Skip to main content
—
Framework library
Framework module · nist-ssdf-800-218

NIST SSDF

The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires.

v1.1 · NIST — Secure Software Development Framework · published 2022-02-03

Standing today
Directory entry

00Answer

from the registry record
What is NIST SSDF?
The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires.
Who does NIST SSDF apply to?
NIST SSDF applies to technology, federal contractors, SaaS, US, global, per NIST — Secure Software Development Framework.
What is the current version of NIST SSDF?
The current edition is v1.1, issued by NIST — Secure Software Development Framework and published 2022-02-03. Source: https://csrc.nist.gov/projects/ssdf.
What does an assessment under NIST SSDF require?
No control catalog has been ingested for NIST SSDF yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

NIST SSDF is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Named and tracked only; practices not ingested as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Prepare the Organization (PO) · Protect the Software (PS) · Produce Well-Secured Software (PW) · Respond to Vulnerabilities (RV)
Applies to
technology · federal contractors · SaaS · US · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06
Pending change
SP 800-218A, the community profile for generative AI and dual-use foundation models, extends the SSDF to AI model development. NIST published the initial public draft of SP 800-218r1 (SSDF v1.2) on 2025-12-17, per Executive Order 14306; the comment period closed 2026-01-30 with no finalization date announced.Expected: SP 800-218r1 in draft; comment period closed 2026-01-30

03Version ledger

2 editions
v1.0Supersededdate not published
v1.1Current edition · supersedes v1.02022-02-03

03aCoexisting versions

1 other version in force
  1. SP 800-218r1 (SSDF v1.2, initial public draft)

    Applies to: Not yet a published edition — for review and comment only; v1.1 remains the only published version

    No scheduled end date — The public-comment period closed 2026-01-30; NIST has not announced a finalization date.

    Source (opens in a new tab)

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to SaaS · The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.

  2. CSA STARSTAR Level 1 and Level 2

    Also applies to SaaS · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.

  3. Also applies to SaaS · The controls catalog underlying ISO/IEC 27001 Annex A — a genuinely separate, currently published standard, not a duplicate of 27001. Buyers who ask for '27001 evidence' routinely cite 27002 control numbers.

  4. Also applies to SaaS · Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.

NIST SSDF | ControlFrame