Compliance & Regulations
In-depth guides and analysis on compliance & regulations from the Safeguard engineering team.
18 articles
Federal SBOM Mandate: Compliance Deadlines and What They Mean for Vendors
Federal agencies are tightening SBOM requirements for software suppliers. Here's what vendors need to know about compliance deadlines, attestation requirements, and practical implementation.
CISA's Secure by Default: Shifting Responsibility to Software Manufacturers
CISA's Secure by Design guidance pushes software vendors to ship secure defaults and take ownership of customer security outcomes, fundamentally changing the security responsibility model.
EU Cyber Resilience Act: Impact on Software Developers and Open Source
The EU's Cyber Resilience Act will impose mandatory cybersecurity requirements on all software sold in Europe. Here's what developers need to know.
CISA Secure by Design Principles: What They Mean for Software Teams
CISA's Secure by Design initiative shifts security responsibility from users to manufacturers. Here's what it means for how you build software.
SBOM Requirements for Medical Devices: FDA's New Mandate
The FDA now requires software bill of materials for medical device submissions. Here's what manufacturers need to know about compliance.
The SBOM Maturity Model: A Practical Roadmap for Enterprise Adoption
Most organizations are still at SBOM Level 0. Here's a five-level maturity model to guide your journey from no SBOMs to full supply chain transparency.
CISA Self-Attestation Form: What Software Producers Need to Know
OMB M-22-18 requires software producers selling to the federal government to self-attest to secure development practices. Here's what's required.
The Open Source Software Security Act of 2022: What It Means for Developers
The U.S. Senate introduced legislation directing CISA to secure open source software used by the federal government. Here's what the bill contains.
NIST CSF Updates Put Supply Chain Risk Management Front and Center
NIST's 2022 updates to the Cybersecurity Framework signal a major shift: supply chain risk management is no longer optional — it's a core pillar.
CISA SBOM Guidance: What Government Agencies Need to Know
CISA's evolving SBOM requirements are reshaping how government agencies procure and manage software. Here's what the guidance says and how to operationalize it.
NIST SP 800-218 (SSDF) Final Publication: What It Means for Your Organization
NIST finalized the Secure Software Development Framework in February 2022. If you sell software to the US government — or plan to — compliance is no longer optional.
Open Source License Compliance: A Practical Guide for 2022
License compliance is not just a legal checkbox — it is a business risk. Misunderstanding copyleft obligations or violating attribution requirements can result in lawsuits, forced code disclosure, or product recalls.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.