Possible improvements to the spec would be to map SCVC controls to existing control documents including: * NIST 800-53 * NIST 800-171 * CMMC * OWASP ASVS * OWASP SAMM * BSIMM