SSDF Compliance and Attestation
Blog post from Endor Labs
On March 14, 2024, CISA issued the Secure Software Development Attestation Form to ensure software suppliers adhere to secure development practices as outlined in Executive Order 14028 and the NIST Secure Software Development Framework (SSDF), with deadlines for critical software by June 8, 2024, and all other applicable software by September 8, 2024. The form applies to newly developed software, existing software with major updates, and continuously updated SaaS, excluding federal-developed software, open-source software, and freely available software without a supplier relationship. It requires software suppliers to describe their software and provide information about the producer, with the option to submit a third-party assessment from a FedRAMP-certified organization. Suppliers can attest company-wide or for specific products, with the form emphasizing secure environments, trusted source code supply chains, code and artifact provenance, and ongoing vulnerability scanning and remediation. Endor Labs offers tools to support compliance across these dimensions, including repository security management, OSS governance, secret detection, CI/CD discovery, and artifact signing, enhancing software supply chain security and transparency.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.