The Problem with "Teaching to-the-test" and Implementing "to-the-scope"
SA-8 Enhancements aggregate as the organization’s overall Engineering Principles Program, Policy, and implementation activity. If this information is scoped exclusively to the needs of a FedRamp PMO's emphasis on assuring the top-level SA-8 control description, and some evidence of Enhancement 33 "Minimization". Implementing "to-the-scope" of an assessment won't accomplish secure and resilient cloud services. Building compliant cloud products mean leveraging all of the applicable best practice guidance associated with the entire Service and Acquisition domain. Software providers should align with NIST's Secure Software Development Framework (SSDF). A robust Cloud Software Development program is a reasonable way to leverage this guidance. The 800-53 points to using the Secure Software Development Framework, SSDF. It falls to the Cloud Offeror to realize that even if this wasn't suggested by their previous year's NIST 171 or FedRAMP audit, this level of tracking will get called as a requirement for earning and maintaining future government contracts.
- Cybersecurity Labeling for Consumer IoT and Software: Executive Order Update and Discussion (December 9, 2021)
- 2nd Public Draft SP 800-161 Revision 1 Workshop (December 1, 2021)
- Executive Order 14028: Guidelines for Enhancing Software Supply Chain Security (November 8, 2021)
- NIST Seeks Comments on Draft Consumer Software Criteria for Labeling (November 1, 2021)
- Draft NIST SP 800-161 Revision 1 (October 28, 2021)
- Improving the Nation’s Cybersecurity: Progress and Next Steps in Carrying Out Executive Order 14028 (October 14, 2021)
- NIST's Secure Software Development Framework (SSDF) Version 1.1 (September 30, 2021)
Given a facilitated GRC system we Shift these compliance targets Left by tagging not only the 33 Enhancements of SA-8, but the array of CIS, DISA, OWASP and other best practices that collectively assure the safety of the entire cloud service environment. It takes a robust system to tag and track the entire Cloud Development Lifecycle. At the very least, we need a product that enables "Select", "Implement", "Assess", "Authorize" and "Monitor" phases of the RMF. For Vendors who need to show their "SBOM" and validation that all components offered are free of vulnerability, an easy choice would be to use a facilitated program such as offered by Security Compass.
The last comment on the example of SA-8, and probably the most significant point about NIST as a body of collective works. NIST intends all control statements as guidance, not taking the place of organic and complete procedures evolved to suit the actual context of organization as they apply reasonable controls to suit their product. Organizations apply a risk framework based on the threats and priorities of their domains of responsibility. Appearing no less than nineteen times in the SP 800-53, NIST states “Simply restating controls does not constitute an organizational policy or procedure.”
“Security controls are seldom put in place as stand-alone solutions to a problem. They are typically more effective when paired with another control or set of controls. Security controls, when selected properly, can have a synergistic effect on the overall security of a system. Each security control in NIST SP 800-53 has a related controls section listing security control(s) that complement that specific control. If users do not understand these interdependencies, the results can be detrimental to the system. [xxxvii]
Another critical dependency between NIST SP 800-53 and May 12, 2021, EO Executive Order on Improving the Nation's Cybersecurity[xxxviii] is the Inspector General FISMA Reporting Measures v1.1 (cisa.gov). [xxxix] System Engineering directly affects Supply Chain Risk. Reading the Inspector General’s evidenced-based assessment guidance it is clear that this SA-8 example is now established by precedent as a necessary marker for a company's achievement of reasonable "defined" maturity.
Question 6. “To what extent does the organization utilize an information security architecture to provide a disciplined and structured methodology for managing risk, including risk from the organization’s supply chain (Federal Information Technology Acquisition Reform Act (FITARA), NIST SP 800-39; NIST SP 800-160; NIST SP 800-37 (Rev. 2) Task P-16; OMB M-19-03; OMB M-15-14, FEA Framework; NIST SP 800-53 Rev. 4: PL-8, SA-3, SA-8, SA-9, SA-12, and PM-9; NIST SP 800-163, Rev. 1 CSF: ID.SC-1 and PR.IP-2; SECURE Technology Act: s. 1326)?”

Figure 2 FY 2021 Inspector General Federal Information Security Modernization Act of 2014 (FISMA) Reporting Metrics Version 1.1 Question 6 page 18 (FY 2021 Inspector General FISMA Reporting Measures v1.1 (cisa.gov))
Conclusion
As the Inspector General and the Federal Acquisition Regulation (FAR) raise scrutiny on all government agency contracts for both the Federal Government and Private sectors, we are increasingly compelled to comply with NIST. NIST supplies industry-led cybersecurity standards, the most widely utilized being the NIST SP 800-53 Rev. 5[xl] Security and Privacy Controls for Federal Information Systems and Organizations. NIST SP 800-53 is the control matrix that references and mediates connection to all of NISTS other products and resources.
NIST requires that any assessment, including those that leverage the SP 800-53, be implemented according to the Risk Management Framework (RMF). Cloud Service Providers (CSP) and Cloud Service Consumers (CSC) share responsibilities to gather or supply an accurate software bill of materials (SBOM), and with that, to acknowledge the detailed level risks associated at every layer and step along each product’s supply chain. The SBOM now ties to the full Cybersecurity Supply Chain Risk Management C-SCRM [xli] and must meet with The United States, Executive Order 14028, Improving the Nation's Cybersecurity.
Organizations can plan, release, and maintain Secure Cloud Products by employing a methodology and facilitated system to Shift Compliance Left. Where the US Supply Chain threat landscape is seen as only tending to a more expansive, dangerous, and complex set of obstacles, the proper use of NIST Standards and products such as Security Compass, SD Elements offers hope.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics