ARTICLE
26 January 2023

Do Business With The Federal Government? Here's A 2022 Cybersecurity Recap: Part Three – Secure Software Development Attestation Requirements

SM
Sheppard, Mullin, Richter & Hampton LLP

Contributor

Businesses turn to Sheppard to deliver sophisticated counsel to help clients move ahead. With more than 1,200 lawyers located in 16 offices worldwide, our client-centered approach is grounded in nearly a century of building enduring relationships on trust and collaboration. Our broad and diversified practices serve global clients—from startups to Fortune 500 companies—at every stage of the business cycle, including high-stakes litigation, complex transactions, sophisticated financings and regulatory issues. With leading edge technologies and innovation behind our team, we pride ourselves on being a strategic partner to our clients.
The new requirements will apply to any third-party software that is used on government information systems or that otherwise "affects" government information.
United States Technology
Sheppard, Mullin, Richter & Hampton LLP are most popular:
  • within Cannabis & Hemp topic(s)

Today we continue our series (see here and here) with the Office of Management and Budget's September 2022 memorandum requiring federal agencies to only use software from software producers that attest compliance with secure software development guidance issued by the NIST. The new requirements will apply to any third-party software that is used on government information systems or that otherwise "affects" government information. You can read our article about the guidance here.

The FAR Council is currently drafting a proposed FAR rule addressing Supply Chain Software Security to integrate these requirements into federal contracts.

Putting it Into Practice – What to expect in 2023: OMB's guidance provided a timeline for agency adoption of these requirements and when requirements will be communicated to software producers. We expect agencies will begin communicating requirements in early 2023 and begin collecting attestation letters for critical software this summer. Software producers should evaluate their software against the NIST guidance. For federal contractors and software resellers, the impact and scope of these requirements remains unclear, but we anticipate additional guidance in 2023.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More