CISA SSDAF

Also known as: Secure Software Development Attestation Form, SSDAF, Secure Software Attestation

CISA Secure Software Development Attestation Form — CISA (US Department of Homeland Security)

The single form on which a software producer tells a federal buying agency, over a signature, that it follows the parts of NIST SP 800-218 that OMB memoranda M-22-18 and M-23-16 made contractual. It is where secure software development stops being advice and becomes a statement an officer of the company is answerable for.

Subscribe to CISA SSDAF (RSS)

Timeline

No changes recorded yet — we are watching, and nothing has been published.

Monitoring

Watched by 1 official source. Watching since 20 September 2026.