---
title: OMB Issues New Cyber Security Requirements for Federal Agencies that Impacts Companies that Sell Software to the Government
description: Software companies need to be on the lookout for a notification from Federal Agencies related to cybersecurity requirements
image: https://info.redstonegci.com/hubfs/images/Blog_Images_with_title/RGCI%20-%20OMB%20Issues%20New%20Cyber%20Security%20Requirements%20for%20Federal%20Agencies%20that%20Impacts%20Companies%20that%20Sell%20Software%20to%20the%20Government.png
---

[ PAY INVOICE](https://redstonegci.com/invoice-payment/) [Call Us Today 256-704-9800](tel:2567049800) [info@redstonegci.com](Mailto:info@redstonegci.com)

<http://www.facebook.com/redstonegci> <http://www.twitter.com/RedstoneGCI> <http://www.linkedin.com/company/redstone-government-consulting-inc-> <https://www.youtube.com/channel/UCQv3eAwiPTTQAnoy7hnUwgg>

[![Redstone_Logo](https://info.redstonegci.com/hubfs/redstone%20logo%20version%201%20-%20rgb-1.png)](https://www.redstonegci.com/)

# OMB Issues New Cyber Security Requirements for Federal Agencies that Impacts Companies that Sell Software to the Government

[Posted by Lynne Nalley, CPA on Fri, Nov 18, 2022 @ 10:11 AM](https://info.redstonegci.com/blog/author/lynne-nalley)

- [Tweet](https://twitter.com/share)

![OMB Issues New Cybersecurity Requirements for Federal Agencies that Impacts Companies that Sell Software to the Government](https://info.redstonegci.com/hs-fs/hubfs/images/Blog_Images_with_title/RGCI%20-%20OMB%20Issues%20New%20Cyber%20Security%20Requirements%20for%20Federal%20Agencies%20that%20Impacts%20Companies%20that%20Sell%20Software%20to%20the%20Government.png?width=1000&height=571&name=RGCI%20-%20OMB%20Issues%20New%20Cyber%20Security%20Requirements%20for%20Federal%20Agencies%20that%20Impacts%20Companies%20that%20Sell%20Software%20to%20the%20Government.png)

Office of Management and Budget (OMB) issued a memorandum dated September 14, 2022, Subject [Enhancing the Security of the Software Supply Chain through Secure Software Development Practices](https://www.whitehouse.gov/wp-content/uploads/2022/09/M-22-18.pdf). This is a result of the President’s [Executive Order on Improving the Nation’s Cybersecurity](https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/).

OMB is requiring Federal agencies to comply with additional NIST requirements. The new requirements which OMB has defined as “NIST guidance” represents the foundation for developing secure software and is comprised of the following two documents:

- [NIST Secure Software Development Framework (SSDF) SP 800-218](https://csrc.nist.gov/publications/detail/sp/800-218/final)
- [NIST Software Supply Chain Security Guidance](https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity/software-supply-chain-security-guidance)

While this guidance is directed to Federal agencies, the implementation of these requirements will have a significant impact on companies that supply software to the federal government or products that include software.

## What Can a Software Developer Expect?

While the effective date of the change is September 14, 2022, Federal Agencies are given a timeline by OMB to inventory and identify all software including critical software by mid December 2022.

Agencies are required to communicate with software providers once they identify the software products that they find critical. OMB has placed a very wide definition on software to include the following:

- Firmware
- Operating systems
- Applications
- Applications services (e.g., cloud-based software)
- Products containing software

Companies should be on the lookout for a notification, as the next step for Federal agencies is to require software providers and developers to provide a self-attestation prior to being awarded future federal contracts. Since there is no contract clause for this requirement, companies may see this pop up as a special clause or requirement in a solicitation.

## Where Can I Find the Self-Attestation Form?

A self-attestation form hasn’t been developed yet. The FAR Council is working on developing a uniform standard self-attestation form. But OMB has stated that the self-attestation must include the following information:

- Software Developers name
- Description of product (e.g., product line level)
- Statement that the Software developer follows secure development practices and **tasks** that are itemized in the self-attestation form

## What is a Task?

It is not defined. Companies will need to decipher which practices in the “NIST Guidance” documents are relevant to mitigate threats to the software development practices and include them in their assessment. Hopefully guidance will be included in the self-attestation form that the FAR council is working on.

Companies should be on the lookout for a notification from the government, in which they are providing software or providing products that contain software, before the end of December 2022. If you are notified, pay careful attention to the requirements for a self-attestation as it may be a requirement in a solicitation you are responding to. At the present time, there is no standard attestation form or specific direction to the contractors.

Redstone GCI can provide our clients with more information and guidance in working with established industry leading partners who can assist in fulfilling numerous cybersecurity compliance requirements including but not limited to penetration testing, incident response, security assessments and POA&M revolving around the information technology infrastructure. Redstone GCI along with our trusted partners can bring you a full solution with ensuring cybersecurity policy and flow-down requirements revolving around all aspects are accomplished including but not limited to purchasing policy requirements.

[![Contact Us for a Consultation](https://no-cache.hubspot.com/cta/default/203971/interactive-173774226074.png) ](https://info.redstonegci.com/hs/cta/wi/redirect?encryptedPayload=AVxigLJ5QwYYGsHcSNKJUNL6oNw6t%2BuAxywSoh3d9sOD6xGjtQ3LHLTLKVgZOU0GqOKR14%2FpnvnVtW1bb0tQH%2B2z2Xn8i8CriOR0FTYMxybTJwuSqc0DpzNPcH95F3aNETOCvnr8Hsiw%2BGCosVwtWZ1Wyi36T41n%2Fy77HGWQxlBqZX6gjdf6&webInteractiveContentId=173774226074&portalId=203971)

### Written by [Lynne Nalley, CPA](https://info.redstonegci.com/blog/author/lynne-nalley)

![Lynne Nalley, CPA](https://info.redstonegci.com/hubfs/images/Staff_/Lynne-Nalley.png) Lynne is a Director with Redstone Government Consulting, Inc. providing government contract consulting services to our clients primarily related to Commercial Item Determinations and support, Cost Accounting Standards, DFARS Business System Audits, Proposals, and Incurred Cost. Prior to joining Redstone Government Consulting, Lynne served in several capacities with DCAA and DCMA for over 35 years. Professional Experience Lynne began her career working with DCAA in the Honeywell Resident Office, Clearwater, FL in 1984. Lynne’s experience included various positions which involved conducting or reviewing forward proposals or rate audits, financial capability audits, progress payments, accounting and estimating systems, cost accounting standards, claims and disclosure statement reviews. She is an expert in FAR, DFARS, CAS and testified as an expert witness. Lynne assisted in drafting the commercial item guidance for DCAA Headquarters. Lynne was assigned as a Regional Technical Specialist where she provided guidance to 20 field offices on highly complex or technical issues relative to forward pricing, financial capability or progress payment issues. As an Assistant for Quality, she was involved in reviewing and ensuring audit reports were in compliance with policy and GAGAS as well as made NASBA certified presentations to the staff including but not limited to billing reviews, CAS, unallowable cost and progress payments. To enhance her experience in government contracting, Lynne accepted a position with DCMA in 2015 as part of the newly organized DCMA Cadre of Experts in the Commercial Item Group. This included performing reviews of prime contractor’s assertions and/or commercial item determinations as well as performing price analyses. Lynne was a project lead and later became a lead analyst where she engaged with the buying commands on requests and reviewed price analysis reviews performed by a team of 5 analysts. She also assisted the DCMA CPSR team relative to commercial items and co-instructed the Commercial Item Training presented to DCMA. Education Lynne earned a Bachelor of Science Degree in Accounting from the University of Central Florida. Certifications State of Florida Certified Public Accountant State of Alabama Certified Public Accountant Defense Acquisition Workforce Improvement Act (DAWIA) Level III- Auditing DAWIA Level III – Contracting

## About Redstone GCI

Redstone GCI is a consulting firm focused on fulfilling the needs of government contractors in all areas of compliance. With a singular mission to help contractors through the multiple layers of “red tape,” we allow contractors to focus on what they do best – support their mission with the U.S. Government. We are home to a group of consultants made up of GovCon industry professionals, CPAs, attorneys, and retired government audit and acquisition professionals.

Our focus and knowledge of audit and compliance functions administered by DCAA and DCMA will always be at the heart of what we do. However, for the past decade, we’ve strategically grown to support other areas of the government contractor back-office with that same level of focus and expertise. We’ve added expertise in contracts management, subcontract administration, proposal pricing, various software systems, HR and employment law, property administration, manufacturing, data analytics/reporting, Grant specialists, M&A, and many other areas. When we see a trend in the needs of contractors, we act to ensure we can provide the best expertise in the market to fulfill those needs.

One thing our clients can be certain of is that with the Redstone GCI Team in your corner, there is no problem too big and no issue too technical for our team to tackle.

 Topics: [DFARS Business Systems](https://info.redstonegci.com/blog/topic/dfars-business-systems), [Contractor Purchasing System Review (CPSR)](https://info.redstonegci.com/blog/topic/contractor-purchasing-system-review-cpsr), [Cybersecurity](https://info.redstonegci.com/blog/topic/cybersecurity)

### Search Posts

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

### Subscribe via E-mail

### Latest Posts

### Posts by category

- [Accounting System Compliance (282)](https://info.redstonegci.com/blog/topic/accounting-system-compliance)
- [Commercial Determination (34)](https://info.redstonegci.com/blog/topic/commercial-determination)
- [Contractor Purchasing System Review (CPSR) (85)](https://info.redstonegci.com/blog/topic/contractor-purchasing-system-review-cpsr)
- [Contracts & Subcontracts Administration (300)](https://info.redstonegci.com/blog/topic/contracts-subcontracts-administration)
- [Cost Accounting Standards (CAS) (60)](https://info.redstonegci.com/blog/topic/cost-accounting-standards-cas)
- [COVID-19 (23)](https://info.redstonegci.com/blog/topic/covid-19)
- [Customer Success Story (2)](https://info.redstonegci.com/blog/topic/customer-success-story)
- [Cybersecurity (28)](https://info.redstonegci.com/blog/topic/cybersecurity)
- [DCAA Audit Support (249)](https://info.redstonegci.com/blog/topic/dcaa-audit-support)
- [Defense Procurement & Acquisition Policy (DPAP) (7)](https://info.redstonegci.com/blog/topic/defense-procurement-acquisition-policy-dpap)
- [Deltek Costpoint (54)](https://info.redstonegci.com/blog/topic/deltek-costpoint)
- [DFARS Business Systems (179)](https://info.redstonegci.com/blog/topic/dfars-business-systems)
- [DOD IG (10)](https://info.redstonegci.com/blog/topic/dod-ig)
- [Employee & Contractor Compensation (22)](https://info.redstonegci.com/blog/topic/employee-contractor-compensation)
- [Employers & Unions (8)](https://info.redstonegci.com/blog/topic/employers-unions)
- [Estimating System Compliance (18)](https://info.redstonegci.com/blog/topic/estimating-system-compliance)
- [Export & Import (19)](https://info.redstonegci.com/blog/topic/export-import)
- [Federal Acquisition Regulation (FAR) (187)](https://info.redstonegci.com/blog/topic/federal-acquisition-regulation-far)
- [Federal Construction Contracting (4)](https://info.redstonegci.com/blog/topic/federal-construction-contracting)
- [Government Compliance Training (59)](https://info.redstonegci.com/blog/topic/government-compliance-training)
- [Government Property Management (18)](https://info.redstonegci.com/blog/topic/government-property-management)
- [Government Regulations (265)](https://info.redstonegci.com/blog/topic/government-regulations)
- [Government Shutdown (9)](https://info.redstonegci.com/blog/topic/government-shutdown)
- [Grants & Cooperative Agreements (2 CFR 200) (32)](https://info.redstonegci.com/blog/topic/grants-cooperative-agreements-2-cfr-200)
- [Human Resources (118)](https://info.redstonegci.com/blog/topic/human-resources)
- [Incurred Cost Proposal Submission (ICP/ICE) (83)](https://info.redstonegci.com/blog/topic/incurred-cost-proposal-submission-icp-ice)
- [Litigation Consulting Support (17)](https://info.redstonegci.com/blog/topic/litigation-consulting-support)
- [Manufacturing Operations Consulting (26)](https://info.redstonegci.com/blog/topic/manufacturing-operations-consulting)
- [Material Management & Accounting System (MMAS) (23)](https://info.redstonegci.com/blog/topic/material-management-accounting-system-mmas)
- [Non-US Government Contractor (3)](https://info.redstonegci.com/blog/topic/non-us-government-contractor)
- [Office of Federal Contract Compliance Programs (31)](https://info.redstonegci.com/blog/topic/office-of-federal-contract-compliance-programs)
- [Organizational Change Management Consulting (17)](https://info.redstonegci.com/blog/topic/organizational-change-management-consulting)
- [Paycheck Protection Program (PPP) Loans (8)](https://info.redstonegci.com/blog/topic/paycheck-protection-program-ppp-loans)
- [Program Management & Project Cost Control (2)](https://info.redstonegci.com/blog/topic/program-management-project-cost-control)
- [Proposal Cost Volume Development & Pricing (79)](https://info.redstonegci.com/blog/topic/proposal-cost-volume-development-pricing)
- [Quickbooks (21)](https://info.redstonegci.com/blog/topic/quickbooks)
- [REAs, Claims & Terminations (10)](https://info.redstonegci.com/blog/topic/reas-claims-terminations)
- [Redstone GCI (50)](https://info.redstonegci.com/blog/topic/redstone-gci)
- [Sequestration (4)](https://info.redstonegci.com/blog/topic/sequestration)
- [Service Contract Act (14)](https://info.redstonegci.com/blog/topic/service-contract-act)
- [Small Business Compliance (121)](https://info.redstonegci.com/blog/topic/small-business-compliance)
- [System Award Management (SAM) (9)](https://info.redstonegci.com/blog/topic/system-award-management-sam)
- [UKG Ready HR Software Consulting (7)](https://info.redstonegci.com/blog/topic/ukg-ready-hr-software-consulting)
- [Unanet (35)](https://info.redstonegci.com/blog/topic/unanet)
- [Vlog (41)](https://info.redstonegci.com/blog/topic/vlog)

### Disclaimer

```
Data published on our website, such as our white papers, blogs and other government contracting commentary reflect our interpretations and opinions of current events and regulations, at the time such data is published, and the perspectives/opinions of other professionals in our industry may vary from our own.  Further, our commentary and perspectives do not reflect legal analyses, since we are not attorneys, but rather government contracts and accounting advisors.  We therefore make no representation that the use of our published information will insulate a company from government challenges, nor otherwise ensure a successful defense on any government procurement adverse action.  Readers agree that articles or blog commentary presented within our website shall not be replicated or re-published without requesting before publication in another medium, and our expressed written consent to do so.
```

**Redstone Government Consulting**  
501 Madison Street SE, Suite 100  
Huntsville, AL 35801

**Phone: ** [256.704.9800](tel:2567049800)  
**Email Us**[ info@redstonegci.com](mailto:info@redstonegci.com)

**[PAY INVOICE](https://redstonegci.com/invoice-payment/)**  
[PCI DSS compliance documentation](https://redstonegci.com/wp-content/uploads/2016/10/pci_dss_self_assessment_certificate.pdf)

<http://www.facebook.com/redstonegci> <http://www.twitter.com/RedstoneGCI> <http://www.linkedin.com/company/redstone-government-consulting-inc-> <https://www.youtube.com/channel/UCQv3eAwiPTTQAnoy7hnUwgg>

© 2026 Redstone Government Consulting | All Rights Reserved | [Privacy Policy](https://redstonegci.com/privacy-policy/) | [Event Refund / Cancellation Policy](https://redstonegci.com/event-refund-cancellation-policy/)