The Cybersecurity and Infrastructure Security Agency (CISA) on March 11th finalized the Attestation Letter for software vendors, marking a significant step towards addressing software security across federal systems.
Software producers must furnish Attestation letters to CISA (https://www.cisa.gov/resources-tools/resources/secure-software-development-attestation-form) and linked SBOMs to agencies using their software. The clock starts with the final approved release of the CISA Attestation form yesterday.
Expected date for critical software vendors to adhere: June 11, 2024
Expected date for all software vendors to adhere: September 11, 2024
What Does This Mean for Software Vendors?
For software vendors engaging with Federal Government Agencies, the finalized CISA Attestation Letter carries immense significance. It serves as a formal declaration of adherence to critical security requirements outlined in the Executive Order 14028 Section 4(e) which is mapped to the National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF, NIST SP 800–218).
Among these requirements are the following key aspects:
SBOM360 Hub, from Lineaje, is designed to help Software publishers to meet these requirements.
Additional Software Vendor Requirements:
These requirements ensure that software producers provide accurate information about their software and attest to its secure development practices, aligning with federal government cybersecurity objectives outlined in Executive Order 14028 and related directives like OMB M-22–18 and M-23–16.
Conclusion
The finalization of the CISA Attestation Letter marks a significant milestone in the ongoing efforts to fortify software security within Federal Government Agencies. By requiring vendors to attest to critical security requirements outlined in the NIST SSDF, CISA is ensuring that software deployed across federal systems adheres to robust security standards.
At Lineaje we automate the CISA Attestation Letter, along with evidence collection to attest with confidence. Come check out what we can do at www.lineaje.com