
What the document says
CISA and international partner agencies published Secure by Design guidance on 13 April 2023 and expanded it on 16 October 2023 with additional agencies and principles. As retrieved on 16 September 2026, the guidance document sets out three principles for software manufacturers: taking ownership of customer security outcomes, embracing radical transparency and accountability, and building the organisational structure so that senior executives, not only engineering teams, are accountable for security. The document asks manufacturers to ship products that are secure by design and to revamp development programmes so that only secure-by-design products reach customers, rather than treating security as a configurable extra.
In May 2024, CISA opened a voluntary Secure by Design Pledge that companies can sign. As retrieved on 16 September 2026, the pledge page lists seven goals, including phishing-resistant multi-factor authentication, eliminating default passwords, reducing whole classes of vulnerability such as SQL injection, improving patch-installation rates, publishing a vulnerability-disclosure policy with safe-harbour terms, issuing CVEs promptly, and giving customers audit-log evidence to detect intrusions. The page states plainly that CISA does not enforce or verify adherence, and that companies report their own progress within a year of signing, whether full, partial, or an honest account of obstacles.
The general Secure by Design hub page, also retrieved on 16 September 2026, frames both documents together: every technology provider must take ownership at the executive level to ensure its products are secure by design.
Confidence and limits
The guidance's content and the pledge's terms are drawn directly from CISA's own pages, which is a solid basis for describing what the initiative asks for. It is a much weaker basis for describing what the initiative has achieved, because compliance and progress reporting are both self-attested by participating companies, and this record does not include any independent audit of a specific signatory's claims.
Why it mattered
Secure by Design gave the 2023 National Cybersecurity Strategy's call to shift responsibility toward vendors a concrete, if voluntary, checklist, and more than 200 companies had joined the pledge by the time this record was retrieved. Its significance lies less in enforcement, which the guidance does not attempt, and more in giving buyers a named standard to ask vendors about during procurement.
Defensive takeaway
Ask prospective and existing software vendors whether they have signed the Secure by Design Pledge, and if they have, ask to see their own published progress report rather than treating the signature itself as evidence of a secure product.
- Has a vendor you rely on signed the Secure by Design Pledge, and have they published a progress report describing what they have and have not achieved?
- Does your procurement checklist ask whether multi-factor authentication and centralised logging come enabled by default, matching the pledge's own goals?
- Would your organisation be able to tell a vendor's marketing claim of secure-by-design practices apart from evidence of an actual reduction in a specific vulnerability class?
A pledge with self-reported progress is a starting point for a conversation with a vendor, not a substitute for asking that vendor to show its work.
Ask vendors whether they have signed the Secure by Design Pledge and request their own published progress report, rather than treating the signature itself as evidence of a secure product.
The guidance's content and the pledge's terms are drawn directly from CISA's own pages. What participating vendors have actually achieved is not established here, since progress reporting is self-attested and this record includes no independent audit of any signatory.
Sources & reading trail
Describes the joint guidance's three principles and its April 2023 origin, updated in October 2023 with additional partner agencies.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Sets out the seven goals of the voluntary pledge launched in May 2024 and states that CISA does not verify adherence.
government-primary · Source published: Not established · Retrieved: 16 September 2026
General hub page describing the Secure by Design initiative and pledge participation as retrieved on 16 September 2026.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.