---
title: "NIST SP 800-218 SSDF v1.1"
canonical_url: "https://www.sorena.io/artifacts/global/nist-sp-800-218-ssdf"
source_url: "https://www.sorena.io/artifacts/global/nist-sp-800-218-ssdf"
author: "Sorena AI"
description: "Plain-language NIST SP 800-218 SSDF v1.1 guidance for software producers and acquirers, covering its four practice groups, risk-based tailoring, evidence, and supplier use."
published_at: "2026-03-04"
updated_at: "2026-07-16"
keywords:
  - "NIST SP 800-218 SSDF"
  - "SSDF v1.1"
  - "Secure Software Development Framework"
  - "secure software development"
  - "NIST secure SDLC"
  - "PO PS PW RV"
  - "software release integrity"
  - "secure build pipeline"
  - "provenance and SBOM"
  - "supplier software security requirements"
  - "vulnerability disclosure program"
  - "SSDF audit evidence"
  - "NIST SP 800-218"
  - "SSDF"
  - "DevSecOps"
  - "Software assurance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# NIST SP 800-218 SSDF v1.1

Plain-language NIST SP 800-218 SSDF v1.1 guidance for software producers and acquirers, covering its four practice groups, risk-based tailoring, evidence, and supplier use.

![NIST SP 800-218 SSDF artifact preview](https://cdn.sorena.io/cdn-cgi/image/width=1200,quality=88,format=auto/images/3rd-parties/nist.jpg)

*NIST SP 800-218 SSDF* *Free Resource*

## NIST SP 800-218 SSDF Secure software development and supplier assurance hub

NIST SP 800-218 SSDF v1.1 is an outcome-focused set of secure software development practices that can be integrated into any software development life cycle. Use it to decide what applies, who owns it, and what evidence supports the decision.

Published in February 2022, the SSDF is voluntary guidance for nongovernmental organizations unless a contract, policy, procurement rule, or other authority incorporates it. Its primary audiences are software producers and software acquirers-not only federal agencies.

[Jump to guides](#topics)

## What this artifact helps you do

- **Translate SSDF tasks into engineering controls**: Start with the four groups-Prepare the Organization (PO), Protect the Software (PS), Produce Well-Secured Software (PW), and Respond to Vulnerabilities (RV)-then select applicable practices and tasks by risk.
- **Strengthen release integrity and provenance**: Connect requirements, roles, toolchains, protected environments, design and code checks, release integrity, provenance, component records, and vulnerability response to reviewable evidence.
- **Improve supplier and vulnerability governance**: Help acquirers state desired secure-development outcomes and help producers explain how their own teams and third-party suppliers address them-without treating an SSDF mapping as certification.

By Sorena AI | Updated 2026 | No signup required

### Quick scan

*SSDF*

- **Implementation playbook**: How to scope software and SDLC boundaries, tailor applicable practices by risk, assign producers and suppliers, and preserve decisions.
- **Evidence for assurance**: Which records support practice-level claims, while keeping customer, contractual, federal attestation, and internal assurance uses distinct.
- **Secure development practices**: Task-level guidance for PO, PS, PW, and RV, including toolchains, components, release integrity, testing, disclosure, remediation, and root-cause learning.

The SSDF states desired outcomes and does not prescribe one tool or implementation. Tailor applicability and formality to risk, then retain evidence close to the SDLC work that produced it.

| Value | Metric |
| --- | --- |
| 19 | Practices |
| 42 | Tasks |
| EO 14028 | Mapped |
| Risk-based | Tailored |

**Key highlights:** Toolchains | Integrity | Response

## Primary sources

- [Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities](https://doi.org/10.6028/NIST.SP.800-218?ref=sorena.io) - Primary NIST publication for SSDF v1.1, including its audience, status, four practice groups, practices, tasks, implementation examples, references, and Appendix A mapping to Executive Order 14028 Section 4e.

*Recommended reading path*

## Choose the next SSDF decision

New to the SSDF? Start with its status, audience, four groups, and risk-based tailoring. If the scope is already settled, jump to implementation evidence, supplier communication, or a focused engineering question.

### 1. Start here: scope and practice structure

Understand what SSDF v1.1 is, who uses it, why it is normally voluntary guidance, and how its 19 practices and 42 tasks are organized into PO, PS, PW, and RV.

1. [NIST SP 800-218 SSDF PO, PS, PW, and RV Practice Deep Dive](/artifacts/global/nist-sp-800-218-ssdf/practice-groups.md): A plain-language map of all 19 SSDF v1.1 practices across PO, PS, PW, and RV, with their purpose, handoffs, tailoring decisions, and evidence boundaries.
2. [NIST SP 800-218 SSDF Secure Development Practices Guide](/artifacts/global/nist-sp-800-218-ssdf/secure-development-practices.md): Integrate applicable SSDF PO, PS, PW, and RV tasks into product intake, design, build, release, component management, and vulnerability response workflows.
3. [NIST SP 800-218 SSDF implementation playbook](/artifacts/global/nist-sp-800-218-ssdf/compliance.md): Scope and tailor SSDF v1.1 practices by risk, assign producer and supplier responsibilities, and connect PO, PS, PW, and RV work to evidence.

### 2. Implementation and evidence

Translate selected practices into owned SDLC work and retain evidence that supports a specific scope, practice, task, release, and risk decision.

4. [NIST SP 800-218 SSDF practice evidence guide](/artifacts/global/nist-sp-800-218-ssdf/evidence-for-audits.md): Build a task-level SSDF evidence index for internal assurance, customers, acquirers, and contract reviews without implying NIST certification.
5. [NIST SP 800-218 SSDF SBOM and Provenance Workflow](/artifacts/global/nist-sp-800-218-ssdf/sbom-and-provenance-workflow.md): Apply SSDF PS.3.2 to collect, safeguard, maintain, and share release-component provenance, including an SBOM where appropriate, without confusing it with release integrity.

### 3. Producer, acquirer, and supplier assurance

Use SSDF vocabulary in acquisition and assurance without assuming that SP 800-218 itself creates a universal attestation, certification, or legal deadline.

6. [NIST SP 800-218 SSDF Self-Attestation Guide](/artifacts/global/nist-sp-800-218-ssdf/ssdf-self-attestation.md): Understand when an SSDF-based self-attestation is requested, which separate authority defines it, and how a producer should scope claims and supporting evidence.
7. [NIST SP 800-218 SSDF Self-Attestation Workflow](/artifacts/global/nist-sp-800-218-ssdf/ssdf-self-attestation-workflow.md): A producer workflow for validating the requesting authority, bounding covered software, mapping representations to SSDF tasks, reviewing evidence, signing, and maintaining the record.

### 4. Compare related frameworks or answer a focused question

See how SSDF relates to SP 800-53 system controls and SLSA supply-chain assurance, or go directly to implementation FAQs.

8. [NIST SSDF vs NIST SP 800-53 SA controls: practical side-by-side comparison](/artifacts/global/nist-sp-800-218-ssdf/ssdf-vs-nist-800-53-sa-controls.md): Compare NIST SSDF and NIST SP 800-53 SA controls with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
9. [NIST SSDF vs SP 800-53 SA controls: practice-to-control mapping table](/artifacts/global/nist-sp-800-218-ssdf/ssdf-vs-800-53-sa-controls.md): Compare NIST SSDF and NIST SP 800-53 SA controls with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
10. [NIST SSDF vs SLSA: practical side-by-side comparison](/artifacts/global/nist-sp-800-218-ssdf/ssdf-vs-slsa.md): Compare NIST SSDF and SLSA with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
11. [NIST SP 800-218 SSDF FAQ: practical implementation questions](/artifacts/global/nist-sp-800-218-ssdf/faq.md): Standalone NIST SP 800-218 SSDF FAQ questions with cited answers, implementation checklists, and evidence guidance.

### 5. More guides

Additional guidance related to this artifact.

12. [How should teams handle code scanning under NIST SP 800-218 SSDF?](/artifacts/global/nist-sp-800-218-ssdf/faq/code-scanning.md): How should teams handle code scanning under NIST SP 800-218 SSDF? Clear, cited guidance with practical evidence checks, owner decisions, and implementation steps.
13. [How should teams handle components under NIST SP 800-218 SSDF?](/artifacts/global/nist-sp-800-218-ssdf/faq/components.md): How should teams handle components under NIST SP 800-218 SSDF? Clear, cited guidance with practical evidence checks, owner decisions, and implementation steps.
14. [How should teams handle release gates under NIST SP 800-218 SSDF?](/artifacts/global/nist-sp-800-218-ssdf/faq/release-gates.md): How should teams handle release gates under NIST SP 800-218 SSDF? Clear, cited guidance with practical evidence checks, owner decisions, and implementation steps.
15. [How should teams handle threat modeling under NIST SP 800-218 SSDF?](/artifacts/global/nist-sp-800-218-ssdf/faq/threat-modeling.md): How should teams handle threat modeling under NIST SP 800-218 SSDF? Clear, cited guidance with practical evidence checks, owner decisions, and implementation steps.
16. [How should teams handle vulnerability disclosure under NIST SP 800-218 SSDF?](/artifacts/global/nist-sp-800-218-ssdf/faq/vulnerability-disclosure.md): How should teams handle vulnerability disclosure under NIST SP 800-218 SSDF? Clear, cited guidance with practical evidence checks, owner decisions, and implementation steps.
17. [What build integrity should teams keep for NIST SSDF SP 800-218?](/artifacts/global/nist-sp-800-218-ssdf/faq/build-integrity.md): What build integrity should teams keep for NIST SSDF SP 800-218. Clear, cited guidance with practical evidence checks, owner decisions, and implementation steps.
18. [What secure coding evidence should teams keep for NIST SSDF SP 800-218?](/artifacts/global/nist-sp-800-218-ssdf/faq/secure-coding-evidence.md): What secure coding evidence should teams keep for NIST SSDF SP 800-218. Clear, cited guidance with practical evidence checks, owner decisions, and implementation steps.
19. [Why does provenance matter in NIST SP 800-218 SSDF implementation?](/artifacts/global/nist-sp-800-218-ssdf/faq/provenance.md): Provenance matters in NIST SP 800-218 SSDF implementation because teams need reviewable evidence for source, dependencies, build process, approvals, and software artifact lineage.

## Explore NIST SP 800-218 SSDF guides

*Guides*

Begin with scope and the four practice groups, then move to implementation, evidence, producer-acquirer communication, workflows, comparisons, and focused questions.

*Next step*

## Move from reading SSDF guidance to operational assessment

NIST SP 800-218 SSDF Secure software development and supplier assurance hub should be the shared entry point for your team. Route execution into Assessment Autopilot for live work and into SSOT when the artifact needs deeper research, evidence governance, or supporting analysis.

- Start from NIST SP 800-218 SSDF Secure software development and supplier assurance hub and route the work by entity, product, team, or control owner.
- Use Assessment Autopilot to turn the guidance into owned tasks, evidence requests, and review checkpoints.
- Use SSOT to keep documents, evidence, and control records in one governed system.
- Move from artifact reading to accountable execution without rebuilding the guidance in separate files.

- [Open Assessment Autopilot](/solutions/assessment.md): Turn the guidance into owned tasks, evidence requests, and review checkpoints for NIST SP 800-218 SSDF Secure software development and supplier assurance hub.
- [Open SSOT](/solutions/ssot.md): Keep documents, evidence, and control records in one governed system from the same artifact.
- [Talk through implementation](/contact.md): Review your current process, evidence model, and next implementation steps.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/global/nist-sp-800-218-ssdf.md
