
Agencies shall inventory all software subject to the requirements of the memorandum.
Agency CIOs shall develop a consistent process to communicate relevant requirements in this memorandum to vendors, and ensure attestation letters are collected in one central agency system.
Agency CIOs shall assess training needs and develop training plans for the review and validation of software attestations and artifacts.
Agencies shall collect attestation letters for "critical software" subject to the requirements of this memorandum.
Agencies shall collect attestation letters for all software subject to the requirements of this memorandum.
Our new offering meets all NIST 800-218 requirements and is available on SEWP.
Our Software Supply Chain Security (SSCS) offering was developed in response to Executive Order 14028 to help Federal agencies meet the requirements and deadlines listed in the Office of Management & Budget (OMB) Memo 22-18.
The SSCS offering was created in accordance with the National Institute of Standards and Technology (NIST) Publication 800-218.
The Software Supply Chain Security Offering, developed to meet NIST guidance, is available today on SEWP