CISA SSDAF
Also known as: Secure Software Development Attestation Form, SSDAF, Secure Software Attestation
CISA Secure Software Development Attestation Form — CISA (US Department of Homeland Security)
The single form on which a software producer tells a federal buying agency, over a signature, that it follows the parts of NIST SP 800-218 that OMB memoranda M-22-18 and M-23-16 made contractual. It is where secure software development stops being advice and becomes a statement an officer of the company is answerable for.
Timeline
No changes recorded yet — we are watching, and nothing has been published.
Monitoring
Watched by 1 official source. Watching since 20 September 2026.