SCRP 2026.2
A moderate update that adds a new Quantum Security (QTS) domain to address post-quantum cryptography risk, refreshes policies against updated SCF domain principles, and strengthens DFARS-related standards.
What changed in this release
- Updated policies, based on refreshed domain principles from the Secure Controls Framework (SCF).
- Refreshed and strengthened guidelines for many controls.
- Strengthened standards for DFARS-related requirements.
- New Quantum Security (QTS) domain, added to address the threat posed by Post-Quantum Cryptography (PQC).
- Wording standardized from “cybersecurity & data protection” to “security, compliance and resilience” throughout the documents.
- Updated maturity model criteria.
- Updated “possible solutions & considerations” criteria.
- Updated compensating controls guidance.
- Set Theory Relationship Mapping (STRM) is now published for all mapped laws, regulations and frameworks, with the exception of NIST 800-53 R4 (deprecated) and the SIG (mappings provided by the Santa Fe Group).
- Changes to the SCRP are highlighted in green so updated content is easy to identify.
Releases older than 2024 (2023 and beyond) are not covered by this errata archive and are significantly out of date. Existing customers are encouraged to repurchase the current version at 50% of the original product price.