Download Publication
%20v1.0%20Control%20Framework%20-%20Thumbnail.png)
Who it's for:
- Third-party risk management teams
- SaaS vendors
- SaaS security engineering teams
SaaS Security Capability Framework (SSCF)
Release Date: 09/23/2025
The SaaS Security Capability Framework (SSCF) is a new technical framework that defines configurable, consumable, and customer-facing security controls provided by SaaS vendors to their customers.
The SSCF represents a comprehensive approach to security management in cloud-based software solutions, designed to bridge the gap between provider security capabilities and customer-specific requirements. The SSCF was developed in collaboration with CSA’s SaaS Working Group and other leading industry experts.
The SSCF provides key benefits to a wide variety of users:
- For TPRM teams, it serves as a baseline of security capabilities during SaaS vendor assessment, simplifying risk assessments and procurement processes.
- For SaaS vendors, it standardizes assessment responses by serving as a consistent framework, reducing custom questionnaires and assessment overhead.
- For SaaS security engineering teams, it provides a baseline implementation checklist, streamlining and accelerating their SaaS security program.
By establishing standardized security features that should be available across all SaaS platforms, the SSCF enables application owners to make informed decisions and maintain a consistent security posture.
What’s Included in this Download:
- SSCF v1.0 Release Document: Describes the new standard, its context, scope, and control domains.
- SSCF v1.0 List of Controls: Contains the SSCF controls aligned to CCM domains.
- SSCF v1.0 Slide Deck: Introduces the background, problem statement, and benefits of the SSCF.
Download this Resource
Prefer to access this resource without
an account?
Download the publication. Download the presentation.
Related Resources
Are you a research volunteer? Request to have your profile displayed on the website here.
Interested in helping develop research with CSA?
Related Certificates & Training

Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more
Learn more