HomeFrameworksDefense, Supply Chain & NIST CatalogueNIST SP 800-218

Framework  Defense, Supply Chain & NIST Catalogue

NIST SP 800-218

NIST Special Publication 800-218, the Secure Software Development Framework (SSDF) version 1.1, published February 2022, is a compact set of secure development practices grouped into four areas: Prepare the Organization, Protect the Software, Produce Well-Secured Software, and Respond to Vulnerabilities.

Each practice has tasks and references to more detailed standards, and it is written to be applied to any development method. Executive Order 14028 made it the yardstick for software sold to the US government: producers attest to following its practices using the CISA Secure Software Development Attestation Form.

NIST later published SP 800-218A, an SSDF community profile for generative AI and dual-use foundation models, and has released a draft of SP 800-218 Revision 1 (verify status on the NIST SSDF project page). The SSDF has no assessor.

In writing, a producer following it needs a secure development policy, defined roles and training, a toolchain and environment security description, threat modeling and design review records, code review and testing evidence, provenance and SBOM records, and a vulnerability disclosure and response process.

AI-compiled
Share
Sponsored
NIST
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with NIST SP 800-218
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary in general. Producers of software used by US federal agencies must self-attest to the SSDF practices under OMB memoranda M-22-18 and M-23-16 via the CISA attestation form; agencies may also request artifacts. Private sector buyers increasingly cite it in supplier security requirements.

What the assessor asks to see

Secure development policy and roles; training records; toolchain inventory and security configuration; environment separation and access controls; threat models and design reviews; code review and static or dynamic testing results; third-party component inventory and SBOM; build provenance and signing records; vulnerability disclosure policy and response records; the signed attestation form.

Assessors

Who assesses NIST SP 800-218

None. Self-attestation by the software producer's senior executive; agencies may accept a third-party assessment from a FedRAMP-recognized 3PAO in place of the form. for the SSDF itself; 3PAOs used as an alternative are accredited under the FedRAMP program.

No firm has claimed a NIST SP 800-218 assessor listing yet. Claim yours →

Consultants

Who helps with NIST SP 800-218

Application security consultancies and DevSecOps tool vendors map pipelines and policies to the SSDF practices and help prepare attestation packages. Engagements are usually gap assessments and policy work of a few weeks to a few months.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a NIST SP 800-218 consultant listing yet. Claim yours →

Related reading

  1. A new test for federal contractors: attesting that your software is developed securelyExplains why the self-attestation form carries False Claims Act exposure and what evidence a signer should retain.Miller & Chevalier
  2. Secure software regulations and self-attestation required for federal contractorsCovers who has to attest, the 3PAO assessment alternative and how the requirement flows down through contracts.K&L Gates
  3. NIST 800-218 (SSDF): what you need to knowWalks the four practice groups and the specific practices the CISA attestation form asks producers to affirm.Checkmarx

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for NIST SP 800-218

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with NIST SP 800-218

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.