Going Hard on Software: OMB Unveils Mandatory Software Supply Chain Security Compliance Requirements
Client Alert | 2 min read | 09.15.22
Yesterday, the Office of Management and Budget (OMB) released Memorandum M-22-18, implementing software supply chain security requirements that will have a significant impact on software companies and vendors in accordance with Executive Order 14028, Improving the Nation’s Cybersecurity. The Memorandum requires all federal agencies and their software suppliers to comply with the NIST Secure Software Development Framework (SSDF), NIST SP 800-218, and the NIST Software Supply Chain Security Guidance whenever third-party software is used on government information systems or otherwise affects government information. The term “software” includes firmware, operating systems, applications, and application services (e.g., cloud-based software), as well as products containing software. It is critical to note that these requirements will apply whenever there is a major version update or new software that the government will be using.
The Memorandum requires agencies to take the following actions:
- within 90 days, agencies must inventory all software subject to the Memorandum;
- within 120 days, agencies will have developed a process to communicate requirements to vendors and ensure that vendor attestation letters can be collected in a central agency system;
- within 180 days, agencies must assess training needs and develop plans for the review and validation of attestation documents;
- within 270 days for critical software and within 365 days for all others, agencies will require self-attestations from all software producers; and
- as needed, obtain from software producers a Software Bill of Materials (SBOM)or other artifact(s) that demonstrate conformance to secure software development practices.
To comply with the Memorandum, software producers must attest that they adhere to the NIST software supply chain frameworks and guidance. In lieu of a self-attestation, software producers may also submit third-party assessments of compliance with the software security standards conducted by a certified FedRAMP assessor or an assessor approved by the agency.
Software producers or vendors providing software to the federal government should begin reviewing their security practices and their overall software development lifecycle immediately to ensure that they can attest to compliance with the applicable NIST standards in the very near future.
Contacts
Insights
Client Alert | 5 min read | 08.21.26
FTC Proposes Enforcement Policy Statement on Personalized Pricing: What Businesses Need to Know
On August 19, 2026, the Federal Trade Commission (FTC) announced a proposed Enforcement Policy Statement on personalized pricing — the practice of companies using consumers’ personal data to set individualized prices, discounts, coupons, or other incentives. The proposed statement, which is open for public comment for 30 days following publication in the Federal Register, marks a major step up in the FTC’s focus on data-driven pricing strategies and puts businesses across industries on notice that undisclosed or inadequately disclosed personalized pricing will not be tolerated. Importantly, while the proposed statement is not a binding legal requirement and does not create new legal obligations, it serves as an enforcement warning that the FTC is prepared to use its existing enforcement authority under Section 5 of the FTC Act (Section 5) and is also a potential harbinger of rulemaking. Businesses that engage in — or are considering — personalized pricing should carefully assess their disclosure practices and data collection procedures against the standards articulated in this statement.
Client Alert | 7 min read | 08.19.26
CMS’s Final Rule Bans Federal Medicaid Funding for Youth Gender-Affirming Care
Client Alert | 2 min read | 08.19.26
Client Alert | 7 min read | 08.17.26
Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

