Panel Discussion: Managing Risk and Compliance in a Shifting Federal Landscape (W03b)
As U.S. federal software supply chain policy continues to evolve, contractors and developers are facing a maze of changing compliance mandates. This panel brings together cybersecurity, legal, and policy experts to unpack the implications of NIST SP 800-218 and related frameworks‚ and how recent Executive Order 14306 may rewrite the rules. Panelists will address the practical realities of meeting secure software development expectations, including beyond-SBOM approaches, attestation rollbacks, and aligning with FedRAMP, CMMC, and global supply chain security models. Whether you’re a software vendor, integrator, or compliance lead, this panel will provide clarity on how to stay ahead of certification risks in a fast-moving environment. Topics for Discussion:
- Key principles and requirements of NIST SP 800-218 (Secure Software Development Framework)
- Understanding the intent and impact of Executive Order 14306 on attestation and NIST guidance
- The shifting role of SBOMs in federal compliance‚ what’s required vs. what’s useful
- How to demonstrate conformance with NIST 800-218, NIST 800-171r3, and CMMC
- FedRAMP as a baseline: What else is needed to meet broader supply chain expectations?
- Legal, operational, and architectural challenges of secure-by-design mandates
- Anticipating future changes in third-party risk, vendor assurance, and global software supply chain regulation
- Best practices for government contractors managing multiple overlapping frameworks




