Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

SSDF Compliance and Attestation

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Chris Hughes
Word Count
1,107
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

On March 14, 2024, CISA issued the Secure Software Development Attestation Form to ensure software suppliers adhere to secure development practices as outlined in Executive Order 14028 and the NIST Secure Software Development Framework (SSDF), with deadlines for critical software by June 8, 2024, and all other applicable software by September 8, 2024. The form applies to newly developed software, existing software with major updates, and continuously updated SaaS, excluding federal-developed software, open-source software, and freely available software without a supplier relationship. It requires software suppliers to describe their software and provide information about the producer, with the option to submit a third-party assessment from a FedRAMP-certified organization. Suppliers can attest company-wide or for specific products, with the form emphasizing secure environments, trusted source code supply chains, code and artifact provenance, and ongoing vulnerability scanning and remediation. Endor Labs offers tools to support compliance across these dimensions, including repository security management, OSS governance, secret detection, CI/CD discovery, and artifact signing, enhancing software supply chain security and transparency.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.