What it helps you do
Give ShopCart’s producers and the people who acquire ShopCart a shared vocabulary for how software gets built securely. PO, PS, PW, and RV name practices across the lifecycle. They are recommendations you can point to in a pipeline review or an acquisition conversation.
A useful way to begin
- Pin SSDF Version 1.1, final February 2022, document history 3 February 2022, DOI 10.6028/NIST.SP.800-218. If someone brings a draft of Version 1.2, label it an initial public draft and keep teaching 1.1 until a Final exists.
- Prepare the Organization (PO): name who owns the secure environment around the pipeline. PO.5 lines up with A3, where the person who writes ShopCart is not the person who promotes it.
- Protect the Software (PS): protect the code and the release. PS.2 is a mechanism for verifying release integrity, and PS.3 archives what shipped. An SBOM (A4) is inventory evidence inside this group. It does not finish SSDF.
- Produce Well-Secured Software (PW) and Respond to Vulnerabilities (RV): PW is how ShopCart is designed, reviewed, and tested. RV is what happens when a vulnerability shows up, with an owner and a review date. Lab 5 is that decision.
What good evidence looks like
Mapped practice owners for PO.5 and PS.2 on a synthetic ShopCart pipeline: who may promote, where the build secret lives, and who keeps the component inventory. A slide that says “SSDF certified” is not that map.
Other records you might already have
- A ShopCart pipeline note that names the owner of the secure build environment (PO.5) and who may promote.
- A release record that names who verifies release integrity (PS.2) and where the component inventory sits, separate from the vulnerability response owner.
Labeled companions
- SP 800-218A. GenAI SSDF community profile only (final 2024-07-26). Not a replacement of SSDF Version 1.1.
- SP 800-218 Rev. 1 (SSDF Version 1.2). Initial public draft. Not the final edition taught on this card.
Claims to retire
SSDF means the executive-order attestation is complete.
SSDF Version 1.1 is a practice framework and a shared vocabulary. Publishing or citing it is not, by itself, a finished attestation.
SSDF is a product.
SP 800-218 Version 1.1 names practices. It is not a tool you install and then call done.
An SBOM alone satisfies SSDF.
An SBOM is inventory evidence. It does not, by itself, complete the SSDF Version 1.1 practices.
Related lessons
This is an original educational guide. Use the publisher’s official materials for the authoritative requirements and licensing terms. A relationship between maps is not one-to-one control equivalence. This card complements the six live maps. It is not a row in that comparison.