Secure Controls Framework
Secure Controls Framework Council, LLC publishes a free, volunteer-maintained cybersecurity and data privacy metaframework of 1,400+ controls across 33 domains, mapping to 200+ laws and frameworks for organizations and GRC professionals seeking multi-framework compliance and certification.
- Company typePrivate
- Founded2018
- HeadquartersSheridan, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Secure Controls Framework does
Secure Controls Framework (SCF) is a private, Wyoming-incorporated limited liability company (Secure Controls Framework Council, LLC) that publishes and maintains a comprehensive cybersecurity and data privacy metaframework. The core product is a control catalog of 1,400+ controls organized across 33 logically structured domains, with crosswalk mappings to more than 200 laws, regulations, and frameworks (including NIST CSF 2.0, NIST 800-171, ISO 27001, HIPAA, GDPR, CMMC, PCI DSS, and SOC 2). The framework uses NIST IR 8477 Set Theory Relationship Mapping (STRM) for defensible, auditable crosswalks, and is distributed free of charge under Creative Commons licensing in CSV/Excel and NIST OSCAL JSON formats via direct download.
The technical and content foundation is supported by a volunteer community of cybersecurity and GRC professionals (CISOs, security architects, engineers, auditors, privacy experts) who contribute to a quarterly release cadence, with NIST OLIR-validated mappings for NIST CSF and NIST SP 800-171. The business model is freemium at the core, with revenue generated from four narrow streams: voluntary donations via Stripe, organization-level SCF CAP conformity assessments conducted by Cyber-AB-accredited 3PAOs, individual-level professional certifications (Practitioner, Architect, Assessor) delivered through SAICO, and licensing arrangements with Licensed Content Providers and Licensed Training Providers. No paid customer logos are disclosed, no headcount is published, and the LLC appears operationally lean with a single registered address in Sheridan, Wyoming.
Customer segments span organizations requiring multi-framework compliance, GRC professionals seeking certification, and a partner ecosystem of assessment organizations, advisory firms, technology integrators, and training providers. Strategic positioning emphasizes open standards, no vendor lock-in, and government-recognized methodology — competing against paid metaframeworks such as HITRUST CSF and Unified Compliance. The Cyber AB partnership formalized in December 2024 anchors the certification program, while SCF Connect (SSOT) and the marketplace ecosystem represent nascent commercialization of platform tooling around the free content base.
Secure Controls Framework firmographics
Firmographics- Name
- Secure Controls Framework
- Legal name
- Secure Controls Framework Council, LLC
- Website
- https://securecontrolsframework.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Secure Controls Framework Council, LLC publishes a free, volunteer-maintained cybersecurity and data privacy metaframework of 1,400+ controls across 33 domains, mapping to 200+ laws and frameworks for organizations and GRC professionals seeking multi-framework compliance and certification.
- Ownership category
- akta.pro rank
Secure Controls Framework industry classification
Industry- Product category
- Cybersecurity Compliance Software
- NAICS
- Computer Systems Design and Related Services (54151)
- akta.pro primary industry
- Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF)
Keywords
Where Secure Controls Framework is headquartered
LocationHeadquarters
- HQ city
- Sheridan
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Secure Controls Framework business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Free Framework Distribution: The SCF core framework is provided completely free of charge under Creative Commons licensing. No revenue is generated from the framework itself. The organization operates on volunteer contributions and accepts donations to support operations.
- SCF Certified Programs: Revenue-generating conformity assessment and certification programs through the SCF CAP ecosystem. Third-Party Assessment Organizations (3PAOs) conduct paid assessments; organizations seeking certification pay assessment fees.
- SCF Training & Certifications: Individual-level professional certifications (SCF Practitioner, Architect, Assessor) delivered through Computer-Based Training (CBT) via SAICO. Fees associated with certification courses and exams.
- Donations: Accepts donations through Stripe to support SCF operations and continued development.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free Core Framework - Full access to 1,400+ controls across 33 domains, all STRM mappings to 200+ LRFs, CSV/Excel and NIST OSCAL JSON formats |
| Subscription | Multi-year contract | SCF Individual Certifications - Practitioner, Architect, and Assessor certification tracks |
| Other | Multi-year contract | SCF CAP Organization Certification - Third-party conformity assessments at three rigor levels |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels5 records
Secure Controls Framework product offering
Product offeringCore offering
The Secure Controls Framework (SCF) is a free, downloadable cybersecurity and data privacy metaframework providing 1,400+ controls across 33 domains that map to 200+ laws, regulations, and frameworks (LRFs) such as HIPAA, ISO 27001, NIST CSF 2.0, NIST 800-171, SOC 2, PCI DSS, GDPR, and CMMC. It uses NIST IR 8477 Set Theory Relationship Mapping (STRM) for defensible crosswalk mappings, is delivered in CSV/Excel and NIST OSCAL JSON formats, and is updated quarterly. The organization also offers paid organization-level conformity certifications through the SCF CAP program (accredited by The Cyber AB) and individual professional certifications (Practitioner, Architect, Assessor) through SAICO.
Product overview
The Secure Controls Framework (SCF) is a free, comprehensive cybersecurity and data privacy metaframework offering a unified control catalog that maps 1,400+ controls across 33 domains to 200+ laws, regulations, and frameworks. The core product is the SCF control catalog itself, downloadable as CSV/Excel or NIST OSCAL JSON formats. Supporting the core framework are complementary methodologies including the Risk Management Model (SCR-RMM), Capability Maturity Model (SCR-CMM), Cybersecurity Assessment Standards (CDPAS), Data Privacy Management Principles (DPMP), Evidence Request List (ERL), and Unified Scoping Guide (USG). The SCF CAP (Conformity Assessment Program) provides organization-level certifications validated by The Cyber AB. Individual certifications (SCF Practitioner, Architect, Assessor) offer professional credentials through SAICO. The marketplace ecosystem includes partner roles: Licensed Content Providers (LCPs), Authorized Control Integrators (ACIs), Authorized Solution Providers (ASPs), Registered Provider Organizations (RPOs), and Third-Party Assessment Organizations (3PAOs). The framework is updated quarterly with version 2026.1 currently released.
Differentiator
Problem solved
Functional benefit
Brands
- SCF CAP: SCF Conformity Assessment Program - organization-level cybersecurity conformity assessments with The Cyber AB as accreditation body.
- SAICO
- SCRMS
- SCR-RMM
- SCR-CMM
- CDPAS
- DPMP
- ERL
- USG
- STRM
Products and services
- Secure Controls Framework (SCF) Core The primary free cybersecurity and data privacy metaframework providing 1,400+ controls across 33 domains that map to 200+ laws, regulations, and frameworks, available in CSV/Excel and NIST OSCAL JSON formats. Designed for organizations of every size to implement one tailored control set that satisfies multiple compliance obligations simultaneously.
- SCF Conformity Assessment Program (SCF CAP) Organization-level conformity assessment and certification program enabling companies to obtain third-party validated SCF Certified designations against multiple frameworks (NIST CSF, HIPAA, CMMC, NY DFS, GDPR) in a single assessment. The Cyber AB serves as the Accreditation Body, and accredited 3PAOs conduct the examine-interview-test assessments producing a Report on Conformity.
- SCF Practitioner Certification Foundation-level individual certification covering the structure and application of the SCF, its 33 control domains, and how to use the framework as a practitioner implementing or managing a security program. Delivered through self-paced Computer-Based Training (CBT) with a defined syllabus and SAICO certification exam.
- SCF Architect Certification Design and implementation-level certification for cybersecurity professionals who design security programs using the SCF. Covers program architecture, control selection and rationalization, SCF implementation, and the SCRMS operational model. Delivered through self-paced CBT.
- SCF Assessor Certification
Quantifiable outcome
- Organizations can satisfy multiple cybersecurity compliance requirements (HIPAA, ISO 27001, NIST CSF, SOC 2, PCI DSS, GDPR) using a single control set instead of managing siloed programs
- +2 more outcomes
Companies that use Secure Controls Framework
Customer profileSegments4 records
Ideal customer profiles3 records
Secure Controls Framework technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
Secure Controls Framework partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core and minor.
- The Cyber ABcoreThe Cyber AB serves as the Accreditation Body (AB) for the SCF CAP conformity assessment program. They accredit and authorize Third-Party Assessment Organizations (3PAOs) to conduct SCF CAP assessments. The partnership validates SCF certifications and provides independent governance of the certification ecosystem.
- NIST (National Institute of Standards and Technology)coreSCF participates in the NIST National Online Information References (OLIR) Program with accepted mappings for NIST CSF and NIST SP 800-171. Uses NIST IR 8477 Set Theory Relationship Mapping (STRM) methodology for all crosswalk mappings. Provides government-recognized validation of the SCF's mapping quality.
- GRC Platform VendorscoreSCF is natively supported by dozens of enterprise GRC platforms. Available in standard CSV/Excel format for universal compatibility and NIST OSCAL JSON for standards-based, machine-readable integration. No proprietary lock-in or licensing fees for core framework integration.
- Third-Party Assessment Organizations (3PAOs)coreIndependent assessment organizations accredited by The Cyber AB to conduct SCF CAP conformity assessments. They perform examine, interview, and test methodology assessments and produce the Report on Conformity (ROC) authorizing certification issuance.
- SCF Licensed Training Providers (LTPs)minorOrganizations licensed to deliver SCF-branded training programs including preparation courses for individual-level SAICO certifications. Part of the SCF CAP ecosystem.
- SCF Licensed Content Providers (LCPs)minorOrganizations licensed to incorporate SCF content into their commercial products, tools, and platforms under the SCF licensing program.
Scale indicators7 records
Recent moves6 records
Expansion highlights5 records
Secure Controls Framework competitors and assessment
Company assessmentDirect peers
- HITRUST: Provides the HITRUST CSF, a competing cybersecurity and privacy metaframework that maps controls across multiple regulations. Most directly comparable to SCF as a multi-framework control catalog, though HITRUST operates on a paid assurance model rather than a free framework.
- Unified Compliance Framework (UCF): Offers a metaframework mapping hundreds of authority documents to a common control set, the closest conceptual analog to SCF's crosswalk approach. Commercial competitor in the same metaframework category.
Emerging players
- Drata: Automated compliance platform that natively integrates SCF mappings and supports frameworks like SOC 2, ISO 27001, and HIPAA. Comparable as a buyer of metaframework content and as a GTM channel for SCF, while also being a potential competitor for compliance budgets.
- Vanta: Leading automated GRC platform that supports multiple frameworks (SOC 2, ISO 27001, HIPAA, NIST) and integrates control mappings. Comparable as both a downstream consumer of metaframework content and an adjacent GRC solution that competes for the same organizational budgets.
- Secureframe: Compliance automation platform supporting frameworks including SOC 2, ISO 27001, HIPAA, and NIST. Comparable as a GRC platform that depends on metaframework content and competes for enterprise compliance spending.
- LogicGate Risk Cloud: GRC automation platform with risk and compliance modules supporting multiple frameworks. Comparable as a flexible GRC platform that competes for mid-market and enterprise compliance budgets where SCF-derived controls are also deployed.
Broad incumbents
- AuditBoard: Enterprise GRC and audit management platform that supports multiple control frameworks. Comparable as a broader GRC incumbent that includes framework crosswalking within a wider audit and risk management portfolio.
- ServiceNow GRC: Enterprise GRC suite from ServiceNow providing integrated risk, compliance, and audit management. Comparable as a broad incumbent with overlap in multi-framework compliance management and authority document mapping.
- RSA Archer: Established enterprise GRC platform supporting risk management, regulatory compliance, and audit across multiple frameworks. Comparable as a long-standing broad incumbent in the GRC technology space.
- OneTrust: Privacy, security, and GRC platform with a heavy emphasis on privacy program management. Comparable as a broad incumbent with overlapping scope in privacy controls and regulatory framework mapping.
Market position
Strengths4 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Secure Controls Framework social profiles
Digital presenceSecure Controls Framework compliance and trust
Trust signalCompliance8 records
Secure Controls Framework financial estimates
Financial estimateRevenue estimate
Valuation estimate
Secure Controls Framework leadership team
Management profileNumber of profiles
Secure Controls Framework funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Secure Controls Framework M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Secure Controls Framework
What does Secure Controls Framework do?
The Secure Controls Framework (SCF) is a free, downloadable cybersecurity and data privacy metaframework providing 1,400+ controls across 33 domains that map to 200+ laws, regulations, and frameworks (LRFs) such as HIPAA, ISO 27001, NIST CSF 2.0, NIST 800-171, SOC 2, PCI DSS, GDPR, and CMMC. It uses NIST IR 8477 Set Theory Relationship Mapping (STRM) for defensible crosswalk mappings, is delivered in CSV/Excel and NIST OSCAL JSON formats, and is updated quarterly. The organization also offers paid organization-level conformity certifications through the SCF CAP program (accredited by The Cyber AB) and individual professional certifications (Practitioner, Architect, Assessor) through SAICO.
Is Secure Controls Framework a public or private company?
Secure Controls Framework is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Secure Controls Framework founded?
Secure Controls Framework was founded in 2018. It employs 1 to 10 people.
Where is Secure Controls Framework based?
Secure Controls Framework is headquartered in Sheridan, United States, in the North America region.
How does Secure Controls Framework make money?
Four revenue lines are on record. Free Framework Distribution is the primary driver. The others are SCF Certified Programs, SCF Training & Certifications and donations.
Who are Secure Controls Framework's main competitors?
Direct peers on record are HITRUST and Unified Compliance Framework (UCF). Emerging players are Drata, Vanta, Secureframe and LogicGate Risk Cloud. Broad incumbents are AuditBoard, ServiceNow GRC, RSA Archer and OneTrust.
Does Secure Controls Framework have an API?
No public API is recorded for Secure Controls Framework.
What industry is Secure Controls Framework in?
Secure Controls Framework's product category is Cybersecurity Compliance Software. Its primary akta.pro industry code is BPAHAFAF, Privacy, Data Protection & Cyber Governance (GRC). Its NAICS code is 54151.