Skip to main content
USTelecom — The Broadband Association
Sample profile — content is illustrative. Verify every name, date, and status against official sources before use.
Back to Agency Atlas
OMBModerate activityReview recommended · 2026-07-10

Office of Management and Budget

Issues federal software- and hardware-security policy and oversees agency implementation of security-assurance requirements; M-26-05 reshaped the software self-attestation regime.

One-minute briefing

Agency snapshot

OMB Memorandum M-26-05 (January 23, 2026) rescinded the government-wide mandate for software producers to submit a secure-software-development self-attestation (terminating M-22-18 and M-23-16), shifting responsibility to individual agencies to set risk-based assurance policies. Agencies may still use the CISA attestation form or request runtime-environment SBOMs at their discretion. Confirm at whitehouse.gov/omb.

1
Active initiatives
0
Upcoming deadlines
1
Priority topics
Most important thing right now

Re-check each contracting agency’s post-M-26-05 attestation/SBOM expectations rather than assuming the prior government-wide mandate applies.

Mandate & jurisdiction

What this agency does

M-26-05 changes whether members selling software to the government must attest or provide SBOMs — now an agency-by-agency question rather than a single mandate.

Software assurance

Sets whether/how agencies require software self-attestation and SBOMs.

Policy memoranda

Directs agency security practices via M-series memos.

Oversight

Monitors agency implementation and budgeting.

Jurisdiction

  • Government-wide management and budget policy
  • Federal software-security assurance policy
  • Agency implementation oversight
Who should care

Software vendors, compliance, and contracts teams.

Operational

Attestation/SBOM process depends on the specific agency.

Compliance

Agency-specific assurance requirements.

Procurement

Contract terms for software security assurance.

Initiatives & deadlines

What they are working on now

MonitorEffectiveCyber incident and software assurance 2026-01-23

M-26-05 software-security policy shift

M-26-05 (Jan 23, 2026) rescinded the government-wide software self-attestation mandate (terminating M-22-18/M-23-16), shifting to agency discretion; agencies may still use the CISA attestation form or request SBOMs covering the runtime production environment.

Key decision-makers

Leadership to know

We focus on the roles whose decisions reach members, and why each one matters — not biographical trivia. Names are intentionally withheld until verified against an official source.

Russell Vought
Director of OMB

Why it mattersSets management policy including software-assurance memoranda.

Review recommended
Working Group analysis

What we are watching

Confidence: ConfirmedSupported by a primary official source on file.

What changed

  • M-26-05 rescinded the government-wide software self-attestation mandate (Jan 2026).

What we are watching

  • How individual agencies set their own assurance policies.

Member exposure

  • Fragmented, agency-specific attestation/SBOM requirements.

Recommended preparation

  • Inventory agency-specific requirements; keep SBOM capability ready.

Open questions

  • Which agencies will still require attestations or SBOMs?
Primary references

Sources & verification

Agency-level sources

This profile is a sample interface. Leadership names, dates, regulatory status, and figures must be confirmed against current official sources before any member distribution.