Securing the Software Supply Chain: How SCITT, SPIFFE, and WIMSE Work Together
I’ve been saying that to follow what’s happening in NHI standards, some of the core work you need to follow is happening in the IETF: SPICE, WIMSE, and SCITT. Everybody loves WIMSE with its workload identity architecture, and building the credential format in SPICE that can meet the needs of NHIs is of course brilliant (I’m not biased, you’re biased!). But thinking about this from the bottom up is what SCITT (Supply Chain Integrity, Transparency, and Trust) is all about, and it’s time to learn more about it and its close allies, SPIFFE (which isn’t happening in the IETF) and, yes, WIMSE. (I’ll cover SPICE in a future blog post.)
🎧 Prefer to listen? Here’s the audio version of this post:
First, let’s talk about why you should care.
Whether you’re a vendor or a product manager, modern software is a patchwork of third-party components, open-source libraries, and cloud-based services. A single weak link can undermine the entire system, putting your company’s product and reputation at risk.
That’s where SCITT comes in. By focusing on verifying every step in the software supply chain, it offers vendors the confidence that their components meet security and integrity standards. Customers, too, are demanding greater transparency, and SCITT is working to become a big part in how that happens.
Key Trends Shaping Supply Chain Security
Conversations about software supply chains are becoming almost as exciting as NHI and AI. Probably because NHI and AI depend on a crazy amount of software, each with its own set of potential vulnerabilities. We’re talking about rising threats, high-profile breaches, and increasing regulatory pressure requiring organizations to rethink how they build, deploy, and manage software. To meet these challenges, the industry is rallying around key practices and frameworks that promote transparency, trust, and resilience. Two of the big trends in this space are the adoption of Software Bill of Materials (SBOMs) and the emergence of global legislation driving accountability.
The Rise of SBOMs (Software Bill of Materials)
An SBOM is essentially an ingredient list for your software, showing all the components inside. The EU’s Cyber Resilience Act (CRA) now requires manufacturers to create and maintain SBOMs for digital products, which must be available for regulatory checks. SCITT can simplify this process by integrating verification mechanisms directly into the supply chain.
A Global Push for Legislation
The primary legislative framework in Europe that covers software supply chain security is the Cyber Resilience Act (CRA). Proposed in September 2022, the CRA introduces mandatory cybersecurity requirements for certain products in order to ensure their security throughout the product lifecycle. The CRA is setting the standard for cybersecurity, mandating secure development practices, vulnerability management, and lifecycle security.
Across the pond, U.S. executive orders also demand greater accountability for third-party software providers, emphasizing secure development attestations and artifact validation. There are two particular ones to pay attention to:
- Executive Order on Improving the Nation’s Cybersecurity (May 2021) directing federal agencies to improve the security and integrity of software critical to the government’s ability to function. If you’re interested in the supply chain aspects, see Section 4 Enhancing Software Supply Chain Security.
- Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity (January 2025) has an even bigger section (Section 2) on Operationalizing Transparency and Security in Third-Party Software Supply Chains.
Changes in administration can negate executive orders, but I suspect core elements like the supply chain requirements are going to stick around.
Supply chain security is evolving, but standards like SCITT, SPIFFE, and WIMSE are still finding their place. If you’re figuring out where these fit in your security strategy or how to engage in standards discussions, let’s talk. 👉 See how I help organizations navigate identity standards.
What Is SCITT?
OK, let’s get back to SCITT. At its core, SCITT provides a framework to ensure integrity and transparency in the software supply chain. It’s about cryptographic proofs, signed attestations, and validated processes that make it easier to trust what you’re building and buying.
- SBOM Integration: SCITT enhances the accuracy and traceability of SBOMs.
- Certified Compiler Tracking: It ensures that trusted tools are used throughout the development process.
- Compliance Made Simple: SCITT aligns perfectly with regulations like the CRA, making it easier for vendors to meet evolving standards.
Don’t Forget SPIFFE and WIMSE!
This isn’t directly an IETF thing, but it’s closely related to SCITT: SPIFFE (Secure Production Identity Framework for Everyone). SPIFFE addresses a critical challenge—workload identity in cloud-native environments. Think of it as a way to ensure that during builds and deployments, only the right processes are communicating with each other. No more hardcoded credentials or guessing who’s knocking on the door—SPIFFE ensures every workload has a secure and verifiable identity.
Here’s what SPIFFE brings to the table:
- Workload Authentication: SPIFFE provides dynamic, secure identities for workloads, removing the need for manual credential management.
- Securing CI/CD Pipelines: It locks down your build and deployment environments, ensuring only authenticated processes can interact with sensitive systems.
- Complementing SCITT: Together, SCITT and SPIFFE form a powerful duo, enhancing transparency and security at every stage of the supply chain.
But wait—what about WIMSE, the Workload Identity for Multi-System Environments effort? Does it cover the same ground as SPIFFE? Well, kind of, but not exactly. Here’s the deal:
- WIMSE: Focuses on creating vendor-neutral standards for managing workload identities across diverse systems. It’s about defining best practices and protocols to make sure everyone is playing by the same rules.
- SPIFFE: Provides the frameworks and tools to implement those principles in real-world systems. In other words, SPIFFE is more about the “how,” while WIMSE is about the “what” and “why.”
Chatting with Justin Richer, co-chair of the WIMSE working group, he helped me clarify the difference: SPIFFE is defining the tools for assigning and trusting the identities; WIMSE is defining the protocols and practices around them.
How SCITT, WIMSE, and SPIFFE Fit Together
Here’s how these three puzzle pieces come together to form a strong foundation for modern software supply chains:
- SCITT: Verifies the integrity and transparency of the supply chain through cryptographic proofs and attestations.
- WIMSE: Defines the standards and best practices for managing workload identities, ensuring a consistent approach across environments.
- SPIFFE: Implements those standards with secure, dynamic identities that can be integrated into SCITT workflows.
Together, they ensure:
- Trustworthy SBOMs: By verifying and securing every component in the supply chain.
- Secure Build Environments: Through workload authentication and protection of CI/CD pipelines.
- Compliance with Global Regulations: Aligning with frameworks like the EU’s Cyber Resilience Act (CRA).
Why This Matters to Vendors and Product Teams
Cybersecurity practitioners don’t need to be convinced (I hope) about the importance of the work happening at the supply chain level. I want to make the case, though, that this matters to a much wider audience. While sales engineers and product teams may be ready to dismiss these deep, dark frameworks and standards as theoretical, recognize that SCITT and SPIFFE deliver practical, real-world benefits:
- Building Trust: Customers and regulators increasingly demand transparency. SCITT and SPIFFE ensure your supply chain is secure and verifiable.
- Staying Competitive: Security is no longer a “nice to have.” Vendors who embrace these frameworks gain a clear market edge.
- Reducing Risks: From SolarWinds to open-source vulnerabilities, supply chain attacks are a thing. These tools help mitigate those threats.
- Operational Efficiency: Automating security processes reduces complexity, saving time and resources. There is SO MUCH going on in terms of attacks and defense, automating your security processes is not really optional.
Wrapping It Up
Efforts like SCITT, SPIFFE, and WIMSE might not grab headlines like the latest tech gadgets, but they’re truly critical and live at the foundation of software security. For vendors and product teams, understanding and leveraging these tools is about staying secure, competitive, and ahead of the curve. For me, I’m definitely going to keep my finger on the pulse of what’s happening in the space. My own decisions on what software and services I purchase or recommend will absolutely be influenced by these efforts.
I want to help you go from overwhelmed at the rapid pace of change in identity-related standards to prepared to strategically invest in the critical standards for your business. Follow me on LinkedIn or reach out to discuss my Digital Identity Standards Development Services.
Want my latest blog posts delivered directly to your inbox? Subscribe here—no carrier pigeons required.
