RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 200 retrospective records ↗

The archive / Build & architecture

Build & architecture / From the archive · 2024 event · prepared 16 September 2026

CISA's pledge asks makers to ship security on by default

The voluntary pledge sets seven one-year goals, including MFA by default, and names no signatory for you.

Visual for this record: CISA's pledge asks makers to ship security on by default
Visual published by cisa.gov, shown for identification of the record. Credit: cisa.gov · source page ↗ Rights: owner-review-pending.

The workload

The Cybersecurity and Infrastructure Security Agency (CISA), the US government's civilian cyber-defense agency, asks software manufacturers — its own pledge does not exempt small ones — to commit to specific, named security practices rather than treating security as optional. CISA's Secure by Design pledge page states, verified, that 'this pledge is voluntary and not legally binding,' and that it is 'structured with seven goals,' each with core criteria a signatory works toward and documents publicly. For a signatory, the workload is naming a plan against each goal, acting on it over roughly a year, and publishing an account of the result — a governance and communications task as much as an engineering one.

What the documents show

CISA's pledge text states, verified, that within one year of signing, a manufacturer commits to demonstrating 'actions taken to measurably increase the use of multi-factor authentication across the manufacturer's products,' and separately, on vulnerability classes, to publishing work done 'to significantly reduce the prevalence of one or more classes of vulnerability,' which may draw on root-cause analysis of the Common Weakness Enumeration (CWE) behind its own past flaws. The parent Secure by Design page frames the goal, verified: features such as multi-factor authentication, logging and single sign-on should ship 'out-of-the-box' and 'at no extra cost.' Neither page carries a publication date, so this reflects the documents as retrieved on 16 September 2026; CISA's own progress-reports page, indexing signatories' updates, lists a post titled as a roadmap for 2024 — the earliest year-specific evidence across these three pages of pledge activity.

The operating cost

Signing carries no fee; it is a public commitment, not a paid program, and CISA's text notes it is not legally binding. The real cost is the engineering and communications work each goal requires — MFA rollout, patch-adoption campaigns, vulnerability-class reduction, and the public write-up each goal calls for — none of which CISA prices in hours or dollars, since the pledge leaves method to each signatory.

The stop condition

CISA's text does not name a point at which a signatory is finished; it describes one-year demonstration windows per goal, not a closing date for the pledge itself. This is an editorial stop condition: for a one-person maker not already a signatory, the more relevant question is not whether to sign a pledge aimed chiefly at larger manufacturers, but whether the same goals — defaults at no extra cost, MFA, patch adoption, reduced vulnerability classes — are already true of the product without a public pledge to enforce them.

  • Are the pledge's core practices — MFA by default, no extra charge for basic security features — already true of this product?
  • Has a specific vendor actually signed the pledge, checked against CISA's own signatories list, rather than assumed?
  • Does a one-person operation gain anything from the pledge's public-accountability structure that a private security checklist would not?

CISA's pledge asks manufacturers to commit to named, checkable practices and publish their own account of progress. It does not certify a product, and its own text is explicit that no legal obligation follows from signing it.

Sources & reading trail

Secure by Design Pledge ↗

States the pledge is voluntary, non-binding, and structured around seven one-year goals including MFA.

Source published: Not established · Retrieved: 16 September 2026

Secure by Design ↗

States the parent mission that security features should ship by default at no extra cost.

Source published: Not established · Retrieved: 16 September 2026

Secure by Design Pledge Progress Reports ↗

Indexes a signatory post dated to a 2024 roadmap, the earliest year-specific evidence of pledge activity found.

Source published: Not established · Retrieved: 16 September 2026

Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.