Skip to main content
Lornets

Evidence note

NIST Secure Software Development Framework v1.1

Government Guidance2022National Institute of Standards and Technology

What does it cover?

A risk-based set of secure software-development practices intended to be integrated into software-development lifecycles.

Key points

  1. 01SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.
  2. 02It is designed to be risk-based and adaptable to different software contexts.
  3. 03SSDF v1.1 remains the current final version while a newer revision process is underway.

Why it matters. Lornets interpretation.

Secure development is a lifecycle capability rather than a final-stage scanner activity. Evidence can come from design, development, build, dependency and change-control practices.

This is the Lornets reading of the source, not a finding of the source itself.

What it does not establish

  1. 01SSDF use does not certify a software application as secure.
  2. 02Relevant practices must be selected proportionately to system context.
  3. 03Draft future revisions must not be presented as current final requirements.

Source

Organisation
National Institute of Standards and Technology
Evidence type
Government Guidance
Published
2022
Version
SP 800-218, SSDF v1.1
Status
Current. Current, revision underway.

View official guidance

Draft SP 800-218 Rev.1 / proposed SSDF v1.2

Relevant Lornets framework areas

Framework domains

  • Security & Access Control
  • Delivery & Change Control

Related evidence

Source record

Published
2022
Last verified
2026-08-11
Source status
Current. Current, revision underway.