Cyber risk has become a topic of core strategic concern for business and government leaders worldwide and is an essential component of an enterprise risk management strategy. The Software and Supply Chain Assurance (SSCA) Forum provides a venue for government, industry, and academic participants from around the world to share their knowledge and expertise regarding software and supply chain risks, effective practices and mitigation strategies, tools and technologies, and any gaps related to the people, processes, or technologies involved.
The effort is co-led by the National Institute of Standards and Technology (NIST), the Department of Homeland Security (DHS), the Department of War (DoW), and the General Services Administration (GSA). Participants represent a diverse group of career professionals including government officials, chief information security officers, those in academia with cybersecurity and supply chain specialties, system administrators, engineers, consultants, vendors, software developers, managers, analysts, specialists in IT and cybersecurity, and many more.
While the general intent is to share information, the SSCA Forum also offers government and private sector participants, including international participants, an opportunity to openly collaborate by presenting and receiving feedback on current and potential future work. Most events are two days long and contain a mixture of discussion and presentation; attendee participation is strongly encouraged.
The forum, initially called the Software Assurance (SwA) Forum and Working Groups, started in 2003 as a Department of Homeland Security (DHS)-sponsored Cross-Sector Cyber Security Working Group (CSCSWG). It was established as part of the Critical Infrastructure Partnership Advisory Council (CIPAC) that provides legal framework for public-private collaboration and participation. Originally, its purpose was to bring together a stakeholder community to protect the Nation’s key information technologies, most of which are enabled and controlled by software. Over time, the community evolved and broadened the scope to also focus on the supply chain. Events were held quarterly; Summer and Winter sessions were intended for working group-type discussions while the Spring and Fall sessions were reserved for more traditional forum presentations.
The SSCA Forum is held 2-3 times a year and is FREE and OPEN to the public. Registration is required.
SSCA Fall Forum:
DATES: September 22-23, 2026
LOCATION: MITRE (McLean, VA Campus)
REGISTRATION: Register for September 2026 SSCA Forum
DRAFT AGENDA: September 2026 SSCA Forum Draft Agenda
POSSIBLE AGENDA TOPICS: AI incident response, Bills of Materials (BOMs), contracts, crypto agility, critical infrastructure security, and vulnerability management.
To receive information about upcoming meetings and related publications and activities, sign up for the sw.assurance Google Group - operated by NIST.
To suggest a topic be included at a future SSCA Forum, submit a SSCA Forum Topic Suggestion Form. The SSCA Forum Topic Suggestion Form is a Google Form. If you prefer to use a PDF version of the form, you can e-mail it to [email protected] with "SSCA Forum Topic Suggestion" as the subject line.
To see slides from a previous forum that were approved for public sharing, click on the year the forum occurred, then the date. Available slides will be hyperlinked on the agenda for that forum:
Agendas and presentations for events prior to 2014 (shown below) are not available.
Security and Privacy: controls assessment, cybersecurity supply chain risk management, information sharing, malware, risk assessment, security controls, security measurement, security programs & operations, systems security engineering, vulnerability management
Technologies: cloud & virtualization, hardware, software & firmware
Applications: communications & wireless, cybersecurity framework
Laws and Regulations: Comprehensive National Cybersecurity Initiative, Cybersecurity Enhancement Act, Cybersecurity Strategy and Implementation Plan, Cyberspace Policy Review, Executive Order 13636, Federal Acquisition Regulation, Federal Information Security Modernization Act, Homeland Security Presidential Directive 12, OMB Circular A-130