Skip to main content

NIST SP 800-218 (SSDF) v1.1

NIST SP 800-218, the Secure Software Development Framework (SSDF), is a set of fundamental secure-development practices published by NIST for producers of software. Version 1.1 groups those practices under four headings: preparing the organization, protecting the software, producing well-secured software, and responding to vulnerabilities. This page indexes each group against the themes below.

Requirement groupThemes
PO Prepare the OrganizationT1 Documented and applied lifecycle
T9 Segregation of duties and least privilege
T15 Accountability for assisted development
PS Protect the SoftwareT8 Change control and traceability
T12 Build and release integrity
PW Produce Well-Secured SoftwareT2 Requirements and security criteria before implementation
T3 Design and analysis before implementation
T4 Secure coding and code quality
T5 Independent review before a change is accepted
T6 Automated security verification
T7 Testing and acceptance
RV Respond to VulnerabilitiesT13 Vulnerability handling and disclosure
T14 Security updates and supported versions