| SA-17(6) | System and Services Acquisition | Structure for Testing |
| SA-17(7) | System and Services Acquisition | Structure for Least Privilege |
| SA-17(8) | System and Services Acquisition | Orchestration |
| SA-17(9) | System and Services Acquisition | Design Diversity |
| SA-18 | System and Services Acquisition | Tamper Resistance and Detection |
| SA-18(1) | System and Services Acquisition | Multiple Phases of System Development Life Cycle |
| SA-18(2) | System and Services Acquisition | Inspection of Systems or Components |
| SA-19 | System and Services Acquisition | Component Authenticity |
| SA-19(1) | System and Services Acquisition | Anti-counterfeit Training |
| SA-19(2) | System and Services Acquisition | Configuration Control for Component Service and Repair |
| SA-19(3) | System and Services Acquisition | Component Disposal |
| SA-19(4) | System and Services Acquisition | Anti-counterfeit Scanning |
| SA-2 | System and Services Acquisition | Allocation of Resources |
| SA-20 | System and Services Acquisition | Customized Development of Critical Components |
| SA-21 | System and Services Acquisition | Developer Screening |
| SA-21(1) | System and Services Acquisition | Validation of Screening |
| SA-22 | System and Services Acquisition | Unsupported System Components |
| SA-22(1) | System and Services Acquisition | Alternative Sources for Continued Support |
| SA-23 | System and Services Acquisition | Specialization |
| SA-24 | System and Services Acquisition | Design For Cyber Resiliency |
| SA-3 | System and Services Acquisition | System Development Life Cycle |
| SA-3(1) | System and Services Acquisition | Manage Preproduction Environment |
| SA-3(2) | System and Services Acquisition | Use of Live or Operational Data |
| SA-3(3) | System and Services Acquisition | Technology Refresh |
| SA-4 | System and Services Acquisition | Acquisition Process |
| SA-4(1) | System and Services Acquisition | Functional Properties of Controls |
| SA-4(10) | System and Services Acquisition | Use of Approved PIV Products |
| SA-4(11) | System and Services Acquisition | System of Records |
| SA-4(12) | System and Services Acquisition | Data Ownership |
| SA-4(2) | System and Services Acquisition | Design and Implementation Information for Controls |
| SA-4(3) | System and Services Acquisition | Development Methods, Techniques, and Practices |
| SA-4(4) | System and Services Acquisition | Assignment of Components to Systems |
| SA-4(5) | System and Services Acquisition | System, Component, and Service Configurations |
| SA-4(6) | System and Services Acquisition | Use of Information Assurance Products |
| SA-4(7) | System and Services Acquisition | NIAP-approved Protection Profiles |
| SA-4(8) | System and Services Acquisition | Continuous Monitoring Plan for Controls |
| SA-4(9) | System and Services Acquisition | Functions, Ports, Protocols, and Services in Use |
| SA-5 | System and Services Acquisition | System Documentation |
| SA-5(1) | System and Services Acquisition | Functional Properties of Security Controls |
| SA-5(2) | System and Services Acquisition | Security-relevant External System Interfaces |
| SA-5(3) | System and Services Acquisition | High-level Design |
| SA-5(4) | System and Services Acquisition | Low-level Design |
| SA-5(5) | System and Services Acquisition | Source Code |
| SA-6 | System and Services Acquisition | Software Usage Restrictions |
| SA-7 | System and Services Acquisition | User-installed Software |
| SA-8 | System and Services Acquisition | Security and Privacy Engineering Principles |
| SA-8(1) | System and Services Acquisition | Clear Abstractions |
| SA-8(10) | System and Services Acquisition | Hierarchical Trust |
| SA-8(11) | System and Services Acquisition | Inverse Modification Threshold |
| SA-8(12) | System and Services Acquisition | Hierarchical Protection |