example, it can demonstrate conformity with NIST CSF, HIPAA, and EU GDPR as part of one engagement rather than three separate assessments.

The SCR CAP allows an organization to specify the applicable statutory, regulatory, and contractual obligations to establish a Minimum Security Requirements (MSR) control set. It leverages leading industry assessment practices to avoid reinventing assessment methodologies.

Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP) Body of Knowledge
SCR CAP Body of Knowledge

Download the SCR CAP BoK (PDF) for the complete assessment methodology, accreditation requirements, 3PAAC standards, and program structure.

Designed by Practitioners, for Practitioners

SCR CAP Key Design Principles

The SCR CAP is designed for cybersecurity and privacy practitioners, by cybersecurity and data privacy practitioners. This concept is based on the need within the industry for a tailored conformity assessment solution capable of addressing several key considerations.

Compliance as a By-Product

View compliance as a natural by-product of secure practices, not a standalone objective. The SCR CAP assesses real security posture across security, compliance, and resilience.

Multi-Framework Scalability

Scale to address multifaceted operational requirements across laws, regulations, and frameworks simultaneously. One assessment satisfies NIST CSF, HIPAA, GDPR, and more.

Risk Tolerance Acknowledgment

Acknowledge the stated risk tolerance of the OSA. The assessment adapts to the organization’s context using NIST-defined risk appetite, tolerance, and threshold distinctions.

Anti-Gaming Protections

Minimize the risk of “gaming” the certification process. The examine, interview, and test methodology ensures substantive evidence review with material control identification.

Technology-Driven Efficiency

Supports Manual Point in Time (MPIT), Augmented Point in Time (APIT), and Augmented Evidence with Human Review (AEHR) assessment methods to reduce costs.

Industry-Recognized Practices

Based on NIST SP 2000-01 (ABC’s of Conformity Assessment), ISO/IEC 17000, ISO/IEC 17065, and CDPAS standards rather than reinventing assessment approaches.

Assessment Criteria

SCR CAP Conformity Designations & Assessment Rigor

The SCR CAP produces a Report on Conformity (ROC) that assigns one of four conformity designations based on assessment findings. Each control is designated as satisfactory, deficient, compensating, or not applicable.

Three Levels of Assessment Rigor

The SCR CAP defines three levels of assessment rigor that determine the depth and scope of evidence evaluation:

Level 1
Standard Rigor

Baseline assessment depth for organizations with lower risk profiles or initial certifications.

Level 2
Enhanced Rigor

Deeper evidence review for organizations with moderate risk profiles or regulatory requirements demanding increased scrutiny.

Level 3
Comprehensive Rigor

Maximum assessment depth for high-risk profiles, critical infrastructure, or stringent regulatory obligations.

Three Assessment Methods

The SCR CAP supports three assessment methods that range from traditional manual assessments to technology-augmented continuous assessments:

MPIT
Manual Point in Time

Traditional methodology where evidence is manually reviewed at a specific point in time by the assessment team.

APIT
Augmented Point in Time

Automation augments the traditional methodology, using AI/autonomous technologies to compare desired state vs. current state via machine-readable configurations.

AEHR
Augmented Evidence with Human Review

Ongoing, continuous control assessment where automation continuously evaluates controls with recurring human reviews to validate findings.

Cybersecurity Materiality & Material Controls

The SCR CAP incorporates cybersecurity materiality into the assessment process. Material controls are fundamental controls whose absence or failure exposes an organization to material impact. They cannot have compensating controls. The SCF designates material controls, material risks, material threats, and material incidents.

Certification Process

Two-Phase SCR Certification Process

The SCR certification process consists of two primary phases that take the OSA from self-assessment through third-party validated certification.

Phase 1: First-Party Declaration (1PD)

The OSA conducts an internal self-assessment to evaluate control implementation against applicable SCF controls. This establishes the assessment boundary, defines the Statement of Applicability (SoA), identifies the MSR control set, and produces a first-party declaration of conformity status. The 1PD phase prepares the OSA by identifying gaps and establishing evidence before engaging a 3PAO.

Phase 2: 3PAAC (Third-Party Assessment, Attestation & Certification)

A qualified 3PAO conducts the formal assessment using examine, interview, and test methodology. The 3PAO produces a Report on Conformity (ROC) consisting of a Technical Assessment Report (TAR) and Executive Assessment Report (EAR). Upon successful completion, the OSA receives the SCR Certified™ designation validated by The Cyber AB.

SCR Certified™ Options

Certifications are available in two forms: (1) LRF-Specific SCR Certification, certifying conformity against a specific authority (e.g., SCR Certified for NIST CSF 2.0); and (2) Tailored SCR Certification, certifying conformity against a custom MSR control set based on the OSA's specific obligations.

SCR CAP Ecosystem

Key Players in the SCR CAP Ecosystem

There are several key players in the SCR CAP Ecosystem that together form a complete, governed conformity assessment infrastructure.

The SCR Ecosystem page is the full reference for who governs what, including The Cyber AB, the Cyber EF, SAICO and the SCF Council.

3PAO

SCR Third-Party Assessment Organizations

Independent assessment organizations accredited to conduct SCR CAP conformity assessments on behalf of organizations seeking certification.

OSA

SCR Organizations Seeking Assessment

The organization pursuing an SCF-based certification, whose security posture and controls implementation is being evaluated but which has not yet completed an SCR CAP conformity assessment.

ASP

SCR Authorized Solutions Providers

Cloud-based platforms and service providers, including CSPs, MSPs and MSSPs, that operate within the defined scope of the SCF and give organizations a structured environment for implementing it.

RPO

SCR Registered Provider Organizations

Consulting and advisory organizations registered to provide SCF implementation, advisory, and assessment preparation services.

CAT

SCR Control Assurance Tools

Governance, Risk and Compliance platforms that specialize in integrating the SCF, so that compliance interpretation and risk management are operationalized inside the tools an organization already runs.

LTP

SCR Licensed Training Providers

Organizations certified by SAICO to deliver approved individual-level certification training programs using SCR Trainers.

LCP

SCF Licensed Content Providers

Organizations authorized by the SCF Council to create derivative SCF content, such as SCF-based policies, standards and procedures.

CAP

SCR Conformity Assessment Program

The program framework that governs all ecosystem participant roles, assessment standards, and certification requirements. Accreditation Body: The Cyber AB.

SCR CAP Ecosystem Flow diagram
Assessment Boundary Scoping

Assessment Boundary Demarcation & PPTDF

The SCR CAP requires clear assessment boundary demarcation using the People, Processes, Technologies, Data, and Facilities (PPTDF) model. The Unified Scoping Guide (USG) provides the methodology for defining what is in scope.

Secure, Compliant & Resilient Management System (SCRMS)

Distinguishes between Minimum Compliance Requirements (MCR), which are mandatory controls driven by obligations, and Discretionary Security Requirements (DSR), which are voluntary controls based on industry practices and risk tolerance.

Control Inheritance & Reciprocity

Supports control inheritance (receiving protection from other entities’ controls) and reciprocity (accepting each other’s assessments). Documented through First-Party Declarations (1PD) and Third-Party Attestations (3PA).