Federal compliance frameworks — EO 14028, CMMC, DISA STIGs, FedRAMP, NIST 800-171 — collectively contain hundreds of controls. A significant subset targets software development directly: how code is built, tested, scanned, packaged, and deployed. This article catalogs those requirements framework by framework, with specific practice IDs and control numbers.