Skip to content
    Back to Regulatory Radar
    ImportantGuidanceApril 13, 2023

    CISA Launches Secure by Design Initiative via Joint International Guidance

    CISA, together with the FBI, NSA, and international partners including the UK NCSC, Australian ACSC, and Canadian Cyber Centre, published Shifting the Balance of Cybersecurity Risk: Security-by-Design and -Default Principles, formally launching the Secure by Design initiative and calling on software manufacturers to take ownership of customer security outcomes. An expanded joint guide followed in October 2023. On May 8, 2024, CISA added a voluntary Secure by Design Pledge for enterprise software manufacturers, initially signed by 68 companies, committing to seven goals: increased MFA adoption, reduction of default passwords, reduction of entire classes of vulnerability, increased customer installation of security patches, published vulnerability disclosure policies, transparent CVE reporting, and giving customers evidence of intrusions. More than 370 companies have since signed.

    NIST CSFSOC 2HITRUSTSaaSDefenseHealthcareFinTech

    Key Analytics

    April 13, 2023
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    3
    Frameworks Affected

    Impact Analysis

    The Secure by Design initiative shifted compliance expectations from solely the customer to shared responsibility with software vendors. Assessors and enterprise buyers increasingly reference Secure by Design and pledge alignment in vendor risk assessments, giving organizations evaluating SaaS vendors a public benchmark for vendor security maturity. The initiative's themes align with the supply chain risk management emphasis in NIST CSF 2.0 and with the 2023 National Cybersecurity Strategy's push to shift liability toward software producers. The pledge remains voluntary and non-binding, with over 370 signers listed by CISA as of mid-2026. Defense contractors face additional scrutiny around the security posture of their software supply chain.

    Recommended Actions

    • Evaluate your organization's alignment with the seven Secure by Design Pledge goals
    • Incorporate Secure by Design criteria into vendor risk assessment questionnaires and scoring
    • Publish or update your vulnerability disclosure policy to align with CISA guidance

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Low20-50 hours
    Key Workstreams
    • Self-assessment against the seven pledge goals with an owner per goal
    • Vulnerability disclosure policy refresh to align with CISA guidance
    • Secure by Design criteria added to vendor assessment scoring

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowLow · 20-50 hours
    Start cold under pressureModerate · 50-110 hours

    Roughly 30 to 60 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events