Key Takeaways - Individual Certifications
- The SCF offers three individual certifications. SCR Practitioner, SCR Architect and SCR Assessor.
- The SCA offers two individual certifications. Certified SCA Practitioner (CSCAP) and Certified SCA Architect (CSCAA).
- SCR certifications are for cybersecurity and GRC professionals who evaluate and implement SCF controls.
- SCA certifications are for software developers and architects focused on Secure Software Development Practices (SSDP).
- All courses use Computer-Based Training (CBT). Learn at your own pace.
- Managed by the SCR Assessor and Instructor Certification Organization (SAICO).
Individual-Level CertificationsCertification Programs
Two complementary certification programs serve different audiences. SCF for cybersecurity and GRC professionals, SCA for software developers and architects.
For cybersecurity and GRC professionals who use the SCF. These certifications equip professionals with the expertise to evaluate and implement SCF controls effectively, ensuring organizations meet regulatory and security best practices. Includes SCR Practitioner, SCR Architect and SCR Assessor levels.
For software developers and architects. Not project managers, security managers or IT directors. Focused purely on Secure Software Development Practices (SSDP) concepts that developers deal with daily, based on the SCA Body of Knowledge (SCA-BoK). Includes Certified SCA Practitioner (CSCAP) and Certified SCA Architect (CSCAA) levels.
All Certifications Use Computer-Based Training (CBT)
Enabling you to learn at your own pace and make the most out of your professional development. Managed by the SCR Assessor and Instructor Certification Organization (SAICO).
SCR CertificationsWhat Certifications Does the Secure Controls Framework (SCF) Offer?
The Secure Controls Framework (SCF) offers three (3) individual-level certifications:
SCA CertificationsWhat Certifications Does the Secure Code Alliance (SCA) Offer?
The Secure Code Alliance (SCA) offers two (2) individual-level certifications:
Common QuestionsFrequently-Asked Questions
Here are answers to the questions professionals ask most about individual certifications:
What is the difference between SCR and SCA certifications?
SCR certifications are for cybersecurity and GRC professionals who implement, design or assess programs built on the Secure Controls Framework. SCA certifications from the Secure Code Alliance are for software developers and architects focused on Secure Software Development Practices (SSDP). The SCF offers three SCR certifications, which are SCR Practitioner, SCR Architect and SCR Assessor. The SCA offers two, the Certified SCA Practitioner (CSCAP) and Certified SCA Architect (CSCAA).
Who manages SCF individual certifications?
SCF individual certifications are managed by SAICO, the SCF Assessor and Instructor Certification Organization, which is a department of the Secure Controls Framework. SAICO runs the SCR Practitioner, SCR Architect and SCR Assessor tracks, and SAICO certification tracks also cover the Secure Code Alliance credentials. This is separate from organization-level certification, where The Cyber AB accredits the 3PAOs that perform SCR CAP assessments.
Are SCF and SCA certification courses self-paced?
Yes, SCF and Secure Code Alliance certification courses use self-paced Computer-Based Training (CBT) on the SCF training platform. Candidates work through the material on their own schedule, and each course ends with a knowledge exam. The time needed varies by track, and the SCF syllabus suggests at least four hours for the SCR Practitioner course, plus extra study time for unfamiliar material.
Is an individual SCR certification the same as an organization's SCR certification?
No, an individual SCR certification shows that a person has the knowledge to implement, design or assess SCF-based programs. An organization-level SCR certification, such as SCR Certified NIST CSF 2.0, is earned by a company after an accredited SCR 3PAO completes a conformity assessment. The two connect through the SCR Assessor credential, because certified SCR Assessors work for SCR 3PAOs to perform those organization assessments.
Which SCF certification should a GRC analyst start with?
A GRC analyst should usually start with the SCR Practitioner certification, which is the foundation-level SAICO credential. It covers the structure of the SCF across its 34 control domains, practical control implementation, and how practitioners fit into the SCR CAP ecosystem. From there, professionals can move to SCR Architect for program design or to SCR Assessor for conformity assessment work.