Free Tool

CISA Secure Software Attestation Form Template
a fourteen-section workbook for the federal SSDA covering identity, signatory chain, the four practice clusters, POAM, 3PAO, SBOM, VEX, audit trail, renewal cadence, and framework crosswalk

A free, copy-ready CISA Secure Software Development Attestation (SSDA) workbook. Fourteen structured sections covering cover identity and software in scope, signatory authority and False Claims Act exposure, practice cluster 1 (separated and secure software development environment), practice cluster 2 (provenance, integrity, SBOM, SLSA), practice cluster 3 (vulnerability disclosure programme and management), practice cluster 4 (good coding practices and secure-by-design), supporting evidence index, POAM (Plan of Action and Milestones) register, 3PAO (Third-Party Assessment Organization) register, SBOM provision and VEX statement commitment, audit trail and document custodian, renewal cadence and ten named amendment triggers, framework crosswalk against NIST SSDF SP 800-218, EO 14028, OMB M-22-18 and M-23-16, NIST CSF 2.0, NIST SP 800-53 Rev. 5, FedRAMP, NIST SP 800-37, ISO/IEC 27001:2022, SOC 2, PCI DSS, EU Cyber Resilience Act Annex I and Annex V, OWASP ASVS, OWASP SAMM, CIS Controls v8.1, and document control footer. Built for federal software producers, AppSec teams, product security teams, internal security teams, GRC and compliance teams, security engineering teams, CISOs, and security architects that need a defensible producer-side workbook the inspector general, the 3PAO assessor, the federal agency contracting officer, the qui tam relator, and the Department of Justice civil enforcement read against the signed SSDA.

No credit card required. Free plan available forever.

Loading tool...

Carry the signed SSDA, the supporting evidence index, and the POAM register on one workspace rather than across folders

SecPortal pairs the signed CISA SSDA to the live security operating record so the inspector general inquiry, the federal agency contracting officer follow-up, the 3PAO assessment, the qui tam relator review, and the annual renewal all read against one workspace with named-actor activity log. Free plan available.

No credit card required. Free plan available forever.