Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Civilian

OMB Memo Calls for Risk-Based Approach to Software Security

by Jane Edwards
January 27, 2026
in Civilian, Government Technology, News
Office of Management and Budget logo. OMB’s new memo calls for agencies to adopt a risk-based approach to software security.

The Office of Management and Budget has issued a memorandum directing federal agencies to adopt a risk-based approach to software and hardware security by implementing secure development principles and comprehensive risk assessments.

The Office of Management and Budget has issued a memorandum directing federal agencies to adopt a risk-based approach to software and hardware security by implementing secure development principles and comprehensive risk assessments.

Table of Contents

    • You might also like
    • DIA Expands AI, OSINT Efforts for Cyber Intelligence Missions
    • DIU Launches Specular MIST Prize Challenge for Maritime Payloads
    • DOW Releases TINA Lite Policy & Implementation Guide
  • Why Did OMB Rescind the Previous Software Security Policies?
  • What Software & Hardware Security Actions Does the OMB Memo Require?

You might also like

DIA Expands AI, OSINT Efforts for Cyber Intelligence Missions

DIU Launches Specular MIST Prize Challenge for Maritime Payloads

DOW Releases TINA Lite Policy & Implementation Guide

OMB Memo Calls for Risk-Based Approach to Software Security

As federal guidance on software and hardware security continues to evolve, stakeholders across government and industry are closely watching how these changes may shape future priorities. To connect with peers and stay engaged in broader cybersecurity discussions, register now for the Potomac Officers Club’s 2026 Cyber Summit on May 21.

Why Did OMB Rescind the Previous Software Security Policies?

In a memo published Friday, OMB Director Russell Vought ordered the rescission of two prior OMB policies, stating that they prioritized compliance over security and imposed burdensome software accounting requirements.

OMB Memorandum M-22-18, introduced by the previous administration in September 2022, sought to strengthen the software supply chain through secure software development practices. However, Vought said the policy “diverted agencies from developing tailored assurance requirements for software and neglected to account for threats posed by insecure hardware.”

OMB also rescinded a companion policy, Memorandum M-23-16, issued in June 2023. That memo reaffirmed secure software development practices and extended deadlines for agencies to collect security attestations from software providers.

What Software & Hardware Security Actions Does the OMB Memo Require?

According to the latest OMB guidance, agencies should continue to maintain complete inventories of their software and hardware and develop assurance policies and processes that align with their risk determinations and mission needs.

Agencies may choose to use the Secure Software Development Attestation Form and other governmentwide resources established under M-22-18. 

The memo also allows agencies to incorporate contractual terms requiring software producers to provide a current software bill of materials upon request.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19

Recommended For You

DIA Expands AI, OSINT Efforts for Cyber Intelligence Missions

by Jane Edwards
July 13, 2026
Defense Intelligence Agency seal. DIA is expanding its use of AI and OSINT to support cybersecurity missions.

DIA has expanded its cyber intelligence capabilities through a new centerLeidos has highlighted AI applications for cyber analysis workflowsThe 2026 Intel Summit will explore OSINT, AI and cybersecurity...

Read moreDetails

DIU Launches Specular MIST Prize Challenge for Maritime Payloads

by Miles Jamison
July 13, 2026
DIU logo. The Defense Innovation Unit has launched the Specular MIST Prize Challenge.

DIU has launched a $5 million competition to accelerate new maritime payload technologiesThe Specular MIST Prize Challenge focuses on autonomous containerized systems for manned and unmanned vesselsSelected participants...

Read moreDetails

DOW Releases TINA Lite Policy & Implementation Guide

by Jane Edwards
July 13, 2026
Department of War seal. DOW has released the first version of its TINA Lite Policy and Implementation Guide.

DOW has issued the TINA Lite guide preview The guide details acquisition planning and approval stepsThe Potomac Officers Club will host two DOW summits this summerThe Department of War...

Read moreDetails

GAO Urges VA to Complete Disability Claims Modernization Efforts

by Miles Jamison
July 13, 2026
VA seal. The Department of Veterans Affairs has not resolved persistent disability compensation and technology challenges.

GAO said longstanding management and technology issues continue despite VA modernization effortsEarlier reviews found weaknesses in contractor exam oversight and claims processor trainingThe watchdog said stronger planning and...

Read moreDetails

CAS Board Finalizes Rule Aligning 4 Cost Accounting Standards With GAAP

by Kristen Smith
July 13, 2026
OMB logo. The OMB board said the final rule on four CAS aims to lower barriers for nontraditional contractors.

The rule, effective Aug. 7, rescinds CAS 408 and 411 in full and most of CAS 404 and 409It eliminates 68 of the 72 requirements in the four...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!