United States of America: Issued OMB Update to Memorandum M-22-18 Enhancing the Security of the Software Supply Chain through Secure Software Development Practices

Compare with different regulatory event:

Description

Issued OMB Update to Memorandum M-22-18 Enhancing the Security of the Software Supply Chain through Secure Software Development Practices

On 9 June 2023, the Office of Management and Budget (OMB) issued an Update to Memorandum M-22-18 for the heads of executive departments and agencies, enhancing the Security of the Software Supply Chain through Secure Software Development Practices. The memorandum reinforces the requirements outlined in M-22-18, emphasising the significance of implementing secure software development practices and extending the timelines for government agencies to gather attestations from software producers. Agencies must collect attestations for critical software within three months after the OMB approves the common form attestation. Within six months of OMB's approval, agencies must collect attestations for all software subject to the requirements of M-22-18. Furthermore, regarding the scope of M-22-18's requirements, attestations should be collected from the producer of the software end product used by an agency. OMB will prioritise extension requests for software products shared among multiple agencies, designating a lead agency for coordination and progress oversight. In any instance where there is a conflict between the provisions of this memorandum and M-22-18, the guidelines stated in this memorandum take precedence.

Original source

Scope

Policy Area
Public procurement
Policy Instrument
Public procurement access
Regulated Economic Activity
software provider: app stores, software provider: other software, infrastructure provider: cloud computing, storage and databases
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2022-09-14
adopted

On 14 September 2022, the Office of Management and Budget (OMB) issued new security requirements th…

2023-02-11
in force

On 11 February 2023, the requirement for federal agencies to develop guidelines for software vendor…

2023-06-09
adopted

On 9 June 2023, the Office of Management and Budget (OMB) issued an Update to Memorandum M-22-18 fo…

2023-06-11
in force

On 11 June 2023, the requirement obliging federal agencies to collect in a centralised system cybe…