SaaS Security Capability Framework (SSCF)
Released: 09/23/2025
The SaaS Security Capability Framework (SSCF) is a new technical framework that defines configurable, consumable, and customer-facing security controls provided by SaaS vendors to their customers.
The SSCF represents a comprehensive approach to security management in cloud-based software solutions, designed to bridge the gap between provider security capabilities and customer-specific requirements. The SSCF was developed in collaboration with CSA’s SaaS Working Group and other leading industry experts.
The SSCF provides key benefits to a wide variety of users:
- For TPRM teams, it serves as a baseline of security capabilities during SaaS vendor assessment, simplifying risk assessments and procurement processes.
- For SaaS vendors, it standardizes assessment responses by serving as a consistent framework, reducing custom questionnaires and assessment overhead.
- For SaaS security engineering teams, it provides a baseline implementation checklist, streamlining and accelerating their SaaS security program.
By establishing standardized security features that should be available across all SaaS platforms, the SSCF enables application owners to make informed decisions and maintain a consistent security posture.
What’s Included in this Download:
- SSCF v1.0 Release Document: Describes the new standard, its context, scope, and control domains.
- SSCF v1.0 List of Controls: Contains the SSCF controls aligned to CCM domains.
- SSCF v1.0 Slide Deck: Introduces the background, problem statement, and benefits of the SSCF.
Topics:
Prefer to access this resource without an account? Download it now.
Best For:
- Third-party risk management teams
- SaaS vendors
- SaaS security engineering teams



