NIST SP 800-218A, published on July 26, 2024, is a community profile of the Secure Software Development Framework (SSDF, SP 800-218 version 1.1) for generative AI and dual-use foundation models. It augments the SSDF's practices and tasks with recommendations, considerations, notes and informative references specific to AI model development across the software development life cycle, and is meant to be used together with SP 800-218 rather than in its place. Its stated audience is producers of AI models, producers of AI systems that use those models, and acquirers of those systems, which for a bank means both the teams building on foundation models and the functions that buy AI-enabled software. It was one of the July 2024 deliverables under Executive Order 14110, alongside the AI 600-1 Generative AI Profile, and remains a standing NIST publication.
OFFICIAL TEXT: csrc.nist.gov ↗ · IN FORCE · NIST
| Document | NIST SP 800-218A (SSDF profile for generative AI) — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (NIST SP 800-218A) |
| Issued by | National Institute of Standards and Technology — AI Risk Management Framework |
| Type | Framework |
| Status | In force |
| Published | Jul 26, 2024 |
| Effective | Jul 26, 2024 |
| Applies to | Voluntary; producers of AI models, producers of AI systems that use those models, and acquirers of those systems — for banks, the teams building on foundation models and the vendor-management and application-security functions that buy them |
| Official source | csrc.nist.gov ↗ |
| Use cases | AI-generated code & coding agents · Cybersecurity · Third-party & vendor AI · Generative & agentic AI |
What are the key points of NIST SP 800-218A (SSDF profile for generative AI)?
- Published July 26, 2024 as a companion to SP 800-218 (SSDF v1.1); augments, does not replace, the SSDF's four practice groups — prepare the organization, protect the software, produce well-secured software, respond to vulnerabilities.
- Adds AI-specific practices, tasks, recommendations and informative references covering model development throughout the life cycle: training data provenance and integrity, model and weight protection, evaluation, and secure integration of models into systems.
- Written for three audiences: AI model producers, producers of systems that use AI models, and acquirers of those systems — so it is a procurement checklist as well as an engineering one.
- One of the Executive Order 14110 deliverables released with the AI 600-1 Generative AI Profile; the Order has since been revoked but the profile stands as a NIST publication.
- For banks it is the reference point when secure-development standards are extended to AI components and to code produced with AI assistance — the practice New York DFS asked regulated entities to put under human review in May 2026.
What did NIST SP 800-218A (SSDF profile for generative AI) change for banks?
It gave application-security and vendor-management teams a NIST-numbered basis for extending the SSDF to AI model development and integration, at the moment regulators began asking how AI-generated and AI-integrated software is reviewed before deployment.
Does SP 800-218A replace the SSDF?
No. It is a community profile that augments SSDF version 1.1 with AI-specific content and is meant to be used in conjunction with SP 800-218.
Who is SP 800-218A for?
Producers of AI models, producers of AI systems that use those models, and acquirers of those AI systems — in a bank, both the engineering teams building on foundation models and the functions that procure AI-enabled software.
| Date | Document | Status |
|---|---|---|
| Apr 7, 2026 | AI RMF critical-infrastructure profile (concept note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure | Proposed |
| Jan 12, 2026 | CAISI RFI on AI agent security (2026) — Request for Information: Security Considerations for Artificial Intelligence Agents | Proposed |
| Dec 16, 2025 | NIST IR 8596 (Cyber AI Profile) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft | Proposed |
| Aug 14, 2025 | NIST COSAiS control overlays — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI | Proposed |
| Mar 24, 2025 | NIST AI 100-2e2025 (Adversarial ML) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) | Final |
| Jul 26, 2024 | NIST AI 600-1 (Generative AI Profile) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) | In force |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning