WASHINGTON – Today, global tech trade association 91¿ì»îÁÖ welcomed the decision by the Office of Management and Budget (OMB) to extend the deadline for implementing OMB Memorandum M-22-18. The September 2022 memorandum requires agencies to inventory all software used in federal systems, collect attestations from software vendors, and develop training plans for reviewing and validating software security artifacts. M-22-18 directed agencies to collect self-attestations for critical software by June 11. However, the appropriate attestation forms are still under review and not yet available for agencies to use.

“91¿ì»îÁÖ recognizes the critical steps OMB has taken to improve software security in the federal government,” said 91¿ì»îÁÖ Executive Vice President of Policy Gordon Bitko. “We welcome OMB’s deadline extension, as it provides much needed relief to software producers and is an important step towards ensuring a consistent rollout process across the federal government. We also appreciate the additional guidance on the clarification of scope around third-party software components. At the same time, we urge OMB to address ongoing concerns regarding liability and issue a confirming statement that helps protect signatories. We strongly encourage OMB to keep up its public engagements so that software product security teams can learn how to meet the government’s expectations, raise outstanding questions, and share best practices.

91¿ì»îÁÖ has previously called on the Biden Administration to provide additional guidance to providers so that the tech sector can help achieve the government’s objective of securing the software development process. Currently, software producers face significant barriers, including inconsistent software security practices across the U.S. government. The Cybersecurity and Infrastructure Agency (CISA) is currently soliciting public comments on a draft standardized form until June 26.

Public Sector]" tabindex="0">Related [Public Sector]