SSDF ยท secure software development
NIST SP 800-218
The Secure Software Development Framework is what federal buyers point at when they ask how your software was built. Unlike most frameworks here, the subject is your development pipeline rather than your corporate environment, so the work lands on engineering rather than on IT.
What the engagement covers
Software producers selling to the federal government. Typical timeline: 2 to 6 months depending on pipeline maturity.
- Assessment against the SSDF practice groups: prepare the organisation, protect the software, produce well secured software, respond to vulnerabilities
- Pipeline controls including source integrity, dependency management and build provenance
- Vulnerability disclosure and response process
- Evidence and artefact collection suitable for a self attestation
- Attestation support against the federal common form
Phases
Where an engagement sits at any point, in the language your assessor uses.
- Pipeline assessment against the practices
- Control and tooling implementation
- Evidence collection
- Attestation submitted
Related reading
- Placeholder: NIST SP 800-218 article
Pulled from the legacy archive until this section is migrated.
- Placeholder: NIST SP 800-218 article
Legacy URL preserved.
Common questions
Who has to attest?
Software producers whose software is used by federal agencies, under the federal secure software development attestation requirement. If an agency customer has asked you for the common form, this is what it is asking about.
Is this just an SBOM requirement?
No. A software bill of materials may be requested, but the framework is broader: how the organisation is prepared, how the software and its build process are protected, how software is produced securely, and how vulnerabilities are responded to.
Can we attest without third party assessment?
Self attestation is the norm, which makes the evidence behind it the thing that matters. Attesting without artefacts that support it is the risk, not the attestation itself.
START HERE
Do not guess how far away you are.
A scored assessment against the NIST SP 800-218 control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, but nothing obliges you to.
Start with a scope
Bring the deadline and who is asking for it. Thirty minutes.