Solutions for Enterprise-Wide Procurement

Software Attestation

OMB Policy M-22-18 initiated requirements for protections to federal systems from threats and vulnerabilities, thereby reducing risk from cyber-attacks, by ensuring the integrity of software by applying sound development practices in accordance with NIST guidance and recommendations. These policies also require that federal agencies must only use software provided by software producers who can attest to government-specified secure software development practices.

CISA developed a standard self-attestation form to that is to be used by federal agencies that captures the minimum security software development requirements that a software producer must meet and attest too. All agencies are HIGHLY ENCOURAGED to use this form when securing these required attestations. Federal agencies are also required to submit these attestations into the virtual repository that CISA created to secure and store this information. A user must register with CISA in order to gain access to the software attestation repository.

NASA SEWP recommends that agency buyers access the virtual repository to see if the software their purchasing has an existing attestation. Be sure to ensure that the scope of the purchase aligns with the scope of the attestation. If you do not see an attestation for that product, then consider submitting your agency's software attestation for others to leverage.

This government-wide agency and industry requirement applies to:

This government-wide agency and industry requirement does not apply to:

(CISA CyberStat Update - March 20, 2024)

More information on these C-SCRM initiatives can be found at:

CISA - https://www.cisa.gov/topics/information-communications-technology-supply-chain-security