On January 23, 2026, the Office of Management and Budget (OMB) issued Memorandum M-26-05 “Adopting a Risk-based Approach to Software and Hardware Security,” which rescinds a previous Biden Administration’s requirement for all federal agencies to obtain a self-attestation from software producers in the “Common Form” developed by the Cybersecurity and Infrastructure Security Agency (CISA) before using certain third-party software. As its rationale, OMB noted that the prior memoranda diverted agencies from developing tailored assurance requirements and failed to account for threats posed by insecure hardware. Memorandum M-26-05 signals that the federal government is moving away from a “one-size fits-all” approach to software security and will instead allow each agency to develop tailored requirements. In creating their own assurance requirements, agencies may still require a self-attestation and/or Software Bill of Materials (SBOM) from the software vendor if the agency determines that such assurances are necessary based on the risks involved and the agency’s needs.
Latest Post
More Posts
From DAS to WAS: Secretary Hegseth’s Acquisition Overhaul and What It Means for Industry
Fraud Prevention in Focus: Examining DOD’s Risk Management Strategies
Trump Administration Issues Executive Orders that Seek to Shape CHIPS Program and Promote Domestic Mineral Production
The Trump Tariffs and Federal Contractors: In These Taxing Times, Contractors Have a Duty To Know These Five Things
U.S. Federal and State Governments Moving Quickly to Restrict Use of DeepSeek
Subscribe: Subscribe via RSS
Blogs
Firm/Org