Skip to content

M-26-05, Adopting a Risk-based Approach to Software and Hardware Security

In effectOMB · OMB memorandum · January 23, 2026

Summary

Rescinds the software attestation requirements of M-22-18 and M-23-16 and requires agencies to set their own risk-based software and hardware security policies, with attestation forms and SBOMs as optional tools.

Read it on www.whitehouse.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Office of Management and Budget (OMB)
Type
OMB memorandum
Number
M-26-05
Issued
January 23, 2026
Status
In effect

Still in force, possibly with amendments.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.