OMB Rescinds the “Common Form” Secure Software Attestation Requirement

Covington – On January 23, 2026, the Office of Management and Budget (OMB) issued Memorandum M-26-05 “Adopting a Risk-based Approach to Software and Hardware Security,” which rescinds a previous Biden Administration’s requirement for all federal agencies to obtain a self-attestation from software producers in the “Common Form” developed by the Cybersecurity and Infrastructure Security Agency (CISA) before using certain third-party software.
🔒 Members Only · Cyber & Privacy BriefYou’ve reached the member portion of this brief.Members read the full analysis and the source documents in every case digest, six days a week.
$750/year
