Skip to main content
Category: Standards and Frameworks

Secure Controls Framework

Also known as: SCF, Common Controls Framework, CCF, SCF metaframework
Simply put

The Secure Controls Framework (SCF) is a comprehensive, freely available catalog of cybersecurity and data privacy controls designed to help organizations build and manage their security and privacy programs. Rather than being a single standalone standard, it acts as a 'framework of frameworks' that maps its controls to many different laws, regulations, and industry frameworks. This mapping is intended to help organizations meet the requirements of multiple frameworks through a single, unified set of controls.

Formal definition

The SCF is a metaframework (a framework of frameworks) that consolidates commonly-used cybersecurity and privacy controls and maps them to numerous external authoritative sources, including laws, regulations, and frameworks. Also referred to as the Common Controls Framework (CCF), it provides a control catalog intended to enable organizations to design, build, and maintain secure and privacy-conscious processes, and to address requirements drawn from multiple frameworks through a common control set. As a mapping and metaframework resource, the SCF is distinct from attestation or certification regimes: it is not itself an audit standard like SOC 2 (an AICPA SSAE 18 attestation resulting in a report) nor a certifiable management system standard like ISO/IEC 27001 (certified by an accredited certification body). Its crosswalks to those frameworks are informative aids to control selection and are typically partial, so use of the SCF does not by itself satisfy the specific requirements of any individual framework, which depend on the applicable scope, criteria, auditor, or certification body.

Why it matters

Most organizations do not face a single compliance obligation in isolation. A growing company may need to demonstrate SOC 2 controls to enterprise customers, pursue ISO/IEC 27001 certification for international markets, and simultaneously address privacy laws and sector-specific regulations. Maintaining separate control sets for each of these obligations creates duplication, gaps, and audit fatigue. The Secure Controls Framework matters because it offers a single, freely available catalog of controls that maps to many external laws, regulations, and frameworks, allowing an organization to work from one unified control set rather than reconciling several overlapping ones.

By consolidating commonly-used cybersecurity and privacy requirements and crosswalking them to numerous authoritative sources, the SCF can reduce redundant effort when a program must satisfy multiple frameworks at once. For GRC teams, this can streamline how controls are designed, documented, and evidenced across concurrent obligations, and it can make it easier to see where a single control contributes to several external requirements.

However, the SCF's value is as an organizing and mapping aid, not as a substitute for the frameworks it references. Its crosswalks to standards such as SOC 2 and ISO/IEC 27001 are informative and typically partial. Using the SCF does not itself produce a SOC 2 report, which is an AICPA SSAE 18 attestation issued by a licensed CPA firm, nor an ISO/IEC 27001 certificate, which is issued by an accredited certification body against the ISMS requirements in clauses 4 through 10. Compliance managers should treat the SCF as a starting point for control selection while recognizing that meeting any individual framework still depends on that framework's specific scope, criteria, auditor, or certification body.

Who it's relevant to

GRC and Compliance Managers
Teams responsible for multiple concurrent obligations can use the SCF to work from a single unified control set and rely on its mappings to see where one control contributes to several frameworks. This can reduce duplication, though managers should confirm that the SCF's partial crosswalks fully cover each framework's specific requirements before relying on them for an audit or certification.
Security Engineers and Program Builders
Because the SCF provides a comprehensive catalog of cybersecurity and privacy controls, engineers can use it to design, build, and maintain secure processes from a common baseline rather than assembling controls from scratch for each standard.
SOC 2 and ISO 27001 Practitioners
Auditors and certification candidates can use the SCF's crosswalks as a starting point to align controls with SOC 2 Trust Services Criteria or ISO/IEC 27001 ISMS requirements and Annex A reference controls. Practitioners should remember that the SCF is neither an attestation standard nor a certifiable management system standard, and that its mappings do not by themselves satisfy either framework.
Organizations Facing Multiple Regulatory Regimes
Companies subject to numerous laws, regulations, and frameworks at once may benefit from the SCF's consolidation of commonly-used requirements into one catalog. Its freely available nature makes it accessible for organizations seeking a structured way to organize controls across overlapping obligations.

Inside SCF

Metaframework Structure
The SCF is a metaframework, meaning it is a comprehensive catalog of controls designed to be mapped against numerous authoritative sources rather than a single standalone standard. It aims to consolidate requirements from multiple frameworks, laws, and regulations into a unified control set.
Control Domains
The SCF organizes its controls into a series of domains covering areas such as governance, risk management, access control, and incident response. The specific number of domains and controls varies by SCF version, so practitioners should reference the edition in use rather than assuming a fixed count.
Cross-Framework Mappings
A core feature is the mapping of each SCF control to corresponding requirements in other frameworks and criteria, which may include SOC 2 Trust Services Criteria and ISO/IEC 27001. These mappings are intended to support organizations pursuing multiple frameworks concurrently, though the coverage and precision of any given mapping depend on the version and should be independently validated.
Relationship to SOC 2 and ISO 27001
The SCF is distinct from both SOC 2 and ISO 27001. SOC 2 is an attestation examination performed by a licensed CPA firm under AICPA SSAE 18, resulting in a report; ISO/IEC 27001 is a certification issued by an accredited certification body against a management system standard. The SCF is neither an attestation nor a certification scheme and confers no such outcome on its own.

Common questions

Answers to the questions practitioners most commonly ask about SCF.

Is the Secure Controls Framework (SCF) a certifiable standard like ISO 27001?
No. The SCF is a reference catalog of controls designed to be mapped across many frameworks and regulations; it is not itself a certifiable standard. Unlike ISO/IEC 27001, which results in a certification issued by an accredited certification body against the ISMS requirements in clauses 4 through 10, the SCF does not have an accreditation or certification scheme of its own. Organizations typically use it as a meta-framework to organize controls and support compliance efforts, then pursue certification or attestation against the specific frameworks they need, such as ISO 27001 or a SOC 2 examination.
Does adopting the SCF mean I automatically satisfy SOC 2 and ISO 27001 at the same time?
No. The SCF provides mappings that can help identify where controls overlap across frameworks, but mapping is partial and satisfying one framework does not automatically satisfy another. A SOC 2 examination is an attestation performed by a licensed CPA firm under the AICPA SSAE 18 standard against the Trust Services Criteria, while ISO 27001 certification is issued against the ISMS requirements and involves selecting Annex A reference controls through a Statement of Applicability. The SCF can reduce duplicated effort, but each framework's specific evidence, scope, and assessment requirements must still be met independently.
How can the SCF help when we need to pursue both a SOC 2 report and ISO 27001 certification?
Because the SCF is structured as a cross-framework catalog, teams typically use it to consolidate control requirements so a single set of implemented controls can be mapped to multiple objectives. In most engagements this helps identify overlaps between the Trust Services Criteria used in a SOC 2 examination and the ISO 27001 ISMS requirements and Annex A reference controls. However, the mappings are a starting point; scoping decisions, the auditor or certification body, and applicable criteria will still determine what evidence is required for each outcome.
Where does the SCF fit relative to selecting ISO 27001 Annex A controls?
The SCF can serve as an internal control library from which you organize and document your controls, but it does not replace the ISO 27001 process. Under ISO 27001, Annex A reference controls are selected via a Statement of Applicability informed by a risk assessment, and the version matters since the 2022 revision restructured Annex A into four themes. If you use the SCF, you would typically map your chosen SCF controls to the applicable Annex A controls for the version you are certifying against, keeping the Statement of Applicability as the authoritative record of inclusion and exclusion.
Can the SCF be used to define the scope of a SOC 2 examination?
Not directly. Scope for a SOC 2 examination is driven by which Trust Services Criteria categories apply, where Security (the Common Criteria) is required and Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope. The SCF can help you organize the controls that support those criteria, but the CPA firm performing the examination assesses your controls against the Trust Services Criteria, not against the SCF. The framework you use internally to catalog controls does not change what the auditor evaluates.
What are the limitations of relying on the SCF for compliance decisions?
The SCF is a control catalog and mapping resource, so it does not by itself produce any assurance outcome. It does not generate a SOC 2 report, which attests only to the controls and period covered and does not guarantee freedom from breaches, and it does not produce an ISO 27001 certificate, which covers only the defined scope of the ISMS. Its mappings are intended to support, not replace, the judgment of your auditor or certification body, and their accuracy for a given framework version should be verified. Treat the SCF as an organizing tool rather than a substitute for framework-specific requirements.

Common misconceptions

Adopting the SCF automatically produces a SOC 2 report or an ISO 27001 certificate.
The SCF is a control catalog and mapping resource, not a certification or attestation scheme. A SOC 2 report can only result from an examination by a licensed CPA firm under SSAE 18, and an ISO 27001 certificate can only be issued by an accredited certification body. Using the SCF may help organize controls, but it does not itself confer either outcome.
The SCF's cross-framework mappings mean that satisfying SCF controls guarantees compliance with SOC 2 and ISO 27001 simultaneously.
Mappings between frameworks are typically partial and depend on scope, version, and interpretation. Satisfying an SCF control mapped to a Trust Services Criterion or an ISO 27001 requirement does not automatically satisfy that requirement in an actual engagement; the auditor, certification body, and defined scope determine the outcome.
The SCF has a fixed, unchanging number of controls and domains.
The SCF is revised over time, and the number of controls and domains varies by version. Practitioners should always cite the specific edition in use rather than relying on a fixed figure.

Best practices

Identify and document the specific SCF version in use, since control counts, domains, and mappings differ between editions.
Independently validate any SCF-to-framework mapping against the authoritative source (such as the current SOC 2 Trust Services Criteria or the applicable ISO/IEC 27001 edition) before relying on it for scoping decisions.
Treat the SCF as an organizing and planning tool rather than a substitute for a SOC 2 examination or an ISO 27001 certification, and engage a licensed CPA firm or an accredited certification body for the respective formal outcomes.
When pursuing multiple frameworks, use the SCF mappings to reduce duplicated effort, but confirm scope-specific requirements with your auditor or certification body, since coverage is typically partial.
Maintain traceability between implemented controls and the framework requirements they are intended to address, so that gaps in SOC 2 or ISO 27001 coverage remain visible.
Reassess SCF adoption and mappings when either the SCF or a target framework is revised, as changes such as the ISO 27001 Annex A restructuring can affect how controls align.