Key Takeaways - Individual SCA Certifications
- The Secure Code Alliance (SCA) addresses the need for developers to implement Secure Software Development Practices (SSDP).
- Two certifications. Certified SCA Practitioner (CSCAP) and Certified SCA Architect (CSCAA).
- These are for software developers and architects only. Not project managers, security managers or IT directors.
- Based on the SCA Body of Knowledge (SCA-BoK) and industry-recognized secure development practices.
- Certified individuals demonstrate competence to ensure application security throughout the operational lifecycle.
- SSDP is increasingly required by statutory, regulatory and contractual obligations across all industries.
SCA PractitionerWhat Is The SCA Practitioner Certification?


Certified SCA Practitioners (CSCAP) are certified individuals who have the knowledge and skills to:
- Implement SCF controls that align with the SCF recommended practices and structure; and
- Maintain an organization’s cybersecurity and data protection program.
Can you look a client in the eyes and honestly answer that you can currently demonstrate that you know what Secure Software Development Practices (SSDP) are? How can you prove that? The CSCAP is evidence you can use to demonstrate competence and even compliance with requirements from EO 14028 for SSDP.
Software developers (practitioners) are expected to use Secure Development Lifecycle (SDL) processes for new systems, system upgrades, or systems that are being repurposed. These processes can be employed at any stage of the system lifecycle and can take advantage of any system or software development methodology, including agile, spiral, or waterfall.
Individuals who earn a CSCAP demonstrate a level of competence necessary to ensure that the security of an organization’s applications, services, and processes are assessed throughout their operational life to reduce risks to the organization and its clients.
If you are interested in becoming a CSCAP, the first step is to take CSCAP training to start that journey, which you can begin here -
https://training.securecontrolsframework.com/products/courses/sca-practitioner!
SCA ArchitectWhat Is The SCA Architect Certification?


Certified SCA Architects (CSCAA) are certified individuals who are:
- Qualified to architect and design SCF-based cybersecurity and data protection programs;
- Capable of addressing the tactical, operational and strategic needs of the organization; and
- Qualified to assist SCA Practitioners with the implementation of SCF controls to turn concepts into reality.
Can you look a client in the eyes and honestly answer that you can currently demonstrate that you know what Secure Software Development Practices (SSDP) are? How can you prove that? The CSCAA is evidence you can use to demonstrate competence and even compliance with requirements from EO 14028 for SSDP.
Software architects (architects) are expected to employ cyber resiliency constructs (e.g., goals, objectives, techniques, approaches, and design principles), as well as the analytic and lifecycle processes, to tailor them to the technical, operational, and threat environments for which the architect’s systems need to be engineered.
Individuals who earn a CSCAA certification demonstrate a level of competence necessary to ensure that the security of an organization’s applications, services, and processes are assessed throughout their operational life to reduce risks to the organization and its clients.
If you are interested in becoming a CSCAA, the first step is to take CSCAA training to start that journey, which you can begin here -
https://training.securecontrolsframework.com/products/courses/sca-architect!
Common QuestionsFrequently-Asked Questions
Here are answers to common questions about the SCA individual certification:
What is the Secure Code Alliance (SCA)?
The Secure Code Alliance (SCA) is a program that certifies software developers and architects in Secure Software Development Practices (SSDP) and recognizes organizations that apply those practices. Individuals earn the CSCAP or CSCAA credential, while organizations can earn designations based on their certified staff or on conformity assessments. The SCA program is published on the Secure Controls Framework website, its organizational CODE assessments use the SCR CAP methodology, and The Cyber AB is the accreditation body for those assessments.
What is the difference between CSCAP and CSCAA?
The Certified SCA Practitioner (CSCAP) is for software developers who apply Secure Development Lifecycle processes in day-to-day work. The Certified SCA Architect (CSCAA) is for software architects who apply cyber resiliency constructs and tailor them to technical, operational and threat environments. CSCAP shows hands-on secure development competence, while CSCAA shows architectural and strategic security competence. Both are built on the SCA Body of Knowledge.
Can project managers or security managers get an SCA certification?
The SCA certifications are intended for software developers and architects only, not project managers, security managers or IT directors. The training focuses on technical secure development topics, such as secure coding practices, the OWASP Top 10 and software bills of materials. Security and GRC professionals who manage programs are a better fit for the SCR Practitioner, SCR Architect or SCR Assessor certifications offered through the Secure Controls Framework.
What topics does the SCA Practitioner course cover?
The SCA Practitioner (CSCAP) course covers secure software development guidance and the requirements that drive it. Topics include NIST SP 800-218, which is the Secure Software Development Framework (SSDF), along with NIST SP 800-218A, NIST SP 800-160, the OWASP Top 10, software bills of materials and secure coding practices. The course also ties development work to requirements such as Executive Order 14028, NIST SP 800-171, PCI DSS v4.0 and ISO 27002:2022.
Can a software company get certified by the Secure Code Alliance?
Yes, organizations can earn SCA designations. The Certified Organization for Development Excellence (CODE) designation comes from a conformity assessment, with CODE 1 assessed against the CISA Secure Software Development Attestation Form and CODE 2 against NIST SP 800-218. These assessments use the SCR CAP methodology. Separately, the Secure Development Organization (SDO) designation has three levels based on how many certified SCA Practitioners and Architects a company employs.