Secure Software Delivery for Federal Environments Module 6 · Toward Continuous

Name What You Practice

Last reviewed · content updated

Advanced

What you'll learn

~15 min
  • Map an estate's existing practices to SSDF tasks and SLSA levels without padding
  • Explain why the risk-based acquisition world makes the named mapping MORE valuable, not less
  • Produce the mapping artifact that answers federal questionnaires from evidence
ℹLeadership brief

What it is: an afternoon’s mapping of the practices your pipelines already perform onto the frameworks buyers and agencies ask for by name - SSDF (NIST’s secure-development practices) and SLSA (the build-integrity ladder) - with honest grades and evidence links.

What it buys: the software-development and supply-chain sections of buyer questionnaires answered from one maintained page instead of from scratch each time; credit in risk-based federal reviews for work already done; a document every line of which a reviewer can verify.

What to fund: an afternoon’s work with an AI CLI and the artifacts, for an estate that already produces them, plus the discipline to claim the floor and name the delta rather than round up.

The strange absence

Here’s an observation from this training’s reference corpus that should sound familiar by now: a shop practicing verified artifact promotion, provenance digests on builds, pinned dependencies with review, secret scanning, two-person change control — with not one mention of SSDF, SLSA, or the DevSecOps reference designs anywhere in its documentation. The estate practices NIST’s Secure Software Development Framework, substantially meets SLSA build-level requirements (SLSA — Supply-chain Levels for Software Artifacts, the 0-to-3 ladder for how trustworthy a build is), and independently reinvented chunks of the federal reference architecture — all unnamed. (The DevSecOps training’s capstone found the identical pattern in its own estate and taught the naming move from the delivery side — Evidence as a Push Pipeline; this lesson is the same move from the federal side, where the stakes changed in 2026.)

Unnamed practice is invisible practice: procurement questionnaires (the two that most vendors will meet are the SIG and the CAIQ — standardized security questionnaires from Shared Assessments and the Cloud Security Alliance), buyer security reviews, and federal solicitations ask for frameworks by name, and “we do that, we just never called it that” is an answer you only get to give if you’re in the room. Usually you’re a PDF in a stack.

Why the 2026 turn raises the stakes

The federal acquisition world’s turn (4.4) — risk-based, agency-owned assurance; blanket attestation collection replaced by attestation-as-one-tool; SBOM-on-request — gets misread as “the compliance pressure is off.” Read it again from the evaluator seat you trained in 4.1: agencies now decide for themselves what assurance to require, per procurement, per risk. A named, evidenced practice mapping is exactly the artifact that answers a risk-based inquiry — and in a world without a fixed checklist, the vendor who shows up with the mapping sets the frame of the conversation. Attestation-optional doesn’t mean assurance-optional; it means the burden of legibility moved to you, and legibility is cheap if your machinery is real.

There’s a second reader, too: the destination platform’s intake (4.3) and the cATO triad’s process leg (4.2) both ask, in their own vocabularies, “is your delivery process disciplined?” A framework mapping written once answers all three audiences — questionnaire, intake, triad — from the same evidence.

The mapping, done honestly

The method is an afternoon with your AI CLI, and its discipline is entirely in what you refuse to claim:

Map our estate against SSDF practice groups and SLSA build levels:
1) inventory what we DO from artifacts, not aspirations: pipeline
configs, branch policies, evidence models, the coverage table
(3.1), the store's trust-model page (3.2), Module 5's transfer
controls;
2) for each SSDF task: our practice, the EVIDENCE MODEL that proves
it (name the query, not the vibe), and a five-value honest grade
where coverage is partial - the Zero Trust training's grading vocabulary:
PARTIAL (works, but scoped narrower than the requirement),
PARTIAL-WITH-DEFECTS (covers it, operates defectively - defects listed),
NONE (not implemented, say so), INHERITED (a platform or provider
control - name it), NOT-APPLICABLE (with the reason on record); a plain
checkmark is reserved for rows you fully own and can evidence. Each
value names WHO owns the gap;
3) SLSA: which build level our provenance and isolation actually
meet - claim the level the evidence supports, note what the next
level would require, claim nothing between levels;
4) emit frameworks-we-practice.md: one page, each claim pointing at
an evidence model or a repo path, gaps listed with owners - the
difference between this and marketing is that every line is a
query someone can run.

Grade-honestly is load-bearing for a reason this training has now taught three times: this document will be read by professional skeptics (an assessor, an intake reviewer, an agency evaluator), and one padded claim converts the whole page from evidence into marketing — after which every honest line pays the discount too. The gap statement (6.1), the trust-model page (3.2), the coverage table (3.1), and this mapping are the same genre: calibrated claims, voluntarily surfaced, mechanically checkable. That genre is this training’s real deliverable.

🔍Framework versions and the attestation status quo (volatile - verify before citing)

As of August 2026: SSDF is NIST SP 800-218 (the base framework; a community-profile ecosystem grows around it). SLSA v1.x is the current line - build-track levels are the ones with teeth; claim by evidence. The government-wide posture is M-26-05 (January 2026): risk-based, agency-owned, attestation optional as a tool, SBOM-on-request - the withdrawn blanket-attestation FAR case (March 2026) confirmed the direction. DoD-side, the SBOM-diff expectations from 4.2 continue independent of any single program’s status. If a new administration memo, an SSDF revision, or a SLSA major lands after this date, re-run the mapping prompt against the current text - the method survives; the citations rotate.

KNOWLEDGE CHECK

Running the mapping, Meridian's team finds their pipeline meets every requirement of a SLSA build level except one: provenance is generated but not yet signed by the build platform. The draft says 'SLSA Level 2 (approximately)'. What does the honest-mapping discipline require instead?

Practice status — among mature regulated delivery programs, commercial and federal

(a few rows carry a more specific status - principle, canon, suspended - where one of the five would mislead)

PracticeStatusAlso called
frameworks-we-practice mappingstrong optionalcontrol crosswalk
SSDF (NIST SP 800-218)federal-referenced framework what solicitations ask for by name—
SLSA build levelsstrong optional claim the floor, name the delta—
five-value honest gradingstrong optionalimplementation-status scale (this site’s convention, from the Zero Trust training)
standard questionnaires (SIG, CAIQ)common baseline what commercial buyers send—

Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging

Key takeaway

Your machinery already practices frameworks it never names — and the risk-based acquisition turn made the named, evidenced mapping more valuable, not less: agencies define assurance per-procurement now, and the vendor who arrives with frameworks-we-practice.md sets the frame. Map from artifacts, grade with the honest vocabulary, claim the floor and name the delta with owners — every line a runnable query. It is the same genre as the gap statement and the trust-model page: calibrated, volunteered, checkable. One lesson left: sequencing the whole journey.

LEADERSHIP DECISION fund the afternoon that produces frameworks-we-
practice.md - it answers a year of questionnaires and
sets the frame in every risk-based review
PRACTITIONER ACTION map practices to SSDF tasks and SLSA levels from
artifacts, grade honestly, claim the floor and name the
delta with owners
SUCCESS MEASURE the SSDF and SLSA sections of a questionnaire turned
around in hours from the mapping, not days from scratch;
zero padded claims surfaced by a reviewer; every line a
runnable check
Search lessons