M-26-05, Adopting a Risk-based Approach to Software and Hardware Security
In effectOMB · OMB memorandum · January 23, 2026
Summary
Rescinds the software attestation requirements of M-22-18 and M-23-16 and requires agencies to set their own risk-based software and hardware security policies, with attestation forms and SBOMs as optional tools.
Replaces
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Office of Management and Budget (OMB)
- Type
- OMB memorandum
- Number
- M-26-05
- Issued
- January 23, 2026
- Status
- In effect
Still in force, possibly with amendments.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.