Book an Appointment

Secure Software Development Lifecycle (SSDLC)

How to systematically integrate security into every phase of software development – with the NIST SSDF as a practice catalog, OWASP SAMM as a maturity model, and security gates from requirements all the way to operations.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

19practices in the NIST SSDF (SP 800-218, version 1.1)
42tasks across the four groups PO, PS, PW, and RV
15security practices across five business functions (OWASP SAMM)
5years of security updates — support period as a rule (CRA)

Most vulnerabilities do not arise in operations but in the development process – and that is where they are cheapest to prevent. A Secure Software Development Lifecycle (SSDLC) therefore anchors security activities as an integral part of every phase instead of compensating for them after the fact with penetration tests. With the NIST Secure Software Development Framework (SSDF) and OWASP SAMM, two established, freely available reference frameworks describe which practices belong to it and how their maturity can be measured. And with the Cyber Resilience Act at the latest, a demonstrably secure development and vulnerability handling process is becoming a regulatory obligation for many manufacturers.

From framework to obligation: the SSDLC milestones

Five dates that set the frame — tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Four building blocks of a resilient SSDLC

The NIST SSDF, its AI profile, OWASP SAMM, and the CRA process obligations side by side.

SP 800-218
  • Version 1.1 (final since February 2022) describes 19 practices with 42 tasks in four groups — deliberately technology- and method-neutral, well suited as a common language between development, security, and procurement.
  • A draft of version 1.2 (SP 800-218r1, Initial Public Draft) has been available since December 17, 2025; the comment period ended on January 30, 2026 — not yet final and to be treated as an outlook only.
Prepare the Organization (PO)Protect the Software (PS)Produce Well-Secured Software (PW)Respond to Vulnerabilities (RV)SP 800-218r1

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

NIST · 2022

Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities (SP 800-218)

Final since February 2022; 19 practices and 42 tasks in the four groups PO, PS, PW, and RV, with implementation examples and references.

NIST · 2024

Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (SP 800-218A)

Final since July 2024; extends the SSDF with AI-specific practices, tasks, and recommendations for the development of generative AI models.

NIST · 2025

Draft Secure Software Development Framework (SSDF) Version 1.2 (SP 800-218r1, Initial Public Draft)

Draft of December 17, 2025, with a comment period until January 30, 2026; not yet published as final as of the editorial cut-off.

OWASP Foundation · 2020

OWASP Software Assurance Maturity Model (SAMM) Version 2

Maturity model with 5 business functions, 15 security practices, each with 2 streams and 3 maturity levels; first release v2.0 in January 2020, current model version 2.2 (July 2024).

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/2847 (Cyber Resilience Act)

Annex I Parts I and II with requirements for product properties and vulnerability handling; reporting obligations from September 11, 2026, full applicability from December 11, 2027.

Where does your development process stand today?

A SAMM-based assessment shows the maturity level and gaps of your SSDLC – you can get a first impression via our self-assessment at ssdlc-assessment.com. We would be happy to put the results into context in a no-obligation initial consultation.