NIST SSDF
The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires.
v1.1 · NIST — Secure Software Development Framework · published 2022-02-03
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
NIST SSDF is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Named and tracked only; practices not ingested as a control catalog.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Prepare the Organization (PO) · Protect the Software (PS) · Produce Well-Secured Software (PW) · Respond to Vulnerabilities (RV)
- Applies to
- technology · federal contractors · SaaS · US · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
- Pending change
- SP 800-218A, the community profile for generative AI and dual-use foundation models, extends the SSDF to AI model development. NIST published the initial public draft of SP 800-218r1 (SSDF v1.2) on 2025-12-17, per Executive Order 14306; the comment period closed 2026-01-30 with no finalization date announced.Expected: SP 800-218r1 in draft; comment period closed 2026-01-30
03Version ledger
| v1.0 | Superseded | date not published |
| v1.1 | Current edition · supersedes v1.0 | 2022-02-03 |
03aCoexisting versions
- SP 800-218r1 (SSDF v1.2, initial public draft)
Applies to: Not yet a published edition — for review and comment only; v1.1 remains the only published version
No scheduled end date — The public-comment period closed 2026-01-30; NIST has not announced a finalization date.
Source (opens in a new tab)
05Change history
06Related frameworks
- CSA CCM and CAIQv4.1
Also applies to SaaS · The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.
- CSA STARSTAR Level 1 and Level 2
Also applies to SaaS · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.
- ISO/IEC 270022022
Also applies to SaaS · The controls catalog underlying ISO/IEC 27001 Annex A — a genuinely separate, currently published standard, not a duplicate of 27001. Buyers who ask for '27001 evidence' routinely cite 27002 control numbers.
- ISO/IEC 270172026
Also applies to SaaS · Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.