DoD Developer’s Guidebook for Software Assurance

SEI Report
This guidebook helps software developers for DoD programs understand expectations for software assurance and standards and requirements that affect assurance.
Publisher

Software Engineering Institute

CMU/SEI Report Number
CMU/SEI-2018-SR-013
DOI (Digital Object Identifier)
10.1184/R1/12367262.v1

Abstract

Software assurance refers to the justified confidence that software functions as intended and is free of vulnerabilities throughout the product lifecycle. While "free of vulnerabilities" is the ideal, in practice the objective is to manage the risk associated with vulnerabilities. To that end, this guidebook helps software developers understand expectations for software assurance. Because developers need to be aware of the regulatory background in which their projects operate, this guidebook summarizes standards and requirements that affect software assurance decisions and provides pointers to key resources that developers should consult. It includes a summary of the State-of-the-Art Resources (SOAR) for Software Vulnerability Detection, Test, and Evaluation report, along with its approach for selecting tools. A bottom-up approach to tool selection is also provided, which considers what activities and tools are typically appropriate at different stages of the development or product lifecycle. Advice is provided for special lifecycle considerations, such as new development and system reengineering, and metrics that may be useful in selecting and applying tools or techniques during development are discussed. Special sections are devoted to assurance in software sustainment and software acquisition. Supplemental materials are provided in the appendices.

Cite This SEI Report

Nichols, B., & Scanlon, T. (2018, December 14). DoD Developer’s Guidebook for Software Assurance. (SEI Report CMU/SEI-2018-SR-013). Retrieved September 11, 2026, from https://doi.org/10.1184/R1/12367262.v1.

@techreport{nichols_2018,
author={Nichols, Bill and Scanlon, Tom},
title={DoD Developer’s Guidebook for Software Assurance},
month={Dec},
year={2018},
number={{CMU/SEI-2018-SR-013},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/12367262.v1},
url={https://doi.org/10.1184/R1/12367262.v1},
note={Accessed: 2026-Sep-11}
}

Nichols, Bill, and Tom Scanlon. "DoD Developer’s Guidebook for Software Assurance." (CMU/SEI-2018-SR-013). Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, December 14, 2018. https://doi.org/10.1184/R1/12367262.v1.

B. Nichols, and T. Scanlon, "DoD Developer’s Guidebook for Software Assurance," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, SEI Report CMU/SEI-2018-SR-013, 14-Dec-2018 [Online]. Available: https://doi.org/10.1184/R1/12367262.v1. [Accessed: 11-Sep-2026].

Nichols, Bill, and Tom Scanlon. "DoD Developer’s Guidebook for Software Assurance." (SEI Report CMU/SEI-2018-SR-013). Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 14 Dec. 2018. https://doi.org/10.1184/R1/12367262.v1. Accessed 11 Sep. 2026.

Nichols, Bill; & Scanlon, Tom. DoD Developer’s Guidebook for Software Assurance. CMU/SEI-2018-SR-013. Software Engineering Institute. 2018. DOI: 10.1184/R1/12367262.v1. https://doi.org/10.1184/R1/12367262.v1