What category of practice vocabulary this is
NIST SSDF Version 1.1 is a software security development framework and a shared vocabulary for discussing practices across the software lifecycle. Producers and acquirers can use the same names. It is not a product you install. It is not an SBOM, not an Executive Order checkbox, not a certification, not NIST AI RMF, and not a web or LLM Top 10.
Who it commonly frames: AppSec path readers who only had a Reference field guide, buyers who treat an SBOM or an Executive Order checkbox as SSDF complete, and readers who fold SSDF into AI RMF or an OWASP awareness list. This is a practice vocabulary. It is not a U.S. statute that forces a certificate, and it is not a certification scheme.
What security people most often confuse: they fold an SBOM file, an Executive Order checkbox, four group names, AI RMF, web Top 10:2025, the LLM Top 10, ASVS, and an Atlas lesson into one seal. This page keeps those objects apart. The field guide at /reference/frameworks/nist-sp-800-218/ stays the edition-pin home. A3 at /learn/topics/pipeline-write-vs-promote/ stays the write-versus-promote practice. A4 at /learn/topics/sbom-evidence-and-priority/ stays inventory evidence. The SBOM lab at /labs/sbom-decision/ stays the priority call. The AI RMF explainer at /learn/explainers/nist-ai-rmf/ stays the voluntary AI framework. The web Top 10 explainer at /learn/explainers/owasp-top-10/ stays the web awareness list. The LLM explainer at /learn/explainers/owasp-llm-top-10/ stays the LLM awareness list. The ASVS explainer at /learn/explainers/owasp-asvs/ stays the verification project. This explainer complements them. It does not replace any of them, and it does not reprint the practice or task catalog.
Edition pin
The edition string to teach is NIST SP 800-218, Secure Software Development Framework (SSDF) Version 1.1, final, February 2022 (document history 3 February 2022), DOI 10.6028/NIST.SP.800-218. Official hubs are https://csrc.nist.gov/pubs/sp/800/218/final and https://doi.org/10.6028/NIST.SP.800-218. Re-opened on 2026-09-26: the publication page still says Date Published February 2022, Document History 02/03/22 Final, and the same DOI.
SP 800-218 Revision 1 (SSDF Version 1.2) remains an initial public draft. Date Published December 17, 2025 (17 December 2025). The public comment period closed on January 30, 2026 (30 January 2026). Do not call Version 1.2 final. Draft hub: https://csrc.nist.gov/pubs/sp/800/218/r1/ipd. This card does not invent an adoption percentage.
PO, PS, PW, and RV are literacy labels
Prepare the Organization (PO), Protect the Software (PS), Produce Well-Secured Software (PW), and Respond to Vulnerabilities (RV) are the four practice groups at slogan depth. PO names who owns the secure environment around the pipeline and the practice conversation. PS names how you protect code and release integrity. Inventory evidence can sit in that conversation, and an SBOM is not SSDF done. PW names how software is designed, reviewed, and tested with security in mind. RV names what happens when a vulnerability shows up, with an owner and a review date.
These are group labels. They are not a finished implementation, and they are not permission to paste the practice or task catalog into Atlas. This page does not list task identifiers. On the synthetic ShopCart pipeline, the person who writes a change is not the person who promotes it. That conversation lives on A3 at /learn/topics/pipeline-write-vs-promote/. This page points there. It does not become a checklist.
Name the practice conversation, then keep the evidence
Ask which software practice conversation is needed, what evidence would be credible, who owns the decision, and what remains outside SSDF. A named owner on a ShopCart pipeline note is a start. A slide that says SSDF certified is not that evidence.
Practice stays on the existing pages. A3 is /learn/topics/pipeline-write-vs-promote/. A4 is /learn/topics/sbom-evidence-and-priority/. The SBOM lab is /labs/sbom-decision/. The path is /learn/paths/appsec-supply-chain/. The landscape segment, when you are comparing control purposes, is /landscape/segments/application-security/. The field guide remains /reference/frameworks/nist-sp-800-218/.
When the need is AI risk placement, use the AI RMF explainer at /learn/explainers/nist-ai-rmf/. When the need is web awareness, use /learn/explainers/owasp-top-10/. When the need is LLM-application awareness labels, use /learn/explainers/owasp-llm-top-10/. When the need is leveled verification, use /learn/explainers/owasp-asvs/. Do not collapse those lanes. The six-map comparison is /reference/frameworks/compare/. It does not add a seventh map object for this vocabulary.
SP 800-218A is a companion, not this edition
SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile, is a name-only companion (final 26 July 2024, document history 07/26/24, Date Published July 2024, DOI 10.6028/NIST.SP.800-218A). Do not swap it into the Version 1.1 edition string. This page does not open a full SP 800-218A Atlas page.
What this card is not
Not an SSDF course. Not a practice or task catalog. Not a G4 revival. Not an Agentic Top 10 card. Not a federal companion page. Not a full SP 800-218A page. Not exploit or red-team PoC homework. Not a web Top 10 rewrite. Not an ASVS rewrite. Not an LLM Top 10 rewrite. Not an AI RMF rewrite. Not a replacement for the field guide at /reference/frameworks/nist-sp-800-218/, for A3 at /learn/topics/pipeline-write-vs-promote/, for A4 at /learn/topics/sbom-evidence-and-priority/, or for the SBOM lab at /labs/sbom-decision/. Not permission to invent an adoption statistic. Not a claim that naming PO, PS, PW, and RV means the product is secure. Not an Atlas attestation of SSDF completion.
Not a CSF 2.0 profile. Outcomes live on /learn/topics/outcomes-then-controls/. The six-map comparison at /reference/frameworks/compare/ does not add a seventh map object for SSDF. A row is not this page. This page is the labeled literacy home beside the field guide.
Rewrite the one-line claim
Replace "we are SSDF certified" with a reading sentence. We use NIST SSDF Version 1.1 as a shared software security practice vocabulary, then name the evidence and decision owner for the specific practice.
When a slide says "SSDF certified" or "SSDF complete," privately ask which edition (SP 800-218, Version 1.1, February 2022), which practice conversation was actually evidenced, who owns the decision, and whether the live need is SSDF vocabulary, an SBOM inventory, AI RMF placement, web Top 10 awareness, LLM awareness, or ASVS verification depth. Do not paste proprietary prompts, customer data, or exploit kits into Atlas.
Common folds next to this vocabulary
Teaching table only. Naming a fold is not a finished implementation.
| Phrase people say | Literacy correction |
|---|---|
| Our SBOM means SSDF is done. | An SBOM is one possible artifact or inventory evidence. It is not the whole SSDF framework and does not prove every practice. A4: /learn/topics/sbom-evidence-and-priority/. SBOM lab: /labs/sbom-decision/. |
| The Executive Order checkbox proves SSDF certification. | A policy or procurement requirement is not an Atlas certificate and does not turn SSDF into a certification scheme. Verify the actual requirement and the evidence owner. Field guide: /reference/frameworks/nist-sp-800-218/. |
| SSDF is AI RMF. | SSDF is a secure software development practice vocabulary. NIST AI RMF 1.0 is a separate voluntary AI risk framework. Explainer: /learn/explainers/nist-ai-rmf/. |
| SSDF is the OWASP web or LLM Top 10. | OWASP Top 10:2025 and GenAI LLM Top 10:2026 are separate awareness lists. SSDF is not either list. Web Top 10: /learn/explainers/owasp-top-10/. LLM Top 10: /learn/explainers/owasp-llm-top-10/. ASVS, when the need is verification depth: /learn/explainers/owasp-asvs/. |
| We named the practices, so the product is secure. | Naming a framework is not evidence of implementation, assessment, certification, or absence of risk. A3: /learn/topics/pipeline-write-vs-promote/. AppSec path: /learn/paths/appsec-supply-chain/. Landscape: /landscape/segments/application-security/. |
| SSDF Version 1.2 is final. | Official NIST status at this review still identifies Revision 1 / Version 1.2 as an initial public draft dated 17 December 2025 (December 17, 2025). Public comment closed 30 January 2026. Do not call it final. |
Claims to retire
Our SBOM means SSDF is done.
An SBOM is one possible artifact or inventory evidence. It is not the whole SSDF framework and does not prove every practice.
The Executive Order checkbox proves SSDF certification.
A policy or procurement requirement is not an Atlas certificate and does not turn SSDF into a certification scheme.
SSDF is AI RMF.
SSDF is a secure software development practice vocabulary. NIST AI RMF 1.0 is a separate voluntary AI risk framework.
SSDF is the OWASP web or LLM Top 10.
OWASP Top 10:2025 and GenAI LLM Top 10:2026 are separate awareness lists. SSDF is not either list.
We named the practices, so the product is secure.
Naming a framework is not evidence of implementation, assessment, certification, or absence of risk.
SSDF Version 1.2 is final.
Revision 1 / Version 1.2 remains an initial public draft dated 17 December 2025. Do not call it final.
SP 800-218A is the Version 1.1 edition pin.
SP 800-218A is a GenAI SSDF community profile companion (final 26 July 2024). Do not swap it into the Version 1.1 edition string.
PO, PS, PW, RV, as labels
Slogan depth only. This table does not reprint the practice or task catalog.
| Group | One-line literacy | Boundary |
|---|---|---|
| Prepare the Organization (PO) | Who owns the secure environment around the pipeline and the practice conversation | Group label. Not a finished practice, and not a task catalog. |
| Protect the Software (PS) | Protect code and release integrity; inventory evidence can sit here (SBOM ≠ done) | Group label. Not a finished practice, and not a task catalog. |
| Produce Well-Secured Software (PW) | How software is designed, reviewed, and tested with security in mind | Group label. Not a finished practice, and not a task catalog. |
| Respond to Vulnerabilities (RV) | What happens when a vulnerability shows up, with an owner and a review date | Group label. Not a finished practice, and not a task catalog. |
CHECK THE CATEGORY
Which sentence matches this page?
Glossary and nearby pages
- NIST SSDF Version 1.1 field guide (edition pin companion, not replaced by this page)
- Who can write, who can promote (A3)
- An SBOM is inventory, not a control (A4)
- Lab: Defer with a date, or patch for a reason
- Application and software supply-chain path
- Landscape: Application and software supply chain
- NIST AI RMF 1.0 explainer (voluntary AI framework, not this vocabulary)
- NIST SP 800-207 ZTA explainer (architecture paradigm, not this vocabulary)
- OWASP LLM Top 10 explainer (awareness list, not this vocabulary)
- OWASP Top 10 explainer (web awareness list, not this vocabulary)
- OWASP ASVS explainer (verification requirements, not this vocabulary)
- Compare the six maps (a row is not this vocabulary, and not a seventh map)
- Outcomes first, then controls (F8a)
- Privacy is not a CIA checkbox
Use the agency page in the sources for the authoritative text. This page has no figure.