SSDF
The Secure Software Development Framework describes practices for building software securely, organised so they can be referenced in contracts and attestations.
Its significance is largely that it has become the vocabulary for demanding secure development from suppliers, particularly where government procurement is involved. It says what practices should exist rather than how to implement them in any given toolchain.
Checked against the primary source.
