Secure Software Development Framework
NIST SP 800-218, a framework of secure software development practices that is referenced by EO 14028 and increasingly by medical device guidance.
Definition
The Secure Software Development Framework (SSDF), published as NIST SP 800-218, is a set of fundamental, sound, secure software development practices grouped into four practice groups: Prepare the Organization (PO), Protect the Software (PS), Produce Well-Secured Software (PW), and Respond to Vulnerabilities (RV). Each practice has tasks, implementation examples, and references that map to common secure-development standards (OWASP SAMM, BSIMM, ISO/IEC 27034, IEC 62443).What this means in practice
SSDF gained urgency through Executive Order 14028 (Improving the Nation's Cybersecurity), which made SSDF conformance attestation a requirement for software sold to the U.S. federal government. For medical device manufacturers, SSDF is now the most widely accepted vocabulary for describing your secure development lifecycle in a 510(k) or PMA cybersecurity submission. SSDF practices are largely a superset of IEC 81001-5-1 §5, citing both demonstrates breadth and medical-specific depth.- •Adopting SSDF in name only, the framework expects measurable practices with evidence (e.g., PW.4 'Reuse Existing, Well-Secured Software When Feasible' requires component selection criteria and provenance records).
- •Conflating SSDF with SPDF, SPDF is FDA's umbrella term; SSDF is one specific framework that can satisfy an SPDF requirement.
- •Forgetting RV (Respond to Vulnerabilities), many manufacturers' SSDF programs are strong on development but weak on post-market response.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsInternational standard defining secure-product-lifecycle activities for health software, including medical devices.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
A documented, risk-based set of processes that build cybersecurity into a medical device across its full lifecycle.
A machine-readable inventory of all software components, including open-source and third-party libraries, used to build a medical device.
More in Cybersecurity
· Same categoryOpenSSF framework defining progressive levels of build-system integrity for software supply chain security, focused on tamper-resistance of the build.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Primary references
3 sources- 1
NIST SP 800-218: SSDF v1.1VerifiedNISTcsrc.nist.gov
- 2
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
- 3
CISA - Healthcare and Public Health SectorVerifiedCISAcisa.gov
Inline markers like [1] jump to the matching reference above.