🌐
NIST CSRC
csrc.nist.gov › projects › ssdf
Secure Software Development Framework | CSRC | CSRC
April 13, 2026 - SSDF Practices | SSDF Use | New ... Framework (SSDF) is a set of fundamental, sound, and secure software development practices based on established secure software development practice documents from organizations such as BSA, OWASP, and SAFECode....
Glossary
This is a potential security issue, you are being redirected to https://csrc.nist.gov · An official website of the United States government
Publications Expand or Collapse
The NIST Cybersecurity and Privacy Program develops and maintains an extensive collection of standards, guidelines, recommendations, and research on the security and privacy of information and information systems.
Special Publications (SPs)
This is a potential security issue, you are being redirected to https://csrc.nist.gov · An official website of the United States government
FIPS (standards)
This is a potential security issue, you are being redirected to https://csrc.nist.gov · An official website of the United States government
🌐
CISA
cisa.gov › resources-tools › resources › nist-sp-800-218-secure-software-development-framework-v11-recommendations-mitigating-risk-software
NIST SP 800-218, Secure Software Development Framework V1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities | CISA
This document recommends the Secure Software Development Framework (SSDF) – a core set of high-level secure software development practices that can be integrated into each SDLC implementation.
🌐
NIST CSRC
csrc.nist.gov › pubs › sp › 800 › 218 › r1 › ipd
NIST Special Publication (SP) 800-218 Rev. 1 (Draft), Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities
December 17, 2025 - Few software development life cycle ... the Secure Software Development Framework (SSDF), which is a core set of high-level secure software development practices that can be integrated into each SDLC implementation....
🌐
NIST
nist.gov › news-events › news › 2025 › 12 › secure-software-development-framework-ssdf-version-12-available-public
Secure Software Development Framework (SSDF) Version 1.2 is Available for Public Comment | NIST
December 18, 2025 - NIST has released the initial public draft of Special Publication (SP) 800-218r1 (Revision 1), Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities, per Executive Order 14306.
🌐
Black Duck
blackduck.com › blog › nist-ssdf-secure-software-development.html
Implementing NIST SSDF: Best Practices for Secure Software Development
August 12, 2025 - The National Institute of Standards and Technology (NIST) Special Publication (SP) 800-218, also known as the Secure Software Development Framework (SSDF) is a critical guide for contemporary secure software development.
🌐
NIST CSRC
csrc.nist.gov › pubs › sp › 800 › 218 › final
NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities
February 3, 2022 - Few software development life cycle ... the Secure Software Development Framework (SSDF) – a core set of high-level secure software development practices that can be integrated into each SDLC implementation....
🌐
Anchore
anchore.com › blog › about-new-nist-ssdf
An Introduction to NIST's Secure Software Development Framework | Anchore
The Secure Software Development Framework (SSDF) is NIST’s guidance for reducing risk in the software lifecycle, from initial design through development, release, and post-release maintenance.
🌐
Wiz
wiz.io › academy › application-security › secure-software-development-framework-ssdf
The Secure Software Development Framework (SSDF) | Wiz
March 20, 2026 - NIST’s Secure Software Development Framework (SSDF) is a structured approach that provides guidelines and best practices for integrating security throughout the software development life cycle (SDLC).
Find elsewhere
🌐
Confluent
confluent.io › learn › nist-ssdf
NIST SSDF (Secure Software Development Framework): A Comprehensive Guide
The National Institute of Standards and Technology's Secure Software Development Framework NIST SSDF is a set of guidelines that are intended to assist organizations in developing their software securely.
🌐
Security Scientist
securityscientist.net › blog › the-complete-guide-for-the-nist-secure-software-development-framework-ssdf
NIST SSDF (SP 800-218): Complete Implementation Guide
December 14, 2023 - The NIST Secure Software Development Framework (SSDF) provides a set of guidelines and best practices for developing secure software. By following the SSDF, organizations can ensure that their software is tamper-proof and resistant to unauthorized ...
🌐
Securebydesignhandbook
securebydesignhandbook.com › united states › nist sp 800-218 (ssdf)
NIST SP 800-218 (SSDF) | Secure-by-Design Handbook
The Secure Software Development Framework (SSDF), detailed in NIST Special Publication 800-218, is a set of fundamental, high-level practices for building secure software.
🌐
Codific
codific.com › home › security › what is nist ssdf and how should you implement it?
What is NIST SSDF and how should you implement it? - Codific
March 9, 2026 - NIST SSDF provides a structured approach to secure software development, reducing vulnerabilities and enhancing resilience. Compliance with NIST SSDF is mandatory for U.S. federal agencies under OMB Memorandum M-22-18.
🌐
Nistcybersecurityprofessional
nistcybersecurityprofessional.website › home › ncsp framework › nist sp 800-218 › ncsp 800-218 foundation certificate
NIST 800‑218 SSDF Training | Secure Software Development Framework
This 2-day, instructor led, NIST Cybersecuirty Professional® (NCSP®) 800-218 Foundation course introduces the NIST Secure Software Development Framework (SSDF), teaching participants how to integrate secure‑by‑design and secure‑by‑default practices into software development and DevSecOps pipelines.
🌐
Nistcybersecurityprofessional
nistcybersecurityprofessional.website › home › ncsp framework › nist sp 800-218 › ncsp 800-218 awareness certificate
NIST 800‑218 Awareness Training | NIST Secure Software Development Framework (SSDF)
NIST Special Publication 800‑218, Secure Software Development Framework (SSDF), provides a set of fundamental, outcome‑based practices for building secure software and reducing vulnerabilities throughout the software development lifecycle.
🌐
NIST CSRC
csrc.nist.gov › News › 2022 › nist-publishes-sp-800-218-ssdf-v11
NIST Updates the Secure Software Development Framework (SSDF) | CSRC
February 4, 2022 - NIST has released Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities.
🌐
JFrog
jfrog.com › home › ssdf
What is the Secure Software Development Framework (SSDF)?
June 29, 2025 - Released as SP 800-218, it consolidates proven security practices from frameworks like BSIMM and OWASP SAMM into a flexible, tool-agnostic guide for embedding security into software development.
🌐
Checkmarx
checkmarx.com › blog › what-you-need-to-know-about-nist-800-218-the-secure-software-development-framework
What You Need To Know About NIST 800-218
February 3, 2026 - From a NIST standard point of view, this is current and applies to modern software development life cycle (SDLC). It is also important to note that some in the government describe the SSDF as a best business practice. This document recommends the Secure Software Development Framework (SSDF) – a core set of high-level secure software development practices that can be integrated into each SDLC implementation.[i]
🌐
NIST
nist.gov › publications › secure-software-development-framework-ssdf-version-11-recommendations-mitigating-risk-1
Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities (Portuguese translation) | NIST
June 16, 2025 - This document recommends the Secure Software Development Framework (SSDF) – a core set of high-level secure software development practices that can be integrated into each SDLC implementation.
🌐
Aclum
data.aclum.org › storage › 2025 › 01 › NIST_csrc_nist_gov_projects_ssdf.pdf pdf
PROJECTS Secure Software Development Framework SSDF    
Recommendations for Mitigating the Risk of Software Vulnerabilities. NIST SP 800-218 replaces the NIST Cybersecurity · White Paper, Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework