★ Annual Review 2027 tickets now on sale Get your tickets →

News/Cyber & AI/OMB Rescinds the “Common Form” Secure Software Attestation Requirement
Expert Opinion·Cyber & AI Brief

OMB Rescinds the “Common Form” Secure Software Attestation Requirement

Covington – On January 23, 2026, the Office of Management and Budget (OMB) issued Memorandum M-26-05 “Adopting a Risk-based Approach to Software and Hardware Security,” which rescinds a previous Biden Administration’s requirement for all federal agencies to obtain a self-attestation from software producers in the “Common Form” developed by the Cybersecurity and Infrastructure Security Agency (CISA) before using certain third-party software.

🔒 Members Only · Cyber & AI BriefYou’ve reached the member portion of this brief.Members read the full analysis and the source documents in every Brief, six days a week.
Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.