New NIST NCCoE Resources on DevSecOps and October 28 Webinar on Agentic AI
The NIST National Cybersecurity Center of Excellence (NCCoE) has published additional resources from the Secure Software Development, Security, and Operations (DevSecOps) Practices project to the live document. The new content includes:
- A mapping of the NIST Secure Software Development Framework (SSDF) to the DevSecOps notional reference model.
- Details on the second example implementation, which focuses on Continuous Integration and Continuous Delivery (CI/CD) pipeline automation and containerized application deployment.
- Functional scenarios demonstrating activities performed during each phase of the software development lifecycle (SDLC).
- An appendix highlighting the key objectives and implementation practices of each SSDF task implemented by the project.
- The Artificial Intelligence section of the DevSecOps notional reference model, which has been updated to reflect recent observations.
Additionally, the NCCoE will be hosting a webinar on October 28, 2026, to discuss this live document, provide updates on the project, and share more about plans for using Agentic AI in DevSecOps. Visit the NCCoE event page to register today!
Background
The NCCoE is collaborating with 14 technology companies to demonstrate how to implement the security practices and tasks from the NIST Secure Software Development Framework (SSDF) using modern DevSecOps pipelines and commercially available technologies.
Through example implementations, the project explores how to build more secure software and reduce vulnerabilities, including emerging considerations such as artificial intelligence and zero trust.
Artificial Intelligence (AI) and DevSecOps
As modern software development increasingly incorporates AI capabilities, the DevSecOps project is exploring the cybersecurity implications of using AI throughout the software development lifecycle. While Build 2 showcases human-directed generative AI, the project is now scoping Build 3 to demonstrate the use of agentic AI capabilities to develop, build, and test code.
In support of Build 3, the DevSecOps and Software and AI Agent Identity and Authorization teams will work together on a single implementation to demonstrate how AI agents can be identified, authenticated, and authorized within the SDLC. The DevSecOps environment will provide the first implementation use case for the AI Agent Identity and Authorization project.
Register Now: Upcoming Webinar
Join us on October 28th at 1:00 P.M. EDT for an NCCoE DevSecOps Practices Project update, including a presentation on the scope of Agentic AI within Build 3, followed by a panel discussion with NCCoE industry collaborators on the role of agentic AI in DevSecOps.
Webinar attendees will have the opportunity to engage with both NCCoE project teams and our participating collaborators. Visit the event page and register today!
We Want Your Feedback!
The recently updated sections of the live document listed above are open for public comment until November 9, 2026. To submit comments, use the comment template on the NCCoE project page.