
What the document says
On 2 March 2023, the White House released the National Cybersecurity Strategy. The accompanying fact sheet organised it around five pillars: defending critical infrastructure, disrupting and dismantling threat actors, shaping market forces to drive security, investing in a resilient future, and forging international partnerships. The central move sits inside the third pillar, which calls for shifting liability for software products and services onto vendors to encourage secure development, rather than leaving that burden with the user who installs a patch. The fact sheet frames this as rebalancing responsibility away from individuals, small businesses and local governments and onto the organisations it describes as most capable and best positioned to reduce risk.
An early piece of implementation followed through the Cybersecurity and Infrastructure Security Agency's Secure by Design guidance, which asks manufacturers to take ownership of security outcomes at the executive level and ship products with protections such as multi-factor authentication and logging included rather than sold as add-ons. As retrieved on 16 September 2026, the page describes a voluntary pledge that more than 200 companies have joined, built around measurable, if self-reported, goals.
The strategy did not remain the government's only framing for long. A March 2026 document, described in contemporary legal analysis as a much shorter framework, took a different position, emphasising common-sense regulation and warning against reducing cyber defence to a compliance checklist, in place of the 2023 emphasis on mandatory baselines and liability shifts.
Confidence and limits
The 2023 strategy's content and framing come directly from the White House's own release. The description of the 2026 document rests on legal-industry analysis, since the underlying PDF could not be rendered for this record; the contrast between the two documents should be read as reported rather than independently verified line by line.
Why it mattered
Software liability had been discussed in policy circles for years without a government committing to the idea in a strategy document. Naming it plainly gave agencies and standards bodies a reference point for guidance such as Secure by Design, and gave software buyers a document to cite when asking vendors why security defaults were not already switched on.
Defensive takeaway
When evaluating a vendor, ask whether security features such as multi-factor authentication and audit logging are included by default rather than sold separately, and treat a vendor's public commitment to a pledge such as Secure by Design as a starting point for questions, not as proof of a secure product.
- Does your procurement process ask vendors whether they have joined a secure-by-design commitment, and does it check for evidence beyond the pledge itself?
- Are security defaults such as MFA and centralised logging included in the base price of the software you buy, or priced as premium add-ons?
- If a policy document sets an expectation for vendors, does your organisation have a way to act on that expectation in contract negotiations?
A strategy document is a statement of intent rather than a guarantee, and the 2023 strategy's own successor shows that such statements can be revised or reprioritised by a later administration well before their goals are fully realised.
Ask vendors whether security defaults such as MFA and centralised logging are included at no extra cost, and treat a public pledge such as Secure by Design as a starting point for procurement questions rather than proof of a secure product.
The 2023 strategy's own content is drawn directly from the White House's release. The characterisation of the 2026 successor document relies on legal-industry analysis rather than the underlying PDF, which could not be rendered for this record.
Sources & reading trail
States the strategy's five pillars and its call to shift software liability toward vendors and the most capable defenders.
government-primary · Source published: 2 March 2023 · Retrieved: 16 September 2026
Living implementation guidance describing the Secure by Design principles and pledge as retrieved on 16 September 2026.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Describes the March 2026 Cyber Strategy for America and contrasts its regulatory approach with the 2023 strategy's liability-shifting emphasis.
reputable-original-reporting · Source published: 6 March 2026 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.