- CISA provides the federal common form and identifies it as one government-wide resource that agencies may choose. The linked form supplies its own representations and submission instructions; other requests may differ.
References and citations
- SP 800-218 explains that notional implementation examples are not required or exhaustive. PO.3.3 addresses tool-generated artifacts, audit trails, review frequency, retention, and responsibility for artifacts.
"core set of high-level secure software development practices"
- Rescinds M-22-18 and M-23-16 and states that agencies may choose the common attestation form or develop assurance policies and processes that match their risk determinations and mission needs.