Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Secure Software Development Framework SSDF


The SSDF uses these established secure development practice documents as references. Note that these references were current at the time SSDF version 1.1 was published, and may no longer be current.

NIST Publications
Software Development
Government, Industry, and Academic Publications
International Standards
Open Web Application Security Project (OWASP)
Software Assurance Forum for Excellence in Code (SAFECode)
Additional Guidance and Recommended Practice Publications

Created February 25, 2021, Updated March 12, 2024