U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Secure Software Development Framework SSDF


The SSDF uses these established secure development practice documents as references. Note that these references were current at the time SSDF version 1.1 was published, and may no longer be current.

NIST Publications
Software Development
Government, Industry, and Academic Publications
International Standards
Open Web Application Security Project (OWASP)
Software Assurance Forum for Excellence in Code (SAFECode)
Additional Guidance and Recommended Practice Publications

Created February 25, 2021, Updated January 10, 2023