The White House Office of Management and Budget (OMB) rescinded the 2022 memo M-22-18, which required federal agencies to use a standardized Secure Software Development Attestation Form to obtain cybersecurity assurances from software vendors before procurement. OMB Director Russell (Russ) Vought argued the approach relied on “unproven and burdensome” processes and that “there is no universal, one-size-fits-all method” for validating provider security; agencies are now directed to apply secure development principles based on comprehensive risk assessments tailored to mission needs.
The rescinded policy was a key implementation of Executive Order 14028, issued in response to the SolarWinds supply-chain intrusion, and was intended to use federal purchasing power to drive secure software development practices across the market. Reporting notes concerns from former Biden cyber officials that removing the government-wide attestation requirement represents a cybersecurity policy rollback and could weaken incentives for vendors to meet consistent baseline practices. OMB’s updated guidance still encourages agencies to maintain complete software and hardware inventories and allows continued optional use of the prior attestation form, while also pointing to alternatives such as contractual requirements for vendors to provide a software bill of materials (SBOM) upon request.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
Following the Jan. 23 memo and its public reporting on Jan. 26-29, former Biden officials and other experts warned the rollback could weaken procurement-driven software security and create fragmented agency requirements, while supporters said it would enable more tailored, evidence-based decisions. Commentators broadly agreed implementation by individual agencies would determine the practical impact.
The new OMB memo directed agencies to validate software and hardware security using secure development principles, mission needs, and comprehensive risk assessments instead of a one-size-fits-all form. Agencies were still told to maintain complete software and hardware inventories and could continue using the attestation form or require SBOMs by contract on request.
On 2026-01-23, OMB Director Russell Vought signed memorandum M-26-05 rescinding M-22-18 and M-23-16. The new memo ended the governmentwide mandate for standardized vendor self-attestations and SBOM-related procurement expectations, arguing the prior approach was burdensome and unproven.
In June 2024, the polyfill.io incident further demonstrated the importance of knowing where third-party code is used across environments. It was later cited as an example of why agencies need actionable inventory data rather than only compliance attestations.
In March 2024, the xz/liblzma backdoor incident underscored the need for rapid, machine-readable visibility into where software components are deployed and what systems they affect. Later commentary cited it as evidence that paperwork alone is insufficient for supply-chain defense.
In 2022, OMB issued memorandum M-22-18 requiring federal agencies to obtain cybersecurity assurances from software suppliers through a standardized governmentwide self-attestation form tied to secure software development practices. The policy was intended to improve federal software supply-chain security.
In May 2021, President Joe Biden signed Executive Order 14028 to strengthen federal cybersecurity, including software supply-chain security measures prompted by the SolarWinds campaign. This order became the policy basis for later OMB software assurance requirements.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcescworld.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.