What Does CISA’s Secure Software Development Form Mean for Contractors?
Summary
CISA intends for the Repository to be the primary vehicle by which software producers may submit a completed Common Form and artifacts. The final Common Form more prominently states that the software producer may choose to demonstrate conformance with the minimum requirements by submitting a third-party assessment documenting that conformance with the NIST Framework (i.e., a third-party assessment performed by a Third Party Assessor Organization (3PAO) that is either FedRAMP certified or approved in writing by an appropriate agency official). Notably, if electing to demonstrate performance by submitting a third-party assessment, the software producer need not sign the form. CISA intends for the Repository to be the primary vehicle by which software producers may submit a completed Common Form and artifacts. Although we expect many agencies to use the Common Form, OMB guidance leaves the door open for attestations to be supplied in other ways.