Friday, December 19, 2025

Federal News Network: White House releases post-SolarWinds federal software security requirements

Agencies will require software vendors to self-certify that they’re following secure development practices under new White House guidance, but it leaves the door open for departments to mandate third-party security assessments as well.

The new guidance from the Office of Management and Budget, “Enhancing the Security of the Software Supply Chain through Secure Software Development Practices,” stems from last year’s cybersecurity executive order…

The OMB memo requires agencies to ensure their software is developed in line with two documents published earlier this year by the National Institute of Standards and Technology: a “Secure Software Development Framework” (SSDF), as well as “Software Supply Chain Security Guidance.” … Read the full article here.

[related-post]

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Innovation in Action: Advancing Government Health with Philips

FORUM is proud to partner with Philips for a series of articles on their groundbreaking innovations in health technology that serve public- and private sector citizens and service members. Please take a look to learn more about how Philips is advancing modern and efficient health care, while improving lives for generations to come.

Don’t Miss A Thing

Jackie Gilbert
Jackie Gilbert
Jackie Gilbert is a Content Analyst for FedHealthIT and Author of 'Anything but COVID-19' on the Daily Take Newsletter for G2Xchange Health and FedCiv.

Subscribe to our mailing list

* indicates required