.png)

Free Cybersecurity & GRC Content

Free? Yes! The resources in this section are 100% free to use. It is all released under Creative Commons licensing by the SCF Council. Download the full Common Controls Framework™ (CCF), maturity models, risk frameworks, evidence templates, and more. No registration. No paywall. No catch.

CORE FRAMEWORK

The SCF: Download the Common Controls Framework™

The primary SCF download contains the full 1,400+ control catalog with all 200+ framework mappings, maturity criteria, control weightings, risk catalog, threat catalog, and assessment guidance. Available in multiple formats including Excel (CSV) and NIST OSCAL JSON.

Full Control Catalog: 1,400+ Controls

The SCF control catalog spans all 33 cybersecurity and data privacy domains, from Governance and Asset Management through Cloud Security and Privacy. Each control includes a unique SCF identifier, control objective, capability maturity criteria at each SCR-CMM level (1–5), proposed weighting, and threat/risk catalog crosswalks.

200+ Framework Mappings via STRM

Every SCF control is mapped to all applicable laws, regulations, and frameworks using the NIST IR 8477 Set Theory Relationship Mapping (STRM) methodology. Mappings include NIST SP 800-53, NIST CSF 2.0, ISO 27001/2, CIS Controls v8, HIPAA, PCI DSS v4, SOC 2, CMMC 2.0, GDPR, CCPA/CPRA, DORA, NIS2, FedRAMP, and 185+ more.

NIST OSCAL JSON Export

The SCF’s NIST OSCAL JSON export enables machine-readable exchange of control catalogs and profiles. It supports native import into FedRAMP automation pipelines, automated compliance workflows, interoperability with OSCAL-compatible GRC tools, and machine-readable crosswalk data for automated gap analysis.

SCR Models: Free Maturity & Risk Frameworks

The Secure, Compliant & Resilient (SCF) resources give the SCF depth beyond basic controls. The maturity models and risk management frameworks integrate directly with the SCF control catalog.

SCR Capability Maturity Model (SCR-CMM)

The SCR-CMM defines six (6) maturity levels for every SCF control, from "Ad Hoc" (Level 1) through "Optimized" (Level 5). It gives organizations a precise benchmark for where their controls stand and what "right" looks like at each stage of program maturity.

  • Level 0: Not Performed
  • Level 1: Performed Informally
  • Level 2: Planned & Tracked
  • Level 3: Well-Defined
  • Level 4: Quantitatively Controlled
  • Level 5: Continuously Improving

SCR Risk Management Model (SCR-RMM)

The SCR-RMM describes how policies, standards, procedures, metrics, threats, and risks all connect through SCF controls as the central nexus. It is a structured risk management model that integrates directly with the SCF control catalog for risk-informed decision making.

Free Assessment Tools & Templates

Beyond the core control catalog, the SCF Council publishes specialized tools that support every phase of a cybersecurity program. All are free under Creative Commons licensing.

Cybersecurity & Data Privacy Assessment Standards (CDPAS)

The CDPAS provides standardized assessment criteria for evaluating cybersecurity and data privacy programs against the SCF control catalog. Used by internal audit teams and third-party assessors to produce consistent, repeatable assessment results.

Evidence Request List (ERL)

The ERL is a pre-built, comprehensive list of audit evidence items mapped to every SCF control. It tells auditors, assessors, and compliance teams exactly what documentation, configurations, and artifacts are needed to demonstrate control effectiveness.

Unified Scoping Guide (USG)

The USG provides structured guidance for defining assessment scope, which is the critical first step in any audit or compliance assessment. Proper scoping determines which systems, data flows, and processes are in-scope for each applicable law or framework.

Specialized GRC Tools & Guidance

Domain-specific tools for organizations with unique compliance challenges, including M&A transactions, data privacy programs, and more.

Mergers, Acquisitions & Divestitures (MA&D)

The SCF MA&D toolkit provides specialized cybersecurity due diligence guidance for M&A transactions.

Data Privacy Management Principles (DPMP)

The DPMP provides structured guidance for building and operating a data privacy management program aligned with the SCF’s Privacy (PRI) domain.

Creative Commons Licensed. Free. Always.

We are committed to keeping the SCF a free resource for organizations to use. Therefore, we are using the Creative Commons Attribution-NoDerivatives 4.0 International Public License to help maintain the integrity of the SCF.

The SCF Is A Living Control Set (LCS)

Unlike static frameworks that fall behind as laws change, the SCF is continuously updated. It is a true Living Control Set that evolves with the regulatory landscape.

Updated with Every New Law & Regulation

When a new law is enacted, such as DORA, NIS2, state privacy laws, or sector-specific rules, the SCF is updated to map the new requirements to existing controls. Your organization's compliance coverage updates without rework.

Updated with Framework Revisions

When NIST releases CSF 2.0, ISO updates 27001, or CIS publishes new Controls, the SCF mappings are updated to reflect the new version. Never maintain separate crosswalk spreadsheets again.

Updated with Emerging Threats

New attack techniques, vulnerabilities, and threat patterns drive new control requirements. The SCF LCS incorporates these changes as expert volunteers identify gaps, ensuring controls stay relevant against real-world threats.

Put The SCF To Work

Downloaded the SCF? Here's what to do next, from implementation guidance to certification pathways.

Start Here: What Is The SCF?

New to the SCF? Start with the overview to understand what the Common Controls Framework™ is, why it exists, and how to use it effectively.