SP 800-218r1 — SSDF v1.2 draft (EO 14306)
NIST has a draft of SP 800-218r1 (Secure Software Development Framework v1.2) under Executive Order 14306. It refreshes the SSDF that underpins the federal secure-software attestation baseline.
Non-regulatory standards anchor: C-SCRM practices (SP 800-161r1), the SSDF attestation baseline (SP 800-218), post-quantum cryptography standards and transition timeline, and CSF 2.0. The full NIST inventory and gap list lives in the companion NIST Tracking Report (July 10, 2026); this entry links to it rather than duplicating it.
NIST is the non-regulatory standards anchor whose outputs flow into CMMC, FAR, and agency requirements. Current headline items: SP 800-218r1 (SSDF v1.2) is in draft under EO 14306; IR 8547 sets the post-quantum transition timeline and is on a finalization watch; FIPS 140-2 validations sunset September 21, 2026; Section 5949-adjacent provenance expectations are emerging; and COSAiS plus the Cyber AI Profile form the AI-security standards track. The full inventory and gap list is in the companion NIST Tracking Report (July 10, 2026). Confirm publication status at csrc.nist.gov.
Plan for the September 21, 2026 FIPS 140-2 sunset, track SP 800-218r1 (SSDF v1.2) for attestation changes, and continue post-quantum inventory against the IR 8547 timeline.
NIST standards are the technical baseline that federal contract and program requirements point to — changes here propagate into member obligations.
SP 800-161r1 shapes supply-chain risk-management expectations referenced by agencies.
SP 800-218 (SSDF) underpins the federal secure-software attestation regime.
Publishes PQC standards and the IR 8547 transition timeline; runs the module validation program (FIPS 140-2 sunset).
COSAiS and the Cyber AI Profile form the emerging AI-security standards track.
Security architecture, compliance, and product teams.
Crypto migration, module re-validation (FIPS 140-3), and SSDF tooling.
Alignment to 800-161r1 / 800-218 referenced in contracts and attestations.
Vendor security requirements tied to NIST frameworks and provenance expectations.
We focus on the roles whose decisions reach members, and why each one matters — not biographical trivia. Names are intentionally withheld until verified against an official source.
Why it mattersOversees standards development referenced across federal programs; confirmed May 2026, sworn in June 2026.
Review recommendedThis profile is a sample interface. Leadership names, dates, regulatory status, and figures must be confirmed against current official sources before any member distribution.