The NCCoE has released updates to its Secure Software Development, Security, and Operations (DevSecOps) Practices project live document. This release introduces several new components to the project. We are requesting feedback on the new components listed below:
- A mapping of the NIST Secure Software Development Framework (SSDF) to the DevSecOps notional reference model.
- Details on the second example implementation, which focuses on Continuous Integration and Continuous Delivery (CI/CD) pipeline automation and containerized application deployment.
- Functional scenarios demonstrating activities performed during each phase of the software development lifecycle (SDLC).
- An appendix highlighting the key objectives and implementation practices of each SSDF task implemented by the project
- The Artificial Intelligence section of the DevSecOps notional reference model, which has been updated to reflect recent observations.
The public comment period for the publication is open through November 9, 2026. Use the comment template below to submit your feedback.
Additionally, join us for a webinar on October 28, 2026 where the team will discuss this live document, provide updates on the project, and share more about plans for using Agentic AI in DevSecOps.
To view the full live document, use the button below.