Key Takeaways - SCR Certifications
- The Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP) enables organizations to earn certifications where no traditional certification exists.
- Governed by The Cyber AB. The same accreditation body the DoD uses for CMMC. Ensuring the highest level of assurance.
- Currently available. SCR Certified, NIST CSF 2.0 and SCR Certified, HIPAA Security Rule.
- Assessments are conducted by accredited SCR Third-Party Assessment Organizations (3PAOs) using SCF controls.
- ComplianceForge provides end-to-end support from gap assessment through certification, with partnership with StrikePath as a recommended 3PAO.
- Designed to be affordable, scalable and practitioner-driven. By cybersecurity professionals, for cybersecurity professionals.
A New ApproachA Third-Party Certification Using SCF Controls
As cybersecurity and data protection operations are multi-faceted, the SCR CAP is designed to ensure that assessed controls reflect the real-world requirements faced by an organization from a statutory, regulatory and contractual perspective. An assessment that only covers a part of an organization's cybersecurity and privacy program results in an inaccurate and incomplete report on its overall security posture, providing a false sense of security.
The SCR CAP is designed for cybersecurity & privacy practitioners by cybersecurity & data privacy practitioners. This concept is based on the need within the industry for a tailored conformity assessment solution that is capable of addressing several key considerations:
- View compliance as a natural by-product of secure practices;
- Scale to address multifaceted operational requirements (e.g., laws, regulations and frameworks);
- Acknowledge the stated risk tolerance of the OSC since not all organizations have the same risk tolerance;
- Minimize the risk of “gaming” the certification process that provides no useful insights into the security posture of the Organization Seeking Assessment (OSA);
- Utilize technology to make the assessment process more efficient to drive down labor-related assessment costs; and
- Leverage existing industry recognized practices, where possible.

What Is The SCR CAP Ecosystem?SCR CAP Ecosystem Overview
The SCR CAP Ecosystem is made up of several key stakeholders that cover organization-level certification, individual-level certification and more. You can download a PDF with more information on the various components that make up the SCR CAP Ecosystem.

SCR Certification Process FlowFlow Chart For How An SCR CAP Assessment
The flow chart below provides a very high level processes flow for how an SCR CAP assessment is structured:

Common QuestionsFrequently-Asked Questions
Here are answers to common questions about SCR certifications:
What is the SCR Conformity Assessment Program (SCR CAP)?
The SCR Conformity Assessment Program (SCR CAP) is an organization-level certification program that uses Secure Controls Framework (SCF) controls as its control set. An accredited SCR 3PAO assesses the Organization Seeking Assessment (OSA), and the program produces a Report on Conformity. Unlike single-focus certifications such as ISO 27001 or CMMC, the SCR CAP can assess conformity with several laws, regulations and frameworks in one engagement. Successful organizations earn an SCR Certified designation.
Who accredits SCR Third-Party Assessment Organizations?
The Cyber AB accredits SCR Third-Party Assessment Organizations (3PAOs). The SCF Council appointed The Cyber AB as the exclusive Accreditation Body for its conformity assessment program in December 2024, and The Cyber AB is also the official accreditation body for the DoD CMMC program. A 3PAO must be accredited before it can perform third-party assessment, attestation and certification services, and accredited 3PAOs are listed on The Cyber AB marketplace.
Which SCR certifications are available today?
The Secure Controls Framework lists several organization-level SCR certifications that are available now. Examples include NIST CSF 2.0, the HIPAA Security Rule, NY DFS 23 NYCRR Part 500, NIST SP 800-171 R3, NIST SP 800-161 R1 C-SCRM baseline, NIST SP 800-218, the CISA Secure Software Development Attestation Form, the New Zealand HISF and SCF CORE Fundamentals. Organizations with broader obligations can also pursue a tailored SCR certification against a custom SCF control set.
What happens during an SCR conformity assessment?
An SCR conformity assessment runs in two phases. In the first phase, the organization completes a First-Party Declaration based on an internal self-assessment. In the second phase, an accredited SCR 3PAO performs the third-party assessment using an examine, interview and test methodology at one of three rigor levels, called Standard, Enhanced and Comprehensive. The applicable SCR assessment guide lists the controls, Assessment Objectives and evidence expected for each certification.
What score is needed to pass an SCR certification assessment?
An organization needs at least 80 percent of assessed controls to be met and operational, with no material deficiency, to pass. Under the published SCR assessment guides for NIST CSF 2.0 and the HIPAA Security Rule, 100 percent earns a Strictly Conforms status and 80 percent or more earns Conforms, and both lead to certification. Results of 70 to 79 percent are a Significant Deficiency. Results below 70 percent, or any deficient material control, are a Material Weakness. Neither earns the designation.