Framework Defense, Supply Chain & NIST Catalogue
NIST SP 800-218
NIST Special Publication 800-218, the Secure Software Development Framework (SSDF) version 1.1, published February 2022, is a compact set of secure development practices grouped into four areas: Prepare the Organization, Protect the Software, Produce Well-Secured Software, and Respond to Vulnerabilities.
Each practice has tasks and references to more detailed standards, and it is written to be applied to any development method. Executive Order 14028 made it the yardstick for software sold to the US government: producers attest to following its practices using the CISA Secure Software Development Attestation Form.
NIST later published SP 800-218A, an SSDF community profile for generative AI and dual-use foundation models, and has released a draft of SP 800-218 Revision 1 (verify status on the NIST SSDF project page). The SSDF has no assessor.
In writing, a producer following it needs a secure development policy, defined roles and training, a toolchain and environment security description, threat modeling and design review records, code review and testing evidence, provenance and SBOM records, and a vulnerability disclosure and response process.
help
Who has to comply
Voluntary in general. Producers of software used by US federal agencies must self-attest to the SSDF practices under OMB memoranda M-22-18 and M-23-16 via the CISA attestation form; agencies may also request artifacts. Private sector buyers increasingly cite it in supplier security requirements.
What the assessor asks to see
Secure development policy and roles; training records; toolchain inventory and security configuration; environment separation and access controls; threat models and design reviews; code review and static or dynamic testing results; third-party component inventory and SBOM; build provenance and signing records; vulnerability disclosure policy and response records; the signed attestation form.
Assessors
Who assesses NIST SP 800-218
None. Self-attestation by the software producer's senior executive; agencies may accept a third-party assessment from a FedRAMP-recognized 3PAO in place of the form. for the SSDF itself; 3PAOs used as an alternative are accredited under the FedRAMP program.
No firm has claimed a NIST SP 800-218 assessor listing yet. Claim yours →
Consultants
Who helps with NIST SP 800-218
Application security consultancies and DevSecOps tool vendors map pipelines and policies to the SSDF practices and help prepare attestation packages. Engagements are usually gap assessments and policy work of a few weeks to a few months.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a NIST SP 800-218 consultant listing yet. Claim yours →
Software
Tools for NIST SP 800-218
Tools that name this framework in their own material.
Related reading
- A new test for federal contractors: attesting that your software is developed securelyExplains why the self-attestation form carries False Claims Act exposure and what evidence a signer should retain.Miller & Chevalier
- Secure software regulations and self-attestation required for federal contractorsCovers who has to attest, the 3PAO assessment alternative and how the requirement flows down through contracts.K&L Gates
- NIST 800-218 (SSDF): what you need to knowWalks the four practice groups and the specific practices the CISA attestation form asks producers to affirm.Checkmarx
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for NIST SP 800-218
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with NIST SP 800-218
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.