A detailed technical breakdown of what US federal compliance frameworks (EO 14028/NIST SSDF, DISA STIGs, CMMC Level 2/NIST 800-171, FedRAMP, FISMA, ITAR) actually require from software build pipelines. The post catalogs specific controls per framework with their technical implementations, then synthesizes cross-cutting SDLC
Table of contents
The landscapeEO 14028 and the NIST Secure Software Development FrameworkDISA STIGs: container and DevSecOps requirementsCMMC Level 2 and NIST 800-171FedRAMP: the SA, SR, CM, RA, and SI familiesFISMA and ITAR: peripheral fitWhat addressing these requirements looks likeHow Lunar fitsSort: