Update to OMB Memo M-22-18, Enhancing Software Security
Posted 12 JUne 2023. This memorandum updates OMB Memorandum M-22-18 on requiremetns for enhancng the security of software supply chains through secure software developmnt practices, extends the timelines for agencies to collect attestations from software producers, and provides supplemental guidance on an agencies’ use of Plan of Actions and Milestones (POA&Ms) when a software producer cannot provide the required attestation.