Skip to main content

Evidence note

NIST Secure Software Development Framework v1.1

Government Guidance2022National Institute of Standards and Technology

What does it cover?

A risk-based set of secure software-development practices intended to be integrated into software-development lifecycles.

Key points

  1. 1SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.
  2. 2It is designed to be risk-based and adaptable to different software contexts.
  3. 3SSDF v1.1 remains the current final version while a newer revision process is underway.

Why it matters. Lornets interpretation.

Secure development is a lifecycle capability rather than a final-stage scanner activity. Evidence can come from design, development, build, dependency and change-control practices.

This is the Lornets reading of the source, not a finding of the source itself.

What it does not establish

  1. 1SSDF use does not certify a software application as secure.
  2. 2Relevant practices must be selected proportionately to system context.
  3. 3Draft future revisions must not be presented as current final requirements.

Source

Organisation
National Institute of Standards and Technology
Evidence type
Government Guidance
Published
2022
Version
SP 800-218, SSDF v1.1
Status
Current. Current, revision underway.

View official guidance

Draft SP 800-218 Rev.1 / proposed SSDF v1.2

Relevant Lornets framework areas

Framework domains

  • Security & Access Control
  • Delivery & Change Control

Related evidence

Last verified 2026-08-11

2024

Government Guidance

NIST AI 600-1: Generative Artificial Intelligence Profile

The profile addresses risks including confabulation, data privacy, information integrity, information security and component integration.

National Institute of Standards and Technology

  • AI Assurance
  • Security & Supply Chain