United States of America: Entry into force of OMB order requiring Federal agencies to collect in a centralised system cybersecurity attestation from software vendors

Compare with different regulatory event:

Description

Entry into force of OMB order requiring Federal agencies to collect in a centralised system cybersecurity attestation from software vendors

On 11 June 2023, the requirement obliging federal agencies to collect in a centralised system cybersecurity attestation letters outlined in the Office of Management and Budget (OMB) Memorandum "Enhancing the Security of the Software Supply Chain through Secure Software Development Practices" comes into force. The Memorandum requires every federal agency to comply with National Institute of Standards and Technology (NIST) guidance when using third-party software. The software that fall under the guidance includes firmware, operating systems, cloud-based software, applications and application services. The Memorandum lists the steps each agency must take to ensure its compliance with secure software development practices, such as obtaining a self-attestation from the software producer for all third-party software used by the agency and obtaining certificates that demonstrate conformance with secure software development practices. In the absence of the self-attestation and certificate, the private entities will not be able to participate in any public tendering or be granted a public procurement.

Original source

Scope

Policy Area
Public procurement
Policy Instrument
Public procurement access
Regulated Economic Activity
software provider: app stores, software provider: other software, infrastructure provider: cloud computing, storage and databases
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2022-09-14
adopted

On 14 September 2022, the Office of Management and Budget (OMB) issued new security requirements th…

2023-02-11
in force

On 11 February 2023, the requirement for federal agencies to develop guidelines for software vendor…

2023-06-09
adopted

On 9 June 2023, the Office of Management and Budget (OMB) issued an Update to Memorandum M-22-18 fo…

2023-06-11
in force

On 11 June 2023, the requirement obliging federal agencies to collect in a centralised system cybe…