Standards Crosswalk
Where these controls map onto ISO 27002, SSDF, PCI DSS, SOC 2, ISO 42001, and the EU instruments.
Practice identifiers in the SSDF column follow Secure Software Development Framework version 1.1, which remains the operative final version; a draft revision was released for comment in December 2025 and had not been finalized as of August 2026.97 Note that the generative AI community profile reintroduces practice PW.3 with an entirely new meaning—confirming the integrity of training, testing, fine-tuning, and aligning data—where SSDF 1.1 has no PW.3 at all.10 Citing PW.3 without naming the document is a common and avoidable error.
| This framework | NIST SSDF (800-218 / 218A) | ISO/IEC 42001 / 5338 | EU AI Act | Other |
|---|---|---|---|---|
| S1Planning | PO.1, PO.2 | 42001 Cl. 6, A.2, A.3; 5338 organizational project-enabling processes | Art. 9 (risk management) | CRA Art. 13; FinOps Framework |
| S2Requirements | PO.1, PW.1 | 42001 A.6 (requirements and specification); 5338 stakeholder and system requirements definition | Arts. 9, 10, 13 | ISO/IEC 27002 8.26 |
| S3Design | PW.1, PW.2, PW.4 | 42001 A.6 (design and development); 5338 architecture and design definition | Arts. 9, 14, 15 | ISO/IEC 27002 8.27; MITRE ATLAS; OWASP Agentic Top 10 |
| S4Development | PW.5, PW.6, PW.7, PS.1 | 42001 A.6; 5338 implementation | Art. 15 | ISO/IEC 27002 8.28, 8.31; PCI DSS 6.2; SLSA Source Track; OWASP NHI Top 10 |
| S5Verification | PW.7, PW.8, RV.1 | 42001 A.6 (verification and validation); 5338 verification, validation, continuous validation | Arts. 9, 15 | ISO/IEC 27002 8.29, 8.33; NIST AI 800-2; NIST AI 100-2e2025 |
| S6Release | PS.2, PS.3, PW.9 | 42001 A.6 (deployment); 5338 transition | Arts. 11, 12, 16 | ISO/IEC 27002 8.32; SLSA Build Track; CISA SBOM minimum elements; CRA Annex I |
| S7Operations | PO.5, RV.1, RV.2, RV.3 | 42001 A.6 (operation and monitoring, event logging); 5338 continuous validation | Arts. 12, 15, 26 | CRA Art. 14 reporting; SOC 2 CC7; OTel GenAI conventions |
| X1Identity | PO.2, PO.5 | 42001 A.3, A.4 | Art. 14 | OWASP NHI Top 10; NCCoE agent identity project |
| X2Provenance | PS.1, PS.2, PS.3, PW.4 | 42001 A.10 (third-party relationships) | Arts. 11, 12 | SLSA; in-toto; Sigstore; CycloneDX / SPDX; CISA AI SBOM elements |
| X3Evaluation | PW.8, RV.1 | 42001 A.6; 5338 continuous validation | Arts. 9, 15 | NIST AI 800-2; NIST AI RMF MEASURE |
| X4Governance | PO.1–PO.4 | 42001 Cl. 4–10, A.2, A.3, A.5 | Arts. 14, 17, 26 | SOC 2 CC1–CC5, CC8; DORA RTS Arts. 15–17; ISO/IEC 42005 |
22.1 Regulatory Notes #
Four points where a framework drafted earlier in 2026 would now be wrong, and one where the underlying assumption is worth stating.
The EU AI Act’s high-risk obligations have been deferred. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on July 8, 2026 and entered into force on July 27, 2026.94 It moved the Chapter III high-risk obligations for Annex III stand-alone systems from August 2, 2026 to December 2, 2027, and for Annex I product-embedded systems from August 2, 2027 to August 2, 2028, citing delayed availability of harmonised standards and delayed designation of national competent authorities. As of August 2026 the binding obligations are the prohibited practices and AI literacy requirements in force since February 2025, the general-purpose AI obligations in force since August 2025, and the Article 50 transparency obligations in force since August 2, 2026. Any framework asserting that Articles 9 through 15 currently bind Annex III providers is wrong by roughly sixteen months. Plan against the deferred dates; do not claim they are current.
The US federal software attestation mandate was rescinded. OMB Memorandum M-26-05, issued January 23, 2026, rescinded the memoranda that created the government-wide secure software self-attestation requirement.95 The attestation form and the SSDF remain available and are now optional, with agencies setting tailored risk-based requirements. The SSDF survives as guidance rather than as a procurement condition. This is a material change for anyone whose control rationale rested on a federal mandate.
The Cyber Resilience Act’s reporting obligations begin imminently. Reporting for actively exploited vulnerabilities and severe incidents applies from September 11, 2026, with full application on December 11, 2027.46 Manufacturers must maintain an SBOM covering at least top-level dependencies, publish a coordinated vulnerability disclosure policy, and define a support period. It is the first regime to make secure development practice a market access condition.
Sector regimes were drafted without agents in contemplation, and the regulator’s position will be that existing obligations apply unchanged. The DORA regulatory technical standards require testing and approval of all systems before production use, source code review covering both static and dynamic testing, non-production environments containing only anonymised or pseudonymised production data, and independence between the approving and implementing functions.4 PCI DSS requires pre-release review of bespoke and custom code, and where that review is manual, a reviewer other than the originating author; automated review is permitted as an alternative.2 The FDA’s predetermined change control plan is the only instrument among these that pre-authorizes a bounded envelope of future autonomous change, and it is worth studying as the closest available regulatory precedent for governing systems that modify themselves after release.96
The underlying assumption. Where an agent acts on regulated data or systems, document the mapping explicitly rather than waiting for guidance. Regulators are unlikely to accept that an obligation lapsed because the party performing the work was not a person.
References cited in this section
8 of 243 · numbering matches the PDF
- 97Murugiah Souppaya, Karen Scarfone, and Donna Dodson, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities, NIST Special Publication 800-218 (Gaithersburg, MD: NIST, February 2022). Version 1.1 remains the operative final version; a draft revision (SP 800-218r1, SSDF 1.2) was released for comment in December 2025 and had not been finalized as of August 2026.doi.org/10.6028/NIST.SP.800-218 ↗
- 10Harold Booth et al., Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile, NIST Special Publication 800-218A (Gaithersburg, MD: NIST, July 2024).doi.org/10.6028/NIST.SP.800-218A ↗
- 94European Parliament and Council, Regulation (EU) 2026/1744 of July 8, 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI), OJ L, 2026. Entered into force July 27, 2026.eur-lex.europa.eu/eli/reg/2026/1744/oj/eng ↗
- 95Office of Management and Budget, Adopting a Risk-Based Approach to Software and Hardware Security, OMB Memorandum M-26-05 (Washington, DC: Executive Office of the President, January 23, 2026). Rescinds M-22-18 and M-23-16. Note that the CISA attestation form page had not been updated to reflect the rescission as of August 2026.
- 46European Parliament and Council, Regulation (EU) 2024/2847 of October 23, 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), OJ L, November 20, 2024. See also European Commission, "Cyber Resilience Act Reporting Obligations,". The final report is due within fourteen days for an actively exploited vulnerability and within one month for a severe incident.digital-strategy.ec.europa.eu/en/policies/cra-reporting ↗
- 4European Commission, Commission Delegated Regulation (EU) 2024/1774 of March 13, 2024 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying ICT risk management tools, methods, processes and policies, OJ L, 2024. Articles 15–17 govern ICT project management, systems acquisition and development, and change management.
- 2PCI Security Standards Council, Payment Card Industry Data Security Standard: Requirements and Testing Procedures, v4.0.1 (Wakefield, MA: PCI SSC, June 2024). Requirement 6.2.3 governs pre-release review of bespoke and custom code; 6.2.3.1 governs manual review, requiring a reviewer other than the originating code author and management approval.
- 96U.S. Food and Drug Administration, Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions, guidance for industry and FDA staff (Silver Spring, MD: FDA, December 2024). Final. A companion lifecycle management guidance issued January 6, 2025 remains in draft.