
The workload
The Cybersecurity and Infrastructure Security Agency (CISA), the US government's civilian cyber-defense agency, asks software manufacturers — its own pledge does not exempt small ones — to commit to specific, named security practices rather than treating security as optional. CISA's Secure by Design pledge page states, verified, that 'this pledge is voluntary and not legally binding,' and that it is 'structured with seven goals,' each with core criteria a signatory works toward and documents publicly. For a signatory, the workload is naming a plan against each goal, acting on it over roughly a year, and publishing an account of the result — a governance and communications task as much as an engineering one.
What the documents show
CISA's pledge text states, verified, that within one year of signing, a manufacturer commits to demonstrating 'actions taken to measurably increase the use of multi-factor authentication across the manufacturer's products,' and separately, on vulnerability classes, to publishing work done 'to significantly reduce the prevalence of one or more classes of vulnerability,' which may draw on root-cause analysis of the Common Weakness Enumeration (CWE) behind its own past flaws. The parent Secure by Design page frames the goal, verified: features such as multi-factor authentication, logging and single sign-on should ship 'out-of-the-box' and 'at no extra cost.' Neither page carries a publication date, so this reflects the documents as retrieved on 16 September 2026; CISA's own progress-reports page, indexing signatories' updates, lists a post titled as a roadmap for 2024 — the earliest year-specific evidence across these three pages of pledge activity.
The operating cost
Signing carries no fee; it is a public commitment, not a paid program, and CISA's text notes it is not legally binding. The real cost is the engineering and communications work each goal requires — MFA rollout, patch-adoption campaigns, vulnerability-class reduction, and the public write-up each goal calls for — none of which CISA prices in hours or dollars, since the pledge leaves method to each signatory.
The stop condition
CISA's text does not name a point at which a signatory is finished; it describes one-year demonstration windows per goal, not a closing date for the pledge itself. This is an editorial stop condition: for a one-person maker not already a signatory, the more relevant question is not whether to sign a pledge aimed chiefly at larger manufacturers, but whether the same goals — defaults at no extra cost, MFA, patch adoption, reduced vulnerability classes — are already true of the product without a public pledge to enforce them.
- Are the pledge's core practices — MFA by default, no extra charge for basic security features — already true of this product?
- Has a specific vendor actually signed the pledge, checked against CISA's own signatories list, rather than assumed?
- Does a one-person operation gain anything from the pledge's public-accountability structure that a private security checklist would not?
CISA's pledge asks manufacturers to commit to named, checkable practices and publish their own account of progress. It does not certify a product, and its own text is explicit that no legal obligation follows from signing it.
Sources & reading trail
States the pledge is voluntary, non-binding, and structured around seven one-year goals including MFA.
Source published: Not established · Retrieved: 16 September 2026
States the parent mission that security features should ship by default at no extra cost.
Source published: Not established · Retrieved: 16 September 2026
Indexes a signatory post dated to a 2024 roadmap, the earliest year-specific evidence of pledge activity found.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.