ConceptioArchiveNIST
NISTpublic full text

NIST SP 800-218r1 ipd: Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities

Harold Booth (NIST); Michael Ogata (NIST); Karen Kent (Trusted Cyber Annex); Murugiah Souppaya (NIST); Donna Dodson (NIST) · National Institute of Standards and Technology (NIST)
NIST · Standards · License: Public Domain
Open Source ↗
accesscontrolcomputersecurityidentityincidentresponsenistriskmanagement
cybersecurity, computer security, cryptography, access control, incident response, privacy, identity, risk management, NIST

You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 800-218 Rev. 1 (Initial Public Draft) Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: December 17, 2025 Comments Due: January 30, 2026 (public comment period is CLOSED) Email Questions to: [email protected] Author(s) Harold Booth (NIST) , Michael Ogata (NIST) , Karen Kent (Trusted Cyber Annex) , Murugiah Souppaya (NIST) , Donna Dodson (NIST) Announcement This document describes new and improved practices, tasks, and examples for the secure and reliable development, delivery, and improvement of software. Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model. SP 800-218 recommends the Secure Software Development Framework (SSDF), which is a core set of high-level secure software development practices that can be integrated into each SDLC implementation. Following such practices should help software producers reduce the number of vulnerabilities in released software, mitigate the potential impacts of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences. Because the framework provides a common vocabulary for secure software development, software acquirers can also use it to foster communications with suppliers in acquisition processes and other management activities. NOTE: A call for patent claims is included in this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy – Inclusion of Patents in ITL Publications . Abstract Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure that the software being developed is well-secured. This document recommends the Secure Software Development Framework (SSDF) — a core set of high-level secure software development practices that can be integrated into each SDLC implementation. Following such practices should help software producers reduce the number of vulnerabilities in released software, reduce the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences. Because the framework provides a common vocabulary for secure software development, software acquirers can also use it to foster communications with suppliers in acquisition processes and other management activities. Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure that the software being developed is well-secured. This document recommends the Secure Software Development... See full abstract Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure that the software being developed is well-secured. This document recommends the Secure Software Development Framework (SSDF) — a core set of high-level secure software development practices that can be integrated into each SDLC implementation. Following such practices should help software producers reduce the number of vulnerabilities in released software, reduce the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences. Because the framework provides a common vocabulary for secure software development, software acquirers can also use it to foster communications with suppliers in acquisition processes and other management activities. Hide full abstract Keywords secure software development ; Secure Software Development Framework (SSDF) ; secure software development practices ; software acquisition ; software development ; software development life cycle (SDLC) ; software security Control Families None selected Documentation Publication: https://doi.org/10.6028/NIST.SP.800-218r1.ipd Download URL Supplemental Material: SSDF project Document History: 12/17/25: SP 800-218 Rev. 1 (Draft) Topics Security and Privacy cybersecurity supply chain risk management , vulnerability management Technologies software & firmware Laws and Regulations Executive Order 14306 HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov

Related documents

Record · ID 2970 · SHA-256 f842d4b2786e2b12
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.