# SA-03 System Development Life Cycle — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/sa-3

Canonical id: `sa-3` · family `SA`

> a. Acquire, develop, and manage the system using [system-development life cycle] that incorporates information security and privacy considerations; b. Define and document information security and privacy roles and responsibilities throughout the system development life cycle; c. Identify individuals having information security and privacy roles and responsibilities; and d. Integrate the organizational information security and privacy risk management process into system development life cycle activities.

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class B
- certification class C
- certification class D

## Key Security Indicators that reach it

- `KSI-PIY-RIS` — Reviewing Investments in Security (Policy and Inventory)
  The effectiveness of the provider's investments in achieving security goals is persistently reviewed.
- `KSI-PIY-RSD` — Reviewing Security in the SDLC (Policy and Inventory)
  The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.

## FedRAMP guidance

_No FedRAMP-specific guidance attaches to this control._
