M-26-05 software-security policy shift
M-26-05 (Jan 23, 2026) rescinded the government-wide software self-attestation mandate (terminating M-22-18/M-23-16), shifting to agency discretion; agencies may still use the CISA attestation form or request SBOMs covering the runtime production environment.
