Secure Controls Framework
Download The SCF

What Are Secure Development Requirements?

Secure Software Development
Secure Code Alliance (SCA) Contributor
•
August 12, 2026

From a day-to-day perspective of requirements for Secure Software Development Practices (SSDP), there are “industry-recognized secure practices” that require secure software development. These frameworks impact nearly every organization, regardless of the industry it serves.

EO 14028, Sec. 4 - Software Supply Chain Security

EO 14028 includes requirements for enhancing software supply chain security:

  • (A) Using administratively separate build environments.
  • (D) Documenting and minimizing dependencies on enterprise products that are part of the environments used to develop, build, and edit software.
  • (F)(ii) Generating and, when requested by a purchaser, providing artifacts that demonstrate conformance to the processes set forth in subsection (e)(i) of this section.
  • (F)(iii) Employing automated tools, or comparable processes, to maintain trusted source code supply chains, thereby ensuring the integrity of the code.
  • (F)(ix) Attesting to conformity with secure software development practices.
  • (F)(x) Ensuring and attesting, to the extent practicable, to the integrity and provenance of open source software used within any portion of a product.

NIST SP 800-171 Rev 3

NIST SP 800-171 Rev 3 contains requirements for secure development practices:

  • 03.04.01 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
  • 03.13.02 Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
  • 03.13.13 Control and monitor the use of mobile code.

Center for Internet Security (CIS)

CIS version 8 contains requirements for secure development practices:

  • 16.1 Establish and Maintain a Secure Application Development Process.
  • 16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities.
  • 16.7 Use Standard Hardening Configuration Templates for Application Infrastructure.
  • 16.9 Train Developers in Application Security Concepts and Secure Coding.
  • 16.10 Apply Secure Design Principles in Application Architectures.
  • 16.11 Leverage Vetted Modules or Services for Application Security Components.

Payment Card Industry Data Security Standard (PCI DSS)

PCI DSS version 4 covers bespoke and custom software development:

  • 6.2.2 Software development personnel working on bespoke and custom software are trained at least once every 12 months on software security relevant to their job function and development languages, including secure software design and secure coding techniques.
  • 6.2.3 Bespoke and custom software is reviewed prior to being released into production or to customers, to identify and correct potential coding vulnerabilities. Code reviews ensure code is developed according to secure coding guidelines and look for both existing and emerging software vulnerabilities.
  • 6.2.4 Software engineering techniques are defined and in use to prevent or mitigate common software attacks (injection, XSS/CSRF, business logic abuse, access control bypass, cryptographic weakness, and high-risk vulnerabilities).
  • 6.3.1 Security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including CERT alerts.
  • 6.3.2 An inventory of bespoke and custom software, and third-party software components incorporated into bespoke and custom software, is maintained to facilitate vulnerability and patch management.
  • 6.5.6 Test data and test accounts are removed from system components before the system goes into production.