Software teams have never shipped code faster. In the 2025 Stack Overflow Developer Survey, 84% of respondents said they use or plan to use AI tools in their development process, and 51% of professional developers use them daily. However, more developers distrust the accuracy of AI tools (46%) than trust it (33%).
That gap between adoption and confidence is where risk lives. AI can produce working code in seconds, but working and secure are not the same thing. Secure Software Development Practices (SSDP) are how an organization closes that gap, and in the age of AI they matter more than ever.
Secure Software Development Practices (SSDP) are the habits, controls and checkpoints that build security into software from the first design decision to the last patch, instead of bolting it on after release. The most widely referenced baseline is the NIST Secure Software Development Framework (SSDF), SP 800-218. It organizes practices into four groups:
NIST SP 800-218 also maps SSDF practices to the Section 4e clauses of Executive Order (EO) 14028, which the SCA covers in an earlier post on EO 14028.
CISA's Secure by Design initiative makes the same case from the business side: customer security should be "a core business requirement, not just a technical feature," and products should be secure to use out of the box.
The framework is also evolving for AI. In July 2024, NIST published SP 800-218A, an SSDF Community Profile that adds practices specific to generative AI and dual-use foundation models.
Veracode's 2026 GenAI Code Security Report, which has tracked more than 100 models, puts the average security pass rate at 56%, virtually unchanged from the prior year. Nearly all generated code compiles, which makes insecure code easy to accept. Even the best model tested still fails nearly one in three security tasks. Veracode notes the tests ran against raw models, not agents or production environments.
When code arrives faster than people can read it, review becomes the bottleneck, and bottlenecks get skipped. Mandatory code review, automated security testing, and clear ownership keep speed from turning into exposure.
AI assistants suggest dependencies as readily as they write functions. A USENIX Security 2025 study of 16 code-generating models found that 19.7% of the packages they're commended did not exist. Attackers can exploit this by publishing malicious packages under those names, so every suggested package needs the same scrutiny as one a developer chose.
Teams that build AI features into their products take on new failure modes. Prompt injection tops the OWASP Top 10 for LLM Applications2025, and OWASP notes that "it is unclear if there are fool-proof methods of prevention." That makes design and testing discipline more important, not less.
Requirements are moving in both directions. On 23 January 2026, OMB Memorandum M-26-05 removed the requirement for federal agencies to use the CISA Secure Software Development Attestation Form, replacing it with agency-specific, risk-based decisions that still point to the NIST SSDF. In the EU, obligations grew: since 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents under the Cyber Resilience Act, starting with an early warning within 24 hours. Either way, the goal is to be secure and compliant, not just compliant. That depends on knowing what is in your code and who changed it, which is exactly what secure development practices produce.
You do not need a new program to respond to AI. You need toapply the discipline you already know to a faster, noisier workflow:
Leadership sets the tone. CISA calls on technology providers to shift the burden of security by "claiming ownership of their customers' security outcomes." The Secure Code Alliance (SCA) helps developers, architects, and their organizations show that they know and apply SSDP, and the free SCA Body of Knowledge (SCA-BoK) is a practical place to start. Prove your code is secure. Prove your team is, too.
What are secure software development practices? Secure software development practices are the processes and controls that build security into every phase of the software lifecycle. The NIST SSDF groups them into four areas: prepare the organization, protect the software, produce well-secured software, and respond to vulnerabilities.
Is AI-generated code secure? Not by default. Veracode's 2026 testing found an average security pass rate of 56% for AI models, even though nearly all of the generated code compiled. Treat AI output as untrusted until it has been reviewed and tested.
Does the NIST SSDF cover AI? Yes. NIST SP 800-218A, published in July 2024, is an SSDF Community Profile that adds practices for generative AI and dual-use foundation models. It is meant to be used alongside SP 800-218, not in place of it.
Why do secure development practices matter for compliance? Regulations such as the EU Cyber Resilience Act require manufacturers to report actively exploited vulnerabilities, with an early warning due within 24 hours as of 11 September 2026. Secure development practices create the component inventory, traceability, and response process those obligations depend on.
Do federal agencies still require the secure software attestation form? Not government-wide. OMB Memorandum M-26-05, issued on 23 January 2026, removed the requirement to use the CISA Secure Software Development Attestation Form. Agencies may still request an attestation or a software bill of materials (SBOM) based on their own risk assessment, and the memo points them to the NIST SSDF.
• StackOverflow, 2025 Developer Survey: AI
• NIST,SP 800-218: Secure Software Development Framework (SSDF) Version 1.1 (Feb 2022)
• NISTCSRC, SSDF project overview (four practice groups; EO 14028 Section 4e mapping)
• NIST,SP 800-218 Rev. 1 initial public draft: SSDF Version 1.2 (Dec 2025)
• Veracode,2026 GenAI Code Security Report press release (28 Jul 2026)
• Spracklen etal., "We Have a Package for You!" USENIX Security 2025 (arXiv)
• OWASP,Top 10 for LLM Applications 2025
• OWASP,LLM01:2025 Prompt Injection
• Covington,Inside Government Contracts: OMB rescinds the Common Form attestationrequirement (Feb 2026)
• MayerBrown, OMB Rescinds Biden-Era Software Security Memoranda (18 Feb 2026)
• Ireland NCSC, EUCyber Resilience Act
• Secure Code Alliance,Security Mindset
• SecureCode Alliance, SSDP Under EO 14028 and NIST SP 800-171 R3 (30 Jan 2026)
• Secure Code Alliance,CSCAP and CSCAPsyllabus v2025.2 (PDF)
• SecureCode Alliance, SCA-BoK