Secure Controls Framework
The Secure Controls Framework (SCF) is a comprehensive, freely available catalog of cybersecurity and data privacy controls designed to help organizations build and manage their security and privacy programs. Rather than being a single standalone standard, it acts as a 'framework of frameworks' that maps its controls to many different laws, regulations, and industry frameworks. This mapping is intended to help organizations meet the requirements of multiple frameworks through a single, unified set of controls.
The SCF is a metaframework (a framework of frameworks) that consolidates commonly-used cybersecurity and privacy controls and maps them to numerous external authoritative sources, including laws, regulations, and frameworks. Also referred to as the Common Controls Framework (CCF), it provides a control catalog intended to enable organizations to design, build, and maintain secure and privacy-conscious processes, and to address requirements drawn from multiple frameworks through a common control set. As a mapping and metaframework resource, the SCF is distinct from attestation or certification regimes: it is not itself an audit standard like SOC 2 (an AICPA SSAE 18 attestation resulting in a report) nor a certifiable management system standard like ISO/IEC 27001 (certified by an accredited certification body). Its crosswalks to those frameworks are informative aids to control selection and are typically partial, so use of the SCF does not by itself satisfy the specific requirements of any individual framework, which depend on the applicable scope, criteria, auditor, or certification body.
Why it matters
Most organizations do not face a single compliance obligation in isolation. A growing company may need to demonstrate SOC 2 controls to enterprise customers, pursue ISO/IEC 27001 certification for international markets, and simultaneously address privacy laws and sector-specific regulations. Maintaining separate control sets for each of these obligations creates duplication, gaps, and audit fatigue. The Secure Controls Framework matters because it offers a single, freely available catalog of controls that maps to many external laws, regulations, and frameworks, allowing an organization to work from one unified control set rather than reconciling several overlapping ones.
By consolidating commonly-used cybersecurity and privacy requirements and crosswalking them to numerous authoritative sources, the SCF can reduce redundant effort when a program must satisfy multiple frameworks at once. For GRC teams, this can streamline how controls are designed, documented, and evidenced across concurrent obligations, and it can make it easier to see where a single control contributes to several external requirements.
However, the SCF's value is as an organizing and mapping aid, not as a substitute for the frameworks it references. Its crosswalks to standards such as SOC 2 and ISO/IEC 27001 are informative and typically partial. Using the SCF does not itself produce a SOC 2 report, which is an AICPA SSAE 18 attestation issued by a licensed CPA firm, nor an ISO/IEC 27001 certificate, which is issued by an accredited certification body against the ISMS requirements in clauses 4 through 10. Compliance managers should treat the SCF as a starting point for control selection while recognizing that meeting any individual framework still depends on that framework's specific scope, criteria, auditor, or certification body.
Who it's relevant to
Inside SCF
Common questions
Answers to the questions practitioners most commonly ask about SCF.