Skip to content

Secure Software Development Attestation Form

In effectCISA · CISA guidance · March 11, 2024

Summary

Standard form, issued with OMB, in which software producers attest that they follow secure development practices drawn from NIST guidance; OMB memos M-22-18 and M-23-16 required agencies to collect it before using covered software.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
CISA guidance
Issued
March 11, 2024
Status
In effect

Still in force, possibly with amendments.

OMB M-26-05 rescinded the memos requiring agencies to collect this form on January 23, 2026; agencies may still choose to use it.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.