Loading

Government Customers: Secure Software Development Attestation

Trust Center
  • Product Security
  • Product Safety
  • Enterprise Security
  • Legal & Privacy
  • Security Advisories
  • Security Certifications
RSS Feed

In May 2021, the White House issued the Executive Order on Improving the Nation's Cybersecurity (EO14028), further operationally clarified by OMB Memorandum M-23-16, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices. These directives aimed to strengthen the cyber operational resilience of US Federal agencies by improving cybersecurity standards, public/private information sharing, and software supply chain security. Pursuant to the orders, the National Institute of Standards and Technology (NIST) published NIST Special Publication 800-218 and the NIST Software Supply Chain Security Guidance (collectively the NIST Secure Software Development Framework, or NIST SSDF) providing best practice guidance.

As part of these directives, US Federal agencies are obligated to obtain attestations from software producers detailing the producer's alignment with government guidance. To streamline the attestation process, the US Cybersecurity & Infrastructure Security Agency (CISA) and the Office of Management and Budget (OMB) have produced a common attestation form detailing the required minimum secure development practices.

Rockwell Automation is proud to be a supplier to the US Government and its prime contractors. In support of the relationships and trust built over many years, we embrace the opportunity to attest to the secure software development practices we use to develop our software and firmware products.

Click here to complete a Secure Software Development Attestation request.

Frequently Asked Questions

Are these attestations solely for US Federal agencies?
Chevron DownChevron Down

To ensure timely attestation delivery, we are limiting attestations to the US Federal agencies.

Can I request an attestation for any Rockwell Automation Software or Firmware product?
Chevron DownChevron Down

The government attestation directives apply to software released or modified with major changes after September 14, 2022. The same directives also remove freely available products from the scope of attestation. We are limiting attestations to products with a lifecycle status of “Active” or “Active Mature.” You can learn more about Rockwell Automation’s Product Lifecycle Status here.

  1. Chevron LeftChevron Left Rockwell Automation Home Chevron RightChevron Right
  2. Chevron LeftChevron Left Trust Center Chevron RightChevron Right
  3. Chevron LeftChevron Left Government Customers: Secure Software Development Attestation Chevron RightChevron Right
Please update your cookie preferences to continue.
This feature requires cookies to enhance your experience. Please update your preferences to allow for these cookies:
  • Social Media Cookies
  • Functional Cookies
  • Performance Cookies
  • Marketing Cookies
  • All Cookies
You can update your preferences at any time. For more information please see our {0} Privacy Policy
CloseClose
OSZAR »