Supported compliance standards
CIS Software Supply Chain Security benchmark
The CIS Software Supply Chain Security benchmark provides prescriptive guidance for establishing a secure configuration posture for Software Development Platforms and Pipelines.
CIS Benchmarks are best practices for the secure configuration of a target system. In this case, the target system is the software supply chain.
OWASP Software Component Verification Standard
The Software Component Verification Standard (SCVS) is a community-driven effort to establish a framework for identifying activities, controls, and best practices, which can help in identifying and reducing risk in a software supply chain.
OpenSSF FLOSS
The OpenSSF FLOSS Best Practices is a set of recommendations from the Open Source Security Foundation (OpenSSF) Best Practices Working Group to help open source developers create and maintain more secure software.
The best practices criteria are divided into three levels, for an incremental adoption:
-
Passing focuses on best practices that well-run FLOSS projects typically already follow. Getting the passing badge is an achievement; at any one time only about 10% of projects pursuing a badge achieve the passing level.
-
Silver is a more stringent set of criteria than passing but is expected to be achievable by small and single-organization projects.
-
Gold is even more stringent than silver and includes criteria that are not achievable by small or single-organization projects.
OpenSSF Scorecard
OpenSSF Scorecards is an automated tool that assesses a number of important heuristics ("checks") associated with software security and assigns each check a score of 0-10. You can use these scores to understand specific areas to improve in order to strengthen the security posture of your project. You can also assess the risks that dependencies introduce, and make informed decisions about accepting these risks, evaluating alternative solutions, or working with the maintainers to make improvements.
ESF Securing the Software Supply Chain DEV
The ESF Securing the Software Supply Chain - Recommended Practices for Developers is a set of guidelines aimed at improving the security of software development by reducing the risk of supply chain attacks.
The set of recommend principles are framed in 5 top-level sections:
-
Secure product criteria and management
-
Develop Secure Code
-
Verify Third-Party Components
-
Harden the Build Environment
-
Deliver Code
By following these guidelines, software developers can reduce the risk of supply chain attacks and ensure the security and integrity of their software.
NIST IR 8547 PQC Transition
Maps a project’s cryptographic inventory to the NIST IR 8547 post-quantum transition timeline: quantum-vulnerable (Shor-broken) public-key cryptography is deprecated from 2030 and disallowed after 2035, built on a cryptographic inventory (CBOM) as the prerequisite for planning the migration.
NSA CNSA 2.0 (Post-Quantum)
Maps a project’s cryptographic inventory to the NSA CNSA 2.0 timeline for national security systems: post-quantum algorithms are to be the default by 2030 and the exclusive option by 2033, with hybrid classical+PQC constructions not approved for NSS.
EU PQC Roadmap
Maps a project’s cryptographic inventory to the EU coordinated post-quantum transition roadmap: governance and inventory from 2026, high-risk use cases migrated by 2030, all systems by 2035, with hybrid classical+PQC constructions encouraged during the transition.
PCI DSS 4.0 PQC
PQC-scoped view of PCI DSS 4.0: requirement 12.3.3 mandates a documented, periodically reviewed cryptographic cipher-suite inventory. PCI DSS sets no post-quantum deadline, so quantum-vulnerable cryptography is surfaced as advisory migration debt rather than a dated failure.
DORA PQC
PQC-scoped view of the EU Digital Operational Resilience Act (Regulation (EU) 2022/2554). DORA’s ICT risk-management framework requires cryptographic controls and a key-management/encryption policy — implying a cryptographic inventory. DORA sets no post-quantum deadline, so quantum-vulnerable cryptography is surfaced as advisory migration debt.
NIS2 PQC
PQC-scoped view of the EU NIS2 Directive (Directive (EU) 2022/2555). Article 21(2)(h) requires policies and procedures on the use of cryptography and encryption — implying a cryptographic inventory. NIS2 sets no post-quantum deadline, so quantum-vulnerable cryptography is surfaced as advisory migration debt.