Inside Cybersecurity

October 6, 2025

Daily News

Tech group seeks clarification on attestation alignment, provenance definition in latest draft of secure software common form

By Sara Friedman / December 19, 2023

The Information Technology Industry Council wants the Cybersecurity and Infrastructure Security Agency to provide details on how it plans to align requirements and define “provenance,” following the release of the second draft common form for contractors to self-attest the security of their software offerings.

CISA and the Office of Management and Budget in April published the first version of the form for public comment. Several groups and individual companies submitted comments to CISA on the draft form identifying...


Log in to access this content.


Not a subscriber? Sign up for 30 days free access to exclusive news and analysis on cybersecurity regulations and more.