The SCF is the exclusive, trademarked Common Controls Framework™ (CCF™) — a Living Control Set with 33 domains, 1,400+ controls, and mappings to 200+ laws, regulations & frameworks. CDPAS is the assessment methodology built on the CCF™ to produce defensible, evidence-based results. Free. Always.
CDPAS integrates directly with the SCF Evidence Request List (ERL), Unified Scoping Guide (USG), and SCR-CMM maturity scoring — the complete SCF assessment ecosystem in one coordinated framework.
Most organizations run separate assessments for cybersecurity and data privacy — different methodologies, different evidence packages, different auditors, different timelines. CDPAS unifies both under a single, evidence-based assessment standard built on the SCF CCF™.
CDPAS defines how assessments are scoped, conducted, evidenced, scored, and reported. It is the procedural layer that sits on top of the SCF control catalog and SCR-CMM maturity model — telling assessors exactly what evidence to examine, how to evaluate it, and how to communicate findings in a consistent, defensible format.
Whether the output is a self-assessment scorecard, a third-party audit report, a regulatory examination response, or a board-level security assurance package, CDPAS provides the methodology to produce it consistently.
CDPAS is developed by volunteer cybersecurity assessors, auditors, and GRC practitioners and released at no cost under Creative Commons Attribution 4.0. No license, no fee, no registration.
CDPAS defines a structured seven-phase process that applies consistently across all four assessment types — ensuring repeatable, defensible, and comparable results regardless of who conducts the assessment.
CDPAS is the procedural layer that ties the entire SCF assessment ecosystem together. Each SCF tool plays a specific role in the CDPAS process.
Defines what is in scope for the CDPAS assessment — systems, data, locations, and applicable laws. The USG output is the direct input to CDPAS-1 (Scope Definition). Without proper scoping, no assessment is reliable.
Learn About USG →Learn About USG →Defines exactly what evidence must be collected for each SCF control. CDPAS uses the ERL in phases 3 and 4 to drive evidence planning and collection — ensuring no required evidence is overlooked and every finding is supported by documented proof.
Learn About ERL →Provides the scoring standard for CDPAS Phase 5 assessments. Every control is scored on the 1–5 CMM scale. CDPAS findings always include a CMM score, making results comparable across organizations and over time.
Learn About SCR-CMM →Provides the risk context for CDPAS findings. CDPAS Phase 6 uses RMM risk scores to prioritize findings by residual risk — ensuring remediation plans address the highest-risk gaps first, not just the most numerous.
Learn About SCR-RMM →The 1,400+ control catalog is the assessment object — every control is a potential assessment point. CDPAS uses the MCR/DSR classification and proposed risk weighting from the catalog to scope and prioritize assessment activity.
Download SCF →CDPAS Type 2 (Third-Party Assessment) is the methodology used in the SCF Conformity Assessment Program (SCF-CAP). Organizations pursuing SCF-CAP certification must undergo a CDPAS Type 2 assessment by an accredited SCF assessor.
Learn About SCF-CAP →CDPAS is designed for the full spectrum of cybersecurity assessment stakeholders — from internal teams conducting self-assessments to accredited third-party assessors performing formal audits.
Use CDPAS Type 1 (self-assessment) to establish baseline maturity, identify gaps, prioritize remediation, and prepare for external audits. CDPAS provides the structured methodology that turns the SCF spreadsheet into a formal internal assessment.
Use CDPAS to structure compliance assessments across multiple regulatory frameworks simultaneously. Map regulator requirements to SCF controls once, collect evidence once, satisfy multiple auditors — eliminating redundant evidence collection across overlapping frameworks.
Use CDPAS as the standard methodology for third-party cybersecurity and privacy assessments. Delivers consistent, comparable results across clients. Accredited SCF assessors use CDPAS for SCF-CAP conformity assessments.
Use CDPAS Type 4 (vendor assessment) to standardize third-party risk evaluation. Replace ad-hoc vendor questionnaires with a structured, CMM-scored methodology that produces comparable ratings across the entire vendor portfolio.
CDPAS provides a recognized, publicly available assessment methodology that regulated entities can use to self-assess and prepare for regulatory examinations. Regulators benefit from examined organizations having a common, structured evidence package format.
CDPAS covers both cybersecurity and data protection — applying the same evidence-based assessment methodology to privacy controls (SCF PRI domain) that is applied to all other security domains, unifying the cyber/privacy assessment under one methodology.
CDPAS assessments are not one-time events — they operate within a continuous PDCA improvement cycle, with each assessment cycle informing the next remediation plan.
Download the CDPAS today! One download to obtain a cohesive, consistent set of standards to govern cybersecurity and data protection related Third Party Assessment, Attestation and Certification Services (3PAAC Services).
Licensed under Creative Commons Attribution 4.0. Volunteer-driven by the SCF Council. No registration required.