Revalidated public source record
NIST SP 800-218 Secure Software Development Framework Version 1.1
Source scope
Final secure software development practices used for implementation and release controls. Version 1.2 remained an initial public draft at the research cutoff.
Publisher, edition, and currentness
| Publisher | NIST |
|---|---|
| Claim status | CURRENT TECHNICAL STANDARD |
| Version or edition | SP 800-218 SSDF Version 1.1; Version 1.2 initial public draft tracked separately |
| Publication status | Version 1.1 final; Version 1.2 initial public draft |
| Publication date | 2022-02-03 |
| Official location | https://csrc.nist.gov/pubs/sp/800/218/final |
| K03 revalidated | 2026-08-14T22:04:09Z |
| Currentness assessment | Version 1.1 remains final; SP 800-218 Rev. 1 / SSDF 1.2 was published as an initial public draft on 2025-12-17 and is not represented as final. |
| Superseded by | No successor is assigned in the current source catalog. |
Claim-level support
Each row records the precise proposition this corpus draws from an official section. The citation does not authorize broader conclusions than the stated proposition.
| Section | Proposition supported in this corpus | Official location |
|---|---|---|
| Version 1.1 final publication | SSDF Version 1.1 provides high-level secure software development practices. | Official section |
| Version 1.2 initial public draft | The official NIST record identifies SSDF Version 1.2 as an initial public draft published 2025-12-17. | Official section |
How this source may be used
- Confirm that the official edition, jurisdiction, and status remain current before high-stakes reliance.
- Cite the exact section supporting the proposition rather than the publication title alone.
- Keep technical conformance separate from factual truth, legal authority, moral status, and institutional operation.
- Record retrieval, correction, supersession, and purpose qualification.
Limitations
An official source can still be irrelevant, incomplete, stale, disputed, or unsuitable for a named decision. A standard can define an interchange or security mechanism without resolving personhood, citizenship, sovereignty, consciousness, consent, legal competence, or factual truth. A statute can regulate systems without recognizing Machine Intelligence as a legal person.
Version 1.1 remains final; SP 800-218 Rev. 1 / SSDF 1.2 was published as an initial public draft on 2025-12-17 and is not represented as final.
Corrections, contradictions, and supersession
- No source-specific correction, contradiction, or supersession record is active.
Where this source is used
Authority boundary
Publication by NIST establishes source provenance and official status within the publisher’s scope. It does not transfer governance, registry, assurance, or legal authority to ᚲ.com. The source remains external; this page is a knowledge record and revalidation log.
Exact source-section claims
Each proposition has a stable ID, status, scope, owning route, evidence relationship, currentness qualification, correction state, and synchronized JSON record. Record completeness does not make the proposition true.
NIST SP 800-218 Secure Software Development Framework Version 1.1 — Version 1.1 final publication
SSDF Version 1.1 provides high-level secure software development practices.
Support relationship
SRC-NIST-SSDF· Version 1.1 final publication · DIRECT SOURCE-SECTION SUPPORT
NIST SP 800-218 Secure Software Development Framework Version 1.1 — Version 1.2 initial public draft
The official NIST record identifies SSDF Version 1.2 as an initial public draft published 2025-12-17.
Support relationship
SRC-NIST-SSDF· Version 1.2 initial public draft · DIRECT SOURCE-SECTION SUPPORT