GRCCopilot
Sign In
National Institute of Standards and Technology (NIST)

NIST Secure Software Development Framework (SSDF)

NIST's authoritative software supply chain security framework — required for U.S. federal software procurement under OMB M-23-16

Start Assessment Create Free Account
15
Controls
45
Questions
Active
Status
May 2031
Expires

About this Framework

The NIST Secure Software Development Framework (SSDF — SP 800-218) is a set of fundamental practices for secure software development that U.S. federal agencies and their software suppliers are required to implement under OMB M-23-16 (CISA software producer attestation). The SSDF organises practices into four groups: Prepare the Organisation (PO), Protect Software (PS), Produce Well-Secured Software (PW) and Respond to Vulnerabilities (RV). It directly addresses software supply chain security requirements from Executive Order 14028 and underpins federal software security attestation requirements.

Key Control Domains

Prepare the Organisation (PO)
Protect Software (PS)
Produce Well-Secured Software (PW)
Respond to Vulnerabilities (RV)

Who Needs This?

  • U.S. federal agencies and their software product suppliers
  • Software companies selling commercial products to the U.S. government
  • DevSecOps and software engineering organisations
  • Supply chain security programme managers and CISOs
  • Organisations implementing Executive Order 14028 software security requirements

Compliance Benefits

  • Required for CISA software attestation — prerequisite for U.S. federal software sales
  • Comprehensive framework addressing software supply chain security risks
  • Aligns with NIST CSF, SP 800-53 and EO 14028 requirements
  • Provides the foundation for software producer self-attestation to government buyers

Official Reference

NIST SP 800-218 (SSDF) Publication
https://csrc.nist.gov/publications/detail/sp/800-218/final

Assessment Details

Issuer / AuthorityNational Institute of Standards and Technology (NIST)
FrameworkNIST Secure Software Development Framework (SSDF)
Controls15
Questions45
StatusActive
Assessment Start25 May 2026
Assessment Expires25 May 2031

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/nist-secure-software-development-framework-ssdf

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.