CISA Launches Secure by Design Initiative via Joint International Guidance
CISA, together with the FBI, NSA, and international partners including the UK NCSC, Australian ACSC, and Canadian Cyber Centre, published Shifting the Balance of Cybersecurity Risk: Security-by-Design and -Default Principles, formally launching the Secure by Design initiative and calling on software manufacturers to take ownership of customer security outcomes. An expanded joint guide followed in October 2023. On May 8, 2024, CISA added a voluntary Secure by Design Pledge for enterprise software manufacturers, initially signed by 68 companies, committing to seven goals: increased MFA adoption, reduction of default passwords, reduction of entire classes of vulnerability, increased customer installation of security patches, published vulnerability disclosure policies, transparent CVE reporting, and giving customers evidence of intrusions. More than 370 companies have since signed.
Key Analytics
Impact Analysis
The Secure by Design initiative shifted compliance expectations from solely the customer to shared responsibility with software vendors. Assessors and enterprise buyers increasingly reference Secure by Design and pledge alignment in vendor risk assessments, giving organizations evaluating SaaS vendors a public benchmark for vendor security maturity. The initiative's themes align with the supply chain risk management emphasis in NIST CSF 2.0 and with the 2023 National Cybersecurity Strategy's push to shift liability toward software producers. The pledge remains voluntary and non-binding, with over 370 signers listed by CISA as of mid-2026. Defense contractors face additional scrutiny around the security posture of their software supply chain.
Recommended Actions
- Evaluate your organization's alignment with the seven Secure by Design Pledge goals
- Incorporate Secure by Design criteria into vendor risk assessment questionnaires and scoring
- Publish or update your vulnerability disclosure policy to align with CISA guidance
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Self-assessment against the seven pledge goals with an owner per goal
- ›Vulnerability disclosure policy refresh to align with CISA guidance
- ›Secure by Design criteria added to vendor assessment scoring
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 30 to 60 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.