ChaptersEventsBlog
Join global cybersecurity leaders shaping the future of AI security! Share your insights on AI Safety in this Deloitte executive survey

SaaS Security Capability Framework (SSCF)

Released: 09/23/2025

SaaS Security Capability Framework (SSCF)
SaaS Security Capability Framework (SSCF)
The SaaS Security Capability Framework (SSCF) is a new technical framework that defines configurable, consumable, and customer-facing security controls provided by SaaS vendors to their customers. 

The SSCF represents a comprehensive approach to security management in cloud-based software solutions, designed to bridge the gap between provider security capabilities and customer-specific requirements. The SSCF was developed in collaboration with CSA’s SaaS Working Group and other leading industry experts.

The SSCF provides key benefits to a wide variety of users:
  • For TPRM teams, it serves as a baseline of security capabilities during SaaS vendor assessment, simplifying risk assessments and procurement processes.
  • For SaaS vendors, it standardizes assessment responses by serving as a consistent framework, reducing custom questionnaires and assessment overhead.
  • For SaaS security engineering teams, it provides a baseline implementation checklist, streamlining and accelerating their SaaS security program.

By establishing standardized security features that should be available across all SaaS platforms, the SSCF enables application owners to make informed decisions and maintain a consistent security posture.
 
What’s Included in this Download:
  • SSCF v1.0 Release Document: Describes the new standard, its context, scope, and control domains.
  • SSCF v1.0 List of Controls: Contains the SSCF controls aligned to CCM domains.
  • SSCF v1.0 Slide Deck: Introduces the background, problem statement, and benefits of the SSCF.

Prefer to access this resource without an account? Download it now.


Best For IconBest For:
  • Third-party risk management teams
  • SaaS vendors
  • SaaS security engineering teams

Partner Event Spotlight

Want to see your content featured here?

Contact us to learn more!

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.