New collection (Request for a new OMB Control Number)
Yes
Regular
11/16/2023
Requested
Previously Approved
36 Months From Approved
72,513
0
175,709
0
0
0
The attestation form information will be used by the department or agency to provide great assurances that help
understand whether the software provider performed due diligence followed secure code practices which align with
NIST 800-216 Secure Software Development Practices (SSDF).
OMB circular M-22-18 requires CISA in consultation with OMB to develop a secure software attestation common form
for all federal departments and agencies. Agencies will collect software attestation information from software
suppliers.
EO: EO 14028 Name/Subject of EO: Improving the Nationâs Cybersecurity
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.