The Secure Controls Framework Conformity Assessment Program (SCF CAP) is an organization-level conformity assessment, which means you can earn a certification using SCF controls. The SCF CAP is designed to utilize tailored cybersecurity and data privacy controls to specifically address the applicable statutory, regulatory and contractual obligations an Organization Seeking Assessment (OSA). The metaframework nature of the SCF enables an OSA is able to perform conformity assessment that can span multiple cybersecurity and data privacy-specific laws, regulations and frameworks.
ComplianceForge Is A SCF Licensed Content Provider (LCP)
ComplianceForge is a Licensed Content Provider (LCP) by the SCF. This means ComplianceForge is able to sell cybersecurity and data protection policies, standards and procedures based on SCF controls.
The benefit ComplianceForge brings as a SCF LCP is operationalizing the SCF by:
Decreased implementation costs (e.g., having to research and write policies, standards and procedures); and
Increased speed of implementation and adoption, since you have have the documentation the same day you order it.
ComplianceForge's SCF-based policies, standards and procedures can save an organization a significant amount of money from the labor-related costs to research, write and refine cybersecurity documentation.
SCF Certification Paths
The SCF CAP has a roadmap to enable the follow SCF-based certifications:
Australia Essential Eight
Canada B-13
Department of Homeland Security (DHS) Zero Trust Capability Framework (ZTCF)
DHS Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form
EU Digital Operational Resilience Act (DORA)
ENISA NIS2 (Directive (EU) 2022/2555)
Federal Acquisition Regulation (FAR) 52.204.21
Gramm Leach Bliley Act (GLBA) - CFR 314
New Zealand Health Information Security Framework 2022
NIST SP 800-66 R2 (HIPAA Secure Rule)
NIST SP 800-161 R1 (C-SCRM baseline)
NIST SP 800-171 R2 (non-CMMC)
NIST SP 800-171 R3 (non-CMMC)
NIST SP 800-207 (zero trust principles)
NY DFS 23 NYCRR500 - 2023 Amendment 2
Secure Code Alliance (SCA) Secure Software Development Practices (SSDP)
Trusted Information Security Assessment Exchange (TISAX) Information Security Assessment (ISA)
NIST CSF 2.0 Certification
The first framework that will be offered for certification is the NIST Cybersecurity Framework version 2 (NIST CSF 2.0). ComplianceForge has editable policies, standards and procedures for NIST CSF 2.0 that can help earn NIST CSF 2.0 certification via the SCF CAP.
Secure Controls Framework (SCF) "Premium Content" - Expertise-Class Policies, Control Objectives, Standards, Guidelines, Controls & Metrics.
Product Walkthrough Video
This short product walkthrough video is designed to give a brief overview about...
NIST Cybersecurity Framework 2.0 (NIST CSF 2.0) Policy Template - Editable Policies & Standards
Product Walkthrough Video
This short product walkthrough video is designed to give a brief overview about what the CDPP is to help answer common...
Cybersecurity Standardized Operating Procedures (CSOP) DSP | SCF Version
Product Walkthrough Video
This short product walkthrough video is designed to give a brief overview about what the CSOP is to help answer common questions we receive...
Cybersecurity Standardized Operating Procedures (CSOP) NIST Cybersecurity Framework 2.0
Product Walkthrough Video
This short product walkthrough video is designed to give a brief overview about what the CSOP is to help answer common...
Cybersecurity & Data Protection Program (CDPP) Bundle #1A - NIST CSF 2.0 (20% discount)
This is a bundle that includes the following two (2) ComplianceForge products that are focused on operationalizing the NIST Cybersecurity...
Cybersecurity & Data Protection Program (CDPP) Bundle #2 (30% discount)
This is a bundle that includes the following ten (10) ComplianceForge products that are focused on operationalizing the NIST Cybersecurity Framework (NIST CSF):
Cybersecurity...
Digital Security Plan (DSP) Bundle #1 - SCF-Aligned Policies, Standards & Procedures (25% Discount)
This is a bundle that includes the following two (2) ComplianceForge products that are focused on operationalizing the Secure Controls Framework...
Digital Security Plan (DSP) Bundle #2 - ENHANCED DIGITAL SECURITY (35% Discount)
This is a bundle that includes the following seven (7) ComplianceForge products that are focused on operationalizing the Secure Controls Framework (SCF):
Digital...
Digital Security Plan (DSP) Bundle #3 - ROBUST DIGITAL SECURITY (45% Discount)
This is a bundle that includes the following thirteen (13) ComplianceForge products that are focused on operationalizing the Secure Controls Framework (SCF):
Digital...