🚀 Submit a Challenge — SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

NIST SSDF · SP 800-218 edition

NIST SSDF Secure Coding Challenges

NIST's Secure Software Development Framework requires role-based secure coding training (PO.2) and defines exactly what "well-secured" source code, review and testing look like (PW.4–PW.9). It's the baseline behind Executive Order 14028's self-attestation for anyone selling software to the U.S. federal government.

Ready when the auditor asks

Generate Your NIST SSDF Training Report

Every completed challenge rolls up into a NIST SSDF training report. Point and click to generate it, then hand it straight to your auditor, customer or partner the moment they ask for evidence.

Capability, not checkbox compliance

Hands-On Challenges for Every Category

NIST SP 800-218 organizes secure development into four practice groups. "Prepare the Organization" (PO.2) requires role-based training for developers, testers and architects before they touch a secure SDLC. "Produce Well-Secured Software" (PW) is where that training gets applied: reusing vetted components, writing code to secure practices, reviewing it, testing it, and configuring it securely by default. Every challenge below is a real vulnerability mapped to a PW practice. Developers fix it without breaking functionality, and every verified fix is evidence your organization can point to for an EO 14028 self-attestation or a federal software supply-chain review.

Satisfying PO.2 role-based training

OWASP Top 10 Course

Role-based secure coding training for developers, testers and architects, the practice SSDF's "Prepare the Organization" group (PO.2) asks for before any of PW.4 through PW.9 can be applied.

Start the Course
Roll it out

Turn the Standard Into a Training Program

Assign these challenges to your team as learning pathways, track verified fixes, and report NIST SSDF coverage to auditors, customers and the board, with evidence, not attendance sheets.