
What the document says
OMB Memorandum M-26-05, Adopting a Risk-based Approach to Software and Hardware Security, was signed by OMB Director Russell T. Vought on 23 January 2026. It rescinds two Biden-administration memoranda, M-22-18 and its companion M-23-16, which had required federal agencies to obtain a standardised, government-wide self-attestation from software producers before using their products, based on practices in NIST's Secure Software Development Framework. The memo's own text describes the prior approach as imposing unproven, burdensome accounting processes that prioritised compliance paperwork over security investment, and as neglecting risks posed by insecure hardware, which the earlier policy did not cover.
The memo does not eliminate agencies' responsibility for software and hardware assurance. It states that each agency head remains ultimately responsible for the security of software and hardware permitted on that agency's network, and directs agencies to keep a complete inventory and develop their own risk-based assurance policies rather than following one standard checklist. Agencies may still use the resources built under M-22-18, including the Secure Software Development Attestation Form that CISA released in March 2024, on a voluntary basis, and may adopt contract terms requiring a current software bill of materials on request.
Confidence and limits
This entry is based on the memo's own text, obtained directly, together with CISA's page describing the form the memo makes optional. What remains uncertain is how individual agencies will exercise the discretion the memo grants them, since a risk-based approach applied inconsistently across dozens of agencies could produce different practical outcomes than the uniform mandate it replaces.
Why it mattered
The rescinded attestation requirement traced back to Executive Order 14028, issued after the SolarWinds compromise, and represented one of the first attempts to standardise how the federal government verified a software vendor's development practices at scale. Removing the mandate does not restore the pre-2022 status quo, since agencies retain the underlying inventory and risk-assessment duties, but it does end the single common form vendors could once satisfy across the federal government, shifting that burden back toward per-agency negotiation, as reported by Nextgov/FCW.
Defensive takeaway
If you sell software to federal agencies, expect to be asked for assurance evidence on a per-agency basis rather than through one standard form, and keep your secure development documentation and any software bill of materials ready to produce on request rather than assuming the attestation form alone will satisfy every buyer.
- Does your agency have a documented, risk-based software and hardware assurance policy now that the standardised attestation mandate is gone?
- If you are a software vendor, can you still produce a current software bill of materials on request even though it is no longer mandated?
- Has your organisation reviewed NIST SP 800-218 directly, rather than relying on the now-optional attestation form as a proxy for secure development practice?
M-26-05 changes the mechanism for federal software assurance, not the underlying expectation that agencies must know what they are running and manage its risk; the memo is explicit that this remains each agency head's responsibility.
If your agency relied on the standardised attestation form as its sole software assurance control, confirm what replaces it under your own risk-based policy, since the underlying inventory framework and the option to request a software bill of materials are still available even though the mandate is gone.
The memo itself was read directly and establishes exactly what it rescinds and what it leaves in place. Outside commentary is used only for reaction and context, not as the basis for any factual claim about the memo's content.
Sources & reading trail
Full text confirming the rescission of M-22-18 and M-23-16 and what agencies must still do.
government-primary · Source published: 23 January 2026 · Retrieved: 16 September 2026
Describes the attestation form created under M-22-18 that M-26-05 makes optional rather than mandatory.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Context and reaction, including the OMB Director's stated rationale, corroborating the memo's own text.
reputable-original-reporting · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.