Skip to content
Back to Home
Compliance Framework

NIST SP 800-218 (SSDF)

NIST SP 800-218, the Secure Software Development Framework, sets out the practices expected of organizations that supply software to the federal government. It reaches software producers rather than system owners, and agencies increasingly ask suppliers to attest to it as a condition of purchase. Verdict maintains the attestation record and the documentation standing behind each practice, so what you sign is backed by something you can show.

Compliance Guide
Detailed guide coming soon
Coming Soon

A detailed guide is on the way

We are preparing a fuller resource on this framework, covering what it asks for, what the record has to show, and how an engagement runs against it. In the meantime, talk to a consultant and we will walk you through how we would approach it for your organization.

Federal Authorization

What an agency, or a company selling to one, has to satisfy before a system can operate or be bought.

Working toward NIST SP 800-218 (SSDF)?

Verdict runs the compliance work and gives you a portal to review it. Tell us where you are and we will tell you what the engagement would look like.

Talk to a Consultant