Curriculum traceability

NIST SSDF (Secure Software Development Framework)

This matrix shows how each curriculum area maps to NIST SSDF (Secure Software Development Framework)requirements — the clause or control it supports, how it's taught, and the evidence the learner and organisation receive. It's a sample, illustrative mapping; your live records (completions, assessment scores, version history) form the per-organisation evidence pack.

What this supports — and what it doesn't

These programs support preparation for NIST SSDF (Secure Software Development Framework) certification: they deliver the awareness and competence training the standard requires (notably Clause 7.2 Competence, 7.3 Awareness, and Annex A 6.3) and produce the documented completion and assessment records auditors look for. They do notby themselves certify your organisation or any individual, and they don't guarantee certification — your organisation still implements the management system and is audited by an accredited certification body. Training is the supporting evidence, not the certificate.

NIST SSDF Secure Software Development Practitioner

Curriculum areaNIST clauses / controlsMethodEvidence produced
SSDF Foundations + 4 Practice Groups
PO + PS + PW + RV
Lesson + KCCompletion + score
Practices + CISA Attestation
19 practices + 47 tasks
Lesson + KCCompletion + score

Hover a clause code for its title. Clause references follow NIST SSDF (Secure Software Development Framework). For a per-organisation, audit-ready evidence pack, get in touch.