Framework library
Framework module · nist-ssdf-800-218

NIST SSDF

The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires.

v1.1 · NIST — Secure Software Development Framework · published 2022-02-03

Standing today
Catalog only

01Standing

Catalog only

A directory entry — authority, version ledger, verification — not a workspace you can open.

NIST SSDF is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.

Named and tracked only; practices not ingested as a control catalog.

02Registry record

checked 2026-08-06
Registry status
Planned · namedWe name the regime and track its authority. Nothing is modelled yet.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Prepare the Organization (PO) · Protect the Software (PS) · Produce Well-Secured Software (PW) · Respond to Vulnerabilities (RV)
Applies to
technology · federal contractors · SaaS · US · global
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
Pending change
SP 800-218A, the community profile for generative AI and dual-use foundation models, extends the SSDF to AI model development. A revision of the base SSDF (SP 800-218r1) has been circulated in draft.Expected: SP 800-218r1 in draft

03Version ledger

2 editions
v1.0Supersededdate not published
v1.1Current edition · supersedes v1.02022-02-03
NIST SSDF — framework module | ControlFrame