Framework module · nist-ssdf-800-218
NIST SSDF
The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires.
v1.1 · NIST — Secure Software Development Framework · published 2022-02-03
Standing today
Catalog only
01Standing
Catalog only
A directory entry — authority, version ledger, verification — not a workspace you can open.
NIST SSDF is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.
Named and tracked only; practices not ingested as a control catalog.
02Registry record
checked 2026-08-06
- Registry status
- Planned · namedWe name the regime and track its authority. Nothing is modelled yet.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Prepare the Organization (PO) · Protect the Software (PS) · Produce Well-Secured Software (PW) · Respond to Vulnerabilities (RV)
- Applies to
- technology · federal contractors · SaaS · US · global
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
- Pending change
- SP 800-218A, the community profile for generative AI and dual-use foundation models, extends the SSDF to AI model development. A revision of the base SSDF (SP 800-218r1) has been circulated in draft.Expected: SP 800-218r1 in draft
03Version ledger
2 editions
| v1.0 | Superseded | date not published |
| v1.1 | Current edition · supersedes v1.0 | 2022-02-03 |