ChaptersEventsBlog
Prove your skills in Illumiverse Labs’ Breach Containment CTF. Register now to stop attackers.

Download Publication

SaaS Security Capability Framework (SSCF)
SaaS Security Capability Framework (SSCF)
Who it's for:
  • Third-party risk management teams
  • SaaS vendors
  • SaaS security engineering teams

SaaS Security Capability Framework (SSCF)

Release Date: 09/23/2025

The SaaS Security Capability Framework (SSCF) is a new technical framework that defines configurable, consumable, and customer-facing security controls provided by SaaS vendors to their customers. 

The SSCF represents a comprehensive approach to security management in cloud-based software solutions, designed to bridge the gap between provider security capabilities and customer-specific requirements. The SSCF was developed in collaboration with CSA’s SaaS Working Group and other leading industry experts.

The SSCF provides key benefits to a wide variety of users:
  • For TPRM teams, it serves as a baseline of security capabilities during SaaS vendor assessment, simplifying risk assessments and procurement processes.
  • For SaaS vendors, it standardizes assessment responses by serving as a consistent framework, reducing custom questionnaires and assessment overhead.
  • For SaaS security engineering teams, it provides a baseline implementation checklist, streamlining and accelerating their SaaS security program.

By establishing standardized security features that should be available across all SaaS platforms, the SSCF enables application owners to make informed decisions and maintain a consistent security posture.
 
What’s Included in this Download:
  • SSCF v1.0 Release Document: Describes the new standard, its context, scope, and control domains.
  • SSCF v1.0 List of Controls: Contains the SSCF controls aligned to CCM domains.
  • SSCF v1.0 Slide Deck: Introduces the background, problem statement, and benefits of the SSCF.
Download this Resource

Prefer to access this resource without an account?
Download the publication. Download the presentation.

Bookmark
Share
Related resources
State of SaaS Security Report 2025
State of SaaS Security Report 2025
SaaS Governance Best Practices for Cloud Customers
SaaS Governance Best Practices for Cloud Customers
Cloud Octagon Model
Cloud Octagon Model
When OAuth Tokens Go Rogue: Lessons from the Salesloft–Drift Breach
When OAuth Tokens Go Rogue: Lessons from the Salesloft–Drift Breach
Published: 10/08/2025
Columbia University Breach Exposes 870,000 Records: The Case for Unified Cloud and SaaS Security
Columbia University Breach Exposes 870,000 Records: The Case for Un...
Published: 09/29/2025
Introducing the SaaS Security Capability Framework (SSCF) v1.0: Raising the Bar for SaaS Security
Introducing the SaaS Security Capability Framework (SSCF) v1.0: Rai...
Published: 09/24/2025
Visibility ≠ Security: The SaaS Illusion That’s Putting Enterprises at Risk
Visibility ≠ Security: The SaaS Illusion That’s Putting Enterprises...
Published: 08/12/2025
Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training