Information SecurityUnited States
SSDF (NIST)
What is SSDF (NIST)?
Secure Software Development Framework. It comprises 4 controls organised across 4 domains, and applies in the United States.
How SSDF (NIST) maps to other frameworks
All 4 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 4 domains SSDF (NIST) groups its controls into
Respond Vulnerabilities
Produce Software
Protect Software
Prepare Org
Where SSDF (NIST) overlaps with the standards you already hold
What SSDF (NIST) means in your sector
What SSDF (NIST) means for your job
Questions people ask about SSDF (NIST)
What is SSDF?
Secure Software Development Framework.
How many controls does SSDF have?
SSDF contains 4 controls organized across 4 domains.
Where does SSDF apply?
SSDF is applicable in United States. Organizations operating in or serving customers in this jurisdiction should evaluate its requirements.
How do I get started with SSDF compliance?
Start by understanding the framework's key controls and domains. Our compliance platform provides AI-powered gap analysis and mapping tools to help you assess your current posture and build a remediation plan.
Query SSDF (NIST) programmatically
SSDF (NIST), its 4 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
SSDF (NIST) API reference and MCP config →How ready are you for SSDF (NIST)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.
Written and maintained by Gerard Blokdyk, The Art of Service.Last updated .