Cisco recently made public its Cloud Controls Framework (CCF), which aggregates a set of comprehensive international and national security compliance and certification requirements. The vendor claims it allows organizations to achieve cloud security certifications more efficiently.

“Customer demand for global SaaS security certifications is ever-increasing, as are the security risks we face,” Prasant Vadlamudi, senior director for global cloud compliance at Cisco, noted in a blog post.

“We are sharing the Cisco CCF with the broader security and risk management community as a guide to help you achieve your market access goals, keep pace with evolving customer demand, and continue to maintain a more secure cloud infrastructure,” he added.

He also explained that the framework is the center of Cisco’s security compliance strategy. It enables users to define, implement, and demonstrate controls for security and privacy certifications across their software-as-a-service (SaaS) portfolio, such as SOC 2, ISO 27001: 2013, FedRAMP, Germany’s BSI C5, Japan’s ISMAP, and the EU Cloud Code of Conduct.

“It provides a structured, ‘build-once-use-many’ approach for achieving multiple regional and international certifications, enabling market access and scalability, as well as easing compliance strain,” Vadlamudi touted.

Several security practitioners applauded Cisco’s willingness to share this framework. “With frameworks like this, it enables us to normalize expectations on what evidence helps us meet various compliance requirements across the world,” said JupiterOne CISO Sounil Yu.

“I have no doubt that the release of Cisco CCF to the public would benefit organizations leveraging Cisco cloud services,” John Yun, VP of product strategy at ColorTokens, said in a statement. “However, such a move has a larger ramification across the industry where cloud service providers, as well as security vendors, are not simply focused on their offerings but willing to collaborate to assist enterprises tackle the difficult challenge of cloud compliance.”

As regulations evolve and new frameworks are integrated into its compliance processes, Cisco pledged to regularly update the Cloud Controls Framework.