The Office of Management and Budget issued Memorandum M-26-05 on January 23, 2026, formally rescinding two Biden era memoranda that had required federal agencies to obtain secure software development attestations from software producers before deploying their products.

The rescinded documents, M-22-18 and M-23-16, had established a common form attestation process mandating that software vendors certify compliance with NIST Special Publication 800-218 Secure Software Development Framework practices. M-26-05 characterizes those requirements as having “imposed unproven and burdensome software accounting processes that prioritized compliance over genuine security investments.”

Under the new framework, agencies adopt a risk based approach to software security. They may still contractually require SBOMs from producers, but the mandate is gone. Where agencies choose to require SBOMs from cloud service providers, M-26-05 specifies they should request bills covering the “runtime production environment” hosting actual government data rather than development or test systems.

Resources developed under M-22-18, including the Secure Software Development Attestation Form, remain available for voluntary use. The shift gives agencies flexibility to tailor security requirements to their risk profiles while removing a uniform compliance burden that critics argued consumed vendor resources without proportionally improving actual software security.