Policy

CISA Releases New Binding Directive on Secure Software Development Practices

CISAMarch 16, 20262 min read
CISA Releases New Binding Directive on Secure Software Development Practices

The Cybersecurity and Infrastructure Security Agency issued a new binding operational directive requiring federal agencies to adopt memory-safe programming languages and mandatory SBOM requirements by Q4 2026.

CISA reports the details above as part of its ongoing coverage in the policy space. The picture is likely to sharpen over the coming days as other researchers weigh in.

For security teams, the practical question is always the same: what changes because of this? Policy sets the floor for security programmes and carries real penalties. Confirm which obligations apply to you and where the current gaps are.

Follow the source link below for the full report and any indicators of compromise the original authors have published.

Related articles