CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software | CISA
Skip to main content
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Staying Secure at Eventsno-cost Cyber Servicessecure your businessKnown Exploited Vulnerabilities CatalogReport A Cyber Issue
Share:
Opens in a new window
Opens in a new window
Opens in a new window
Press Release
CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software
Tailored Guidance to Use and Understand OSS Solutions, Contribute to and Produce Projects, and Evaluate AI Models
Released<br>July 30, 2026
Related topics:
Cybersecurity Best Practices
WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) published Open Source Software: Security Principles and Practices, a new resource for federal agencies with considerations and best practices to use and assess Open Source Software (OSS) solutions, contribute to projects, produce OSS, and evaluate open source artificial intelligence (AI) models. The guidance aligns with Executive Order 14144 that highlights the benefits of OSS for federal agencies, and Executive Order 14306 that directs federal networks to be more secure and better manage their use of OSS. Exploits like log4shell and xz utils underscore the need for agencies to understand the dependencies embedded within their software components.<br>Across the federal government and in every critical infrastructure sector, OSS is a widely used and critical building block in our software supply chain. Many federal agencies use OSS to improve capacity and efficiency that enables them to better fulfill their mission. With this guide, CISA urges agencies to establish a process to review and approve OSS that supports staff in using solutions that best meet their needs while still managing risks. The guidance includes established principles for patching, a framework to evaluate trustworthiness and risk tolerance, and best practices to engage with OSS securely, responsibly and sustainably.<br>“As part of our statutory mission, CISA remains laser-focused on enhancing the nation's cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,” said Acting Executive Assistant Director for Cybersecurity Chris Butera . “CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.”<br>For open source AI systems, the guidance urges agencies to obtain sufficient transparency into all relevant components, including training data, of the AI system before deeming the product as OSS for risk management purposes. Only with transparency and access can agencies understand and study the software, analyze it for vulnerabilities, and remediate any found vulnerabilities or risks.<br>For more information, visit Open Source Security on CISA.gov.
Related Articles
Jul 29, 2026
Press Release
CISA and Partners Unveil Updated Software Bill of Materials Resource That Improves Transparency, Security and Risk-Informed Decision Making
Jul 28, 2026
Press Release
CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure
Jul 23, 2026
Press Release
CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity
Jul 22, 2026
Press Release
CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers