🌐
NIST CSRC
csrc.nist.gov › pubs › sp › 800 › 218 › final
NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities
February 3, 2022 - Supplemental Material: SP 800-218 Table in Excel (xlsx) Delta from April 2020 paper (docx) Delta from September 2021 public draft (docx) SSDF Project homepage Executive Order 14028, Improving the Nation's Cybersecurity
🌐
NIST CSRC
csrc.nist.gov › files › pubs › sp › 800 › 218 › final › docs › nist.sp.800-218.ssdf-table.xlsx xlsx
SSDF - NIST Computer Security Resource Center
CSRC provides access to NIST's cybersecurity- and information security-related projects, publications, news and events.
🌐
NIST CSRC
csrc.nist.gov › projects › ssdf
Secure Software Development Framework | CSRC | CSRC
April 13, 2026 - NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities has been posted as final, along with a Microsoft Excel version of the SSDF 1.1 table. SP 800-218 includes mappings from Executive ...
🌐
Securecontrolsframework
securecontrolsframework.com › strm-bundle
SCF Set Theory Relationship Mapping (STRM) Excel
October 10, 2024 - SCF Set Theory Relationship Mapping (STRM) - Excel download using NIST IR 8477 guidance for crosswalk mapping.
🌐
Scribd
scribd.com › document › 600368792 › NIST-SP-800-218-SSDF-table
NIST SP 800-218 SSDF-table | PDF | Vulnerability (Computing) | Security
NIST.SP.800-218.SSDF-table - Free download as Excel Spreadsheet (.xls / .xlsx), PDF File (.pdf), Text File (.txt) or read online for free. This document outlines practices and tasks for defining security requirements for software development.
🌐
Aclum
data.aclum.org › wp-content › uploads › 2025 › 01 › NIST_csrc_nist_gov_projects_ssdf.pdf pdf
PROJECTS Secure Software Development Framework SSDF    
NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations · for Mitigating the Risk of Software Vulnerabilities has been posted as final, along with a Microsoft Excel version of the
🌐
NIST
nvlpubs.nist.gov › nistpubs › SpecialPublications › NIST.SP.800-218-draft.pdf pdf
NIST.SP.800-218-draft.pdf
September 30, 2021 - Natl. Inst. Stand. Technol. Spec. Publ. 800-218, 31 pages (September 2021)
🌐
NIST CSRC
csrc.nist.gov › projects
Projects | CSRC - NIST Computer Security Resource Center
A recording of the workshop can be viewed on NIST's website. NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities has been posted as final, along with a Microsoft Excel version of ...
Find elsewhere
🌐
CSRC
csrc.nist.rip › Publications › Search
Search | CSRC
Includes current (Final and Draft) SP 800 pubs. All SP Series: Current NIST Special Publications (SP), including SP 800 (Computer/Information Security) and SP 1800 (Cybersecurity Practice Guides) pubs. Also includes SP 500 (Computer Systems Technology) pubs related to cybersecurity and privacy.
🌐
Reddit
reddit.com › r/devsecops › nist sp 800-218 – what is this framework and how to utilize it
r/devsecops on Reddit: NIST SP 800-218 – What Is This Framework and How To Utilize It
August 29, 2022 - This article can help: https://scribesecurity.com/blog/nist-sp-800-218-what-is-this-framework-and-how-to-utilize-it/?utm_campaign=Reddit groups&utm_source=reddit&utm_medium=social&utm_term=Reddit Groups SSDF framework blog&utm_content=Reddit Groups SSDF framework blog Share
🌐
NIST
nvlpubs.nist.gov › nistpubs › specialpublications › nist.sp.800-218.pdf pdf
NIST Special Publication 800-218 Secure Software Development
An artifact is “a piece of evidence” [adapted from IR7692]. Evidence is “grounds for belief or disbelief; data on which to base proof or to establish truth or falsehood” [SP800160]. Artifacts provide records of secure software development practices.
🌐
NIST CSRC
csrc.nist.gov › pubs › sp › 800 › 218 › ipd
NIST Special Publication (SP) 800-218 (Withdrawn), Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities
September 30, 2021 - Few software development life cycle ... developed is well secured. Draft SP 800-218 recommends a core set of high-level secure software development practices called the SSDF that can be integrated within each SDLC implementation....
🌐
CISA
cisa.gov › resources-tools › resources › nist-sp-800-218-secure-software-development-framework-v11-recommendations-mitigating-risk-software
NIST SP 800-218, Secure Software Development Framework V1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities | CISA
NIST SP 800-218, Secure Software ... Technology Supply Chain Security · This document describes a set of fundamental, sound practices for secure software development called the Secure Software Development Framework (SSDF)....
🌐
NIST
nvlpubs.nist.gov › nistpubs › SpecialPublications › NIST.SP.800-218A.pdf pdf
NIST Special Publication 800 NIST SP 800-218A
Additional information about this publication is available at https://csrc.nist.gov/pubs/sp/800/218/a/final,
🌐
Sonatype
sonatype.com › resources › guides › stay-compliant-nist-sp-800-218-cisa-requirements
Stay Compliant with NIST SP 800-218 and CISA Attestation ...
Stay compliant with NIST SP 800-218 and CISA requirements. Discover how Sonatype enhances software supply chain security and can help you comply.
🌐
NIST CSRC
csrc.nist.gov › pubs › sp › 800 › 218 › r1 › ipd
NIST Special Publication (SP) 800-218 Rev. 1 (Draft), Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities
December 17, 2025 - Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model. SP 800-218 recommends the Secure Software Development Framework (SSDF), which is a core set of high-level secure ...
🌐
NIST CSRC
csrc.nist.gov › News › 2026 › nist-releases-sp-800-18r2
NIST Releases SP 800-18r2 | CSRC
3 weeks ago - NIST has released Special Publication (SP) 800-18r2 (Revision 2), Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems. This revision broadens the scope of system planning to encompass three interconnected plan types that are collectively referred to ...