Attestation · Last verified
Secure Software Development Attestation Form
A U.S. government-wide software attestation form: the OMB memoranda requiring its collection were rescinded by OMB M-26-05 on 23 January 2026. M-26-05 now frames it as optional: "Agencies may choose to use the government-wide secure software development resources developed under M-22-18, such as the Secure Software Development Attestation Form.".
- Class
- Attestation
- Owner
- Cybersecurity and Infrastructure Security Agency (CISA)
- Last verified
What it is
This is a self-attestation given by the software producer, not a certificate and not something an agency issues. Under the originating memorandum, OMB M-22-18 (14 September 2022), "agencies are required to obtain a self-attestation from the software producer before using the software", and "A software producer's self-attestation serves as a 'conformance statement' described by the NIST Guidance."
M-22-18 also allowed a third-party route: "A third-party assessment provided by either a certified FedRAMP Third Party Assessor Organization (3PAO) or one approved by the agency shall be acceptable in lieu of a software producer's self-attestation, including in the case of open source software or products incorporating open source software, provided the 3PAO uses the NIST Guidance as the assessment baseline." Self-attestation was the floor, not the ceiling: "Self-attestation is the minimum level required; however, agencies may make risk-based determinations that a third-party assessment is required due to the criticality of the service or product that is being acquired, as defined in M-21-30."
The common form itself entered the timeline through OMB M-23-16 (9 June 2023), which tied agency collection deadlines to "the M-22-18 attestation common form released by the Cybersecurity and Infrastructure Security Agency (CISA) (hereinafter 'common form')" being "approved by OMB under the Paperwork Reduction Act (PRA)".
The current legal position is set by OMB M-26-05 (23 January 2026): "Accordingly, OMB Memoranda M-22-18 and M-23-16, a companion policy, are hereby rescinded." The same memorandum keeps a duty in force — "Agencies shall continue to maintain a complete inventory of software and hardware and develop software and hardware assurance policies and processes that match their risk determinations and mission needs" — and repositions the form: "Agencies may choose to use the government-wide secure software development resources developed under M-22-18, such as the Secure Software Development Attestation Form." M-26-05 adds that agencies "may also choose to adopt contractual terms that require a software producer to provide a current software bill of materials (SBOM) upon request."
Who owns it
The common form was released by the Cybersecurity and Infrastructure Security Agency (CISA) and, under M-23-16, was subject to OMB approval under the Paperwork Reduction Act. The form's current publication status, version and PRA control number could not be verified as of 31 August 2026 — CISA's form pages did not answer to automated access.
Who asks for it
Voluntary. The government-wide collection requirement (OMB M-22-18 and M-23-16) was rescinded by OMB M-26-05 on 23 January 2026, which states that agencies "may choose to use" the form. Whether a specific agency requires it by contract must be confirmed with that agency's procurement authority.
Since 23 January 2026, use is an agency-by-agency choice under M-26-05 ("Agencies may choose to use" the form), and an agency may impose it through its own contractual terms — in which case the obligation is contractual, arising from that contract, not from a government-wide mandate. Confirm any specific requirement with the relevant agency's procurement authority.
Sources
- OMB M-26-05 — Adopting a Risk-based Approach to Software and Hardware Security (23 January 2026) ↗ — accessed
- OMB M-22-18 — Enhancing the Security of the Software Supply Chain through Secure Software Development Practices (14 September 2022; rescinded) ↗ — accessed
- OMB M-23-16 — Update to Memorandum M-22-18 (9 June 2023; rescinded) ↗ — accessed
- OMB — memoranda index (M-26-05 listed; M-22-18 and M-23-16 no longer listed) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.