M-22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices
RescindedOMB · OMB memorandum · September 14, 2022
Summary
Requires agencies to use only software whose producers attest that they follow NIST's Secure Software Development Framework practices, and lets agencies ask for an SBOM and other evidence based on risk.
Replaced by
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Office of Management and Budget (OMB)
- Type
- OMB memorandum
- Number
- M-22-18
- Issued
- September 14, 2022
- Status
- Rescinded
Cancelled by its issuer.
Rescinded by M-26-05 on January 23, 2026.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.