Assessing the Response (or Lack Thereof) to the Secure Software Attestation Form
July 30, 2024

Nick Mistry
Lineaje

In May 2021, the Biden Administration issued Executive Order (EO) 14028, Improving the Nation's Cybersecurity. The legislation urged any organization working with federal agencies to modernize and prioritize security protocols to safeguard the sensitive data created and stored by the government.

A key theme within the EO was the importance of secure software, and rightfully so. Despite the Biden Administration calling attention to this issue, software supply chain attacks in the US impacted over 2,700 organizations in 2023 — growing over 50% year-over-year.

To better facilitate the secure development of software built and bought by federal agencies, the Cybersecurity and Infrastructure Security Agency (CISA) and Office of Management and Budget (OMB) created the Secure Software Development Attestation form. Software producers working with federal agencies had until June 11, 2024 for critical software and until September 11, 2024 for all software to submit the form, signed by the software producer's CEO.

The Secure Software Attestation Form Requirements

The Secure Software Attestation Form requires software producers to use industry standards derived from the National Institute of Standards and Technology (NIST) secure software development framework (SSDF). The form calls for software producers to:

■ Protect and segregate network environments involved in building software.

■ Monitor those who have authorization to access the code.

■ Enforce basic security hygiene practices, including multi-factor authentication (MFA).

■ Maintain trusted source code supply chains by managing risks of the supply chain.

Be able to determine the lineage of the software for any internal code, open-source and third-party software components.

■ Utilize automated tools or similar processes to scan for security vulnerabilities, ensuring that software is up-to-date on current releases.

■ Notify any federal agencies if software violates the terms of the Secure Software Development Attestation form.

Are Organizations Ready to Comply?

While the time to fill out the Secure Software Attestation Form has come and gone for critical software and around the corner for all software, a recent survey from Lineaje, conducted a month before the June deadline, revealed significant gaps in software producers' preparedness and awareness.

The survey, which polled over 100 security professionals attending RSA Conference 2024, found that less than one in five companies impacted by the form were prepared to meet the imminent deadline.

Failure to comply with the form requirements has the potential to cause severe consequences for software producers and federal agencies alike, including potential legal and financial penalties for software producers, increased vulnerability to cyberattacks, and damage to both the software producers and federal agencies' reputations.

Despite the looming threats, an overwhelming majority of respondents (84%) had not yet implemented Software Bills of Materials (SBOMs) into development processes — which EO 14028 made mandatory back in May of 2021. Even more concerning, over half (65%) had never even heard of EO 14028. Even those who were familiar with it, half were unaware of its specific requirements.

Organizations Are Missing the Tools and Resources to Secure Software Supply Chain

In addition to the lack of knowledge of the latest compliance regulations, many security professionals simply do not have the tools to identify and mitigate security concerns in the software supply chain.

Open-source software components make up anywhere from 80%-90% of all software built today. While convenient, 82% of open-source software components are inherently risky. Over half of respondents in the survey said their companies utilized open source software components, but only 16% say the average open source is secure.

Many security professionals (56%) claimed to have the tools to identify and mitigate security concerns in open source software, but nearly a quarter were unsure, and one in five had no tools. In addition, 45% of security professionals are struggling with budget limitations and staffing resources (33%) to adopt proper software supply security measures.

Moving Forward

Businesses can't operate without open source software. However, organizations also can't survive long-term if that software is compromised with security vulnerabilities. To stay secure, software vendors and cybersecurity professionals must educate themselves and examine where they fall short on compliance deadlines. Doing so will protect their organizations, and also contribute to enhancing national security. 

In addition, organizations need to prioritize the creation and upkeep of SBOMs. With an SBOM, organizations are able to assess software components' risks and address any vulnerabilities before an adversary can exploit it.

Software producers and consumers must also have real-time visibility into the quality of software components. It can often be the difference between a well-maintained and secure software supply chain, or one that is easily manipulated by threat actors.

Over the next few years, I suspect that compliance measures like EO 14028 will continue to emerge. If the response, or lack thereof, to the Secure Software Development Attestation form is a preview of what we can expect with future legislation, we'll likely see software supply chain attacks continue to plague public and private sector organizations alike. However, if developers and security professionals partner together to create and maintain secure code, prioritize real-time visibility, and commit to investing in technologies that enable them to adequately protect their software supply chain, we may be able to fulfill the vision of improving the nation's cybersecurity after all.

Nick Mistry is SVP and CISO at Lineaje
Share this

Industry News

March 10, 2025

Parasoft is accelerating the release of its C/C++test 2025.1 solution, following the just-published MISRA C:2025 coding standard.

March 10, 2025

GitHub is making GitHub Advanced Security (GHAS) more accessible for developers and teams of all sizes.

March 10, 2025

ArmorCode announced the enhanced ArmorCode Partner Program, highlighting its goal to achieve a 100 percent channel-first sales model.

March 06, 2025

Parasoft is showcasing its latest product innovations at embedded world Exhibition, booth 4-318, including new GenAI integration with Microsoft Visual Studio Code (VS Code) to optimize test automation of safety-critical applications while reducing development time, cost, and risk.

March 06, 2025

JFrog announced general availability of its integration with NVIDIA NIM microservices, part of the NVIDIA AI Enterprise software platform.

March 06, 2025

CloudCasa by Catalogic announce an integration with SUSE® Rancher Prime via a new Rancher Prime Extension.

March 05, 2025

MacStadium announced the extended availability of Orka Cluster 3.2, establishing the market’s first enterprise-grade macOS virtualization solution available across multiple deployment options.

March 05, 2025

JFrog is partnering with Hugging Face, host of a repository of public machine learning (ML) models — the Hugging Face Hub — designed to achieve more robust security scans and analysis forevery ML model in their library.

March 05, 2025

Copado launched DevOps Automation Agent on Salesforce's AgentExchange, a global ecosystem marketplace powered by AppExchange for leading partners building new third-party agents and agent actions for Agentforce.

March 05, 2025

Harness completed its merger with Traceable, effective March 4, 2025.

March 04, 2025

JFrog released JFrog ML, an MLOps solution as part of the JFrog Platform designed to enable development teams, data scientists and ML engineers to quickly develop and deploy enterprise-ready AI applications at scale.

March 04, 2025

Progress announced the addition of Web Application Firewall (WAF) functionality to Progress® MOVEit® Cloud managed file transfer (MFT) solution.

March 04, 2025

Couchbase launched Couchbase Edge Server, an offline-first, lightweight database server and sync solution designed to provide low latency data access, consolidation, storage and processing for applications in resource-constrained edge environments.

March 04, 2025

Sonatype announced end-to-end AI Software Composition Analysis (AI SCA) capabilities that enable enterprises to harness the full potential of AI.

March 03, 2025

Aviatrix® announced the launch of the Aviatrix Kubernetes Firewall.