White House Extends Software Attestation Deadline
Summary
The memo today comes just three days before Federal agencies’ previous deadline to start collecting software security attestation letters that was set earlier this year. CISA published a draft version of the “Secure Software Self-Attestation Form” expected to be used by all agencies in late April. The self-attestation form, the agency said, requires software producers serving the government to confirm that they have implanted specific security practices. Requirements for software vendors working with the government to attest to the safety of their products were also included in the Biden administration’s May 2021 cyber executive order. In addition to extending the deadlines today, OMB also offered several points to clarify the scope of how agencies should approach the secure software requirements.