Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

Individual Secure Controls Framework (SCF) Certifications

If you use the Secure Controls Framework (SCF), it is worthwhile to explore SCF training and certifications. There are three (3) SCR certifications for individuals:

  • SCR Practitioner
  • SCR Architect
  • SCR Assessor
Key Takeaways - Individual SCR Certifications
  • Three SCF individual certifications. SCR Practitioner, SCR Architect and SCR Assessor.
  • Managed by the SCR Assessor and Instructor Certification Organization (SAICO).
  • Equip professionals with expertise to evaluate and implement SCF controls effectively.
  • All courses use Computer-Based Training (CBT). Learn at your own pace.
  • SCR Assessors work for SCR 3PAOs to perform SCR Certification services for organizations.
SCR Practitioner

What Is The SCR Practitioner Certification?

SCR Practitioner Banner
SAICO SCR Practitioner

SCR Practitioners are SAICO-certified individuals who have the knowledge and skills to:

  • Implement SCF controls that align with the SCF recommended practices and structure; and
  • Maintain an organization’s cybersecurity and data protection program.
If you are interested in becoming an SCR Practitioner, the first step is to take SCR Practitioner training to start that journey, which you can begin here - https://training.securecontrolsframework.com/products/courses/scf-practitioner-training!
SCR Architect

What Is The SCR Architect Certification?

SCR Architect Banner
SAICO SCR Architect

SCR Architects are certified individuals who are:

  • Qualified to architect and design SCF-based cybersecurity & data protection programs;
  • Capable of addressing the tactical, operational & strategic needs of the organization; and
  • Qualified to assist SCR Practitioners with the implementation of SCF controls to turn concepts into reality.
If you are interested in becoming an SCR Architect, the first step is to take SCR Architect training to start that journey, which you can begin here - https://training.securecontrolsframework.com/products/courses/scf-architect-training!
SCR Assessor

What Is The SCR Assessor Certification?

SCR Assessor Banner
SAICO SCR Assessor

SCR Assessors are certified individuals who are:

  • Qualified to participate in and/or lead an SCR Third-Party Assessment Organization's (3PAO's) assessment team to perform Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP) assessments; and
  • Knowledgeable to analyze SCF controls to determine if the control is appropriate, properly implemented & produces the desired results to meet Assessment Objectives (AOs).
If you are interested in becoming an SCR Assessor, the first step is to take SCR Assessor training to start that journey, which you can begin here - https://training.securecontrolsframework.com/products/courses/scf-assessor-training!
Common Questions

Frequently-Asked Questions

Here are answers to common questions about earning an individual SCF certification:

How do I become an SCF assessor?
To become an SCF assessor, complete SCR Assessor training through SAICO and pass the certification exam, which has 100 questions. The SAICO syllabus also requires a qualifying credential, such as Security+ for entry-level assessors or CISA or CISSP for assessment team leads, or a related bachelor's degree from an ABET-accredited or CAE-designated school. Certified SCR Assessors then work for SCR 3PAOs accredited by The Cyber AB to perform SCR CAP assessments.
What is the SCR Practitioner certification?
The SCR Practitioner is the foundation-level SAICO certification for professionals who implement and maintain SCF-based cybersecurity and data protection programs. It is aimed at GRC analysts, compliance officers, security program managers and IT security staff. The SAICO syllabus calls for at least six months of practical SCF experience, and the closed-book exam has 50 questions with a 90-minute time limit.
What are the prerequisites for the SCR Architect certification?
The SCR Architect certification requires a prior SCR Practitioner certification and at least five years of experience as a full-time cybersecurity professional, according to the SAICO training syllabus. SCR Architects are qualified to design SCF-based cybersecurity and data protection programs that meet tactical, operational and strategic needs. They also help SCR Practitioners turn control concepts into working implementations. The exam is closed-book with 100 questions.
How long is an SCR individual certification valid?
SAICO certifications are valid for one year from issuance. To renew, the holder pays an annual certification maintenance fee and passes a knowledge test, or the certification expires. SCR Assessors must also complete at least 20 hours of Continuing Professional Education each year, while the SCR Practitioner role has no minimum CPE requirement. Keeping the credential current matters for assessors because they perform SCR CAP assessments for 3PAOs.
How do I get SCF certified as an individual?
To get SCF certified as an individual, pick the SCR track that fits your role, enroll in its self-paced training on the SCF training platform, and pass the exam. Practitioner suits people who implement and maintain controls, Architect suits people who design SCF-based programs, and Assessor suits people who will perform SCR CAP assessments for a 3PAO. Organizations seeking company-level certification follow the separate SCR CAP process instead.