Download Publication
Who it's for:
- Third-party risk management teams
- SaaS vendors
- SaaS security engineering teams
SaaS Security Capability Framework (SSCF)
Release Date: 09/23/2025
- For TPRM teams, it serves as a baseline of security capabilities during SaaS vendor assessment, simplifying risk assessments and procurement processes.
- For SaaS vendors, it standardizes assessment responses by serving as a consistent framework, reducing custom questionnaires and assessment overhead.
- For SaaS security engineering teams, it provides a baseline implementation checklist, streamlining and accelerating their SaaS security program.
- SSCF v1.0 Release Document: Describes the new standard, its context, scope, and control domains.
- SSCF v1.0 List of Controls: Contains the SSCF controls aligned to CCM domains.
- SSCF v1.0 Slide Deck: Introduces the background, problem statement, and benefits of the SSCF.
Download this Resource
Prefer to access this resource without
an account?
Download the publication. Download the presentation.
Related Resources
Acknowledgements

Michael Roza
Risk, Audit, Control and Compliance Professional at EVC
Michael Roza is a seasoned risk, audit, control and compliance, and cybersecurity professional with over 20 years of experience across multinational enterprises and startups. As a Cloud Security Alliance (CSA) Research member for over 10 years, he has led and contributed to more than 140 CSA projects spanning Zero Trust, AI, IoT, Top Threats, DecSecOps, Cloud Key Management, Cloud Control Matrix, and many others.
He has co-chaired...

Boris Sieklik
MongoDB
.png)
Joseph Longo
GitLab

Idan Fast
Co-Founder and CTO, Grip Security

Uli Petersen
Senior Key Expert, Siemens AG
Interested in helping develop research with CSA?
Related Certificates & Training
.png)
Learn more


.jpeg)
.jpeg)
.jpeg)
%20v1.0%20Control%20Framework%20-%20Latest%20News.png)