Advancing Secure Software Pipelines: NIST NCCoE DevSecOps Build 2 and Palo Alto Networks Contribution to Identity and Secrets Security

Oct 05, 2026
2 minutes

The successful completion of Build 2 marks another significant milestone for the NIST National Cybersecurity Center of Excellence (NCCoE) Secure Software Development, Security, and Operations (DevSecOps) Practices project. Palo Alto Networks, now strengthened by our integration with Idira (formerly CyberArk), is proud to contribute our combined, expanded expertise to Example Implementation 2 (E2), developed together with Microsoft, DigiCert, Sagittal AI, GitLab, Resilience Cyber Security (formerly Scribe Security), and NextLabs, further raising the bar for modern, secure software delivery benchmarks.

While Build 1 laid the ground rules for shifting security left and automating defensive checks across CI/CD workflows, Build 2 tackles one of the most critical attack vectors in modern software development: identity, secrets, and access management across dynamic environments.

By embedding NIST Secure Software Development Framework (SSDF) practices directly into pipeline execution, Build 2 demonstrates how organizations can systematically protect non-human identities, credentials, and privileged access, enabling software pipelines to remain resilient from code creation to cloud deployment. Within this multi-vendor architecture, Palo Alto Networks contribution centers on certificate lifecycle management, secrets governance, and code signing.

Key Takeaways from Example Implementation 2 (E2)

Build 2 establishes an actionable blueprint for integrating identity security and secrets governance directly into automated build systems:

  • Secrets and Machine Identity Governance: Modern CI/CD pipelines rely heavily on service accounts, API keys, and automated tokens. Build 2 shows how Next-Gen Trust Security (formerly CyberArk's Certificate Manager), Secrets Hub, Secrets Manager, Privilege Cloud, and Machine Identity Security work together to manage certificates, rotate credentials, and safeguard privileged access, eliminating the attack surface created by hardcoded secrets.
  • Automated Secrets Governance without Velocity Loss: Security shouldn't slow down release cycles. By automating secret rotation and certificate lifecycle management within automated builds, and pairing them with GitLab's CI/CD automation, developers can maintain rapid delivery speeds while upholding robust security controls.
  • Certificate Lifecycle and Code Signing Integrity: Build 2 relies on Next-Gen Trust Security to automate certificate issuance and renewal and to sign build artifacts, source code, and container images, giving teams a verifiable chain of trust from commit to deployment without manual certificate handling.

As software supply chains become increasingly targeted, Palo Alto Networks remains dedicated to our collaboration with the NIST NCCoE and our fellow collaborators. Together, we are building practical, referenceable architectures that empower organizations to innovate safely and secure the global software supply chain.