NIST CSRC
csrc.nist.gov › pubs › sp › 800 › 218 › final
NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities
February 3, 2022 - Supplemental Material: SP 800-218 Table in Excel (xlsx) Delta from April 2020 paper (docx) Delta from September 2021 public draft (docx) SSDF Project homepage Executive Order 14028, Improving the Nation's Cybersecurity
NIST CSRC
csrc.nist.gov › files › pubs › sp › 800 › 218 › final › docs › nist.sp.800-218.ssdf-table.xlsx xlsx
SSDF - NIST Computer Security Resource Center
CSRC provides access to NIST's cybersecurity- and information security-related projects, publications, news and events.
Videos
16:19
Implementing NIST 800-218: Secure Software Development Framework ...
55:48
GRC | NIST 800-218 Secure Software Development Framework (SSDF) ...
08:13
Creating a Secure Software Development Life Cycle - YouTube
01:14
How to Leverage SAMM to Become NIST 800-218 Compliant - YouTube
47:28
NIST’s Secure Software Development Framework with Elzar Camper ...
Workshop: Executive Order 14028: Guidelines for Enhancing Software ...
NIST CSRC
csrc.nist.gov › projects › ssdf
Secure Software Development Framework | CSRC | CSRC
April 13, 2026 - NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities has been posted as final, along with a Microsoft Excel version of the SSDF 1.1 table. SP 800-218 includes mappings from Executive ...
Aclum
data.aclum.org › wp-content › uploads › 2025 › 01 › NIST_csrc_nist_gov_projects_ssdf.pdf pdf
PROJECTS Secure Software Development Framework SSDF
NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations · for Mitigating the Risk of Software Vulnerabilities has been posted as final, along with a Microsoft Excel version of the
NIST
nvlpubs.nist.gov › nistpubs › SpecialPublications › NIST.SP.800-218-draft.pdf pdf
NIST.SP.800-218-draft.pdf
September 30, 2021 - Natl. Inst. Stand. Technol. Spec. Publ. 800-218, 31 pages (September 2021)
NIST CSRC
csrc.nist.gov › projects
Projects | CSRC - NIST Computer Security Resource Center
A recording of the workshop can be viewed on NIST's website. NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities has been posted as final, along with a Microsoft Excel version of ...
CSRC
csrc.nist.rip › Publications › Search
Search | CSRC
Includes current (Final and Draft) SP 800 pubs. All SP Series: Current NIST Special Publications (SP), including SP 800 (Computer/Information Security) and SP 1800 (Cybersecurity Practice Guides) pubs. Also includes SP 500 (Computer Systems Technology) pubs related to cybersecurity and privacy.
Reddit
reddit.com › r/devsecops › nist sp 800-218 – what is this framework and how to utilize it
r/devsecops on Reddit: NIST SP 800-218 – What Is This Framework and How To Utilize It
August 29, 2022 - This article can help: https://scribesecurity.com/blog/nist-sp-800-218-what-is-this-framework-and-how-to-utilize-it/?utm_campaign=Reddit groups&utm_source=reddit&utm_medium=social&utm_term=Reddit Groups SSDF framework blog&utm_content=Reddit Groups SSDF framework blog Share
NIST
nvlpubs.nist.gov › nistpubs › SpecialPublications › NIST.SP.800-218A.ipd.pdf pdf
NIST SP 800-218A initial public draft, Secure Software ...
April 29, 2024 - NIST Special Publication (SP) 800-218.
CSRC
csrc.nist.rip › external › nvlpubs.nist.gov › nistpubs › SpecialPublications › NIST.SP.800-218-draft.pdf pdf
Draft NIST Special Publication 800-218 1 Secure Software Development 2
September 30, 2021 - Natl. Inst. Stand. Technol. Spec. Publ. 800-218, 31 pages (September 2021)
NIST
nvlpubs.nist.gov › nistpubs › specialpublications › nist.sp.800-218.pdf pdf
NIST Special Publication 800-218 Secure Software Development
An artifact is “a piece of evidence” [adapted from IR7692]. Evidence is “grounds for belief or disbelief; data on which to base proof or to establish truth or falsehood” [SP800160]. Artifacts provide records of secure software development practices.
NIST CSRC
csrc.nist.gov › pubs › sp › 800 › 218 › ipd
NIST Special Publication (SP) 800-218 (Withdrawn), Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities
September 30, 2021 - Few software development life cycle ... developed is well secured. Draft SP 800-218 recommends a core set of high-level secure software development practices called the SSDF that can be integrated within each SDLC implementation....
CISA
cisa.gov › resources-tools › resources › nist-sp-800-218-secure-software-development-framework-v11-recommendations-mitigating-risk-software
NIST SP 800-218, Secure Software Development Framework V1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities | CISA
NIST SP 800-218, Secure Software ... Technology Supply Chain Security · This document describes a set of fundamental, sound practices for secure software development called the Secure Software Development Framework (SSDF)....
NIST
nvlpubs.nist.gov › nistpubs › SpecialPublications › NIST.SP.800-218A.pdf pdf
NIST Special Publication 800 NIST SP 800-218A
Additional information about this publication is available at https://csrc.nist.gov/pubs/sp/800/218/a/final,
Reddit
reddit.com › r/nistcontrols › mapping of nist csf 2.0 to iso27001:2022 controls (excel)
r/NISTControls on Reddit: Mapping of NIST CSF 2.0 to ISO27001:2022 controls (Excel)
March 21, 2024 -
Hi guys, anyone has the mapping of this?
Top answer 1 of 4
2
Iirc if you look at the PDF for 2.0 and scroll towards the bottom there is a cross map of controls to ISO 27001. Can’t remember if it is 2022 though or not.
2 of 4
1
For whatever reason they didn't map 2.0 to ISO/IEC 27001. It looks like they only mapped to SP 800-221A, SP 800-218, CSF 1.1, and CIS CSC. They didn't even map to SP 800-53 . Weird. You can wait for mappings to start popping up or you can leverage the Secure Controls Framework for an indirect route. They have mapping for the public draft from August but it looks like we'll have to wait for the newest update for the final published 2.0 mapping. If you give it a bit Aron Lange typically maps ISO back to NIST, so you could reverse engineer it that way as well.
NIST CSRC
csrc.nist.gov › pubs › sp › 800 › 218 › r1 › ipd
NIST Special Publication (SP) 800-218 Rev. 1 (Draft), Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities
December 17, 2025 - Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model. SP 800-218 recommends the Secure Software Development Framework (SSDF), which is a core set of high-level secure ...
NIST CSRC
csrc.nist.gov › News › 2026 › nist-releases-sp-800-18r2
NIST Releases SP 800-18r2 | CSRC
3 weeks ago - NIST has released Special Publication (SP) 800-18r2 (Revision 2), Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems. This revision broadens the scope of system planning to encompass three interconnected plan types that are collectively referred to ...