Secure by Design: A Guide for Manufacturers (CISA)
CISA's Secure by Design guidance (Shifting the Balance of Cybersecurity Risk, April 2023, updated October 2023 with eighteen authoring agencies) and the voluntary Secure by Design Pledge (May 2024): three principles for software manufacturers (own customer security outcomes, radical transparency and accountability, lead from the top) with their demonstration practices, secure by design and secure by default tactics, recommendations for customers, and the pledge's seven goals. Voluntary guidance, not law. 69 leaves read against the October 2023 text and the pledge.
Secure by Design: A Guide for Manufacturers (CISA) is a compliance framework from International (CISA-led joint guidance; eighteen authoring organisations) with 7 domains and 69 controls that map to 101 other frameworks. The largest domains are Principle 1: Take ownership of customer security outcomes – Secure by Design: A Guide for Manufacturers (CISA) (18 controls), Principle 2: Embrace radical transparency and accountability – Secure by Design: A Guide for Manufacturers (CISA) (13 controls), Secure by design tactics: development roadmap practices – Secure by Design: A Guide for Manufacturers (CISA) (12 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Principle 1: Take ownership of customer security outcomes – Secure by Design: A Guide for Manufacturers (CISA)
Principle 2: Embrace radical transparency and accountability – Secure by Design: A Guide for Manufacturers (CISA)
Principle 3: Lead from the top – Secure by Design: A Guide for Manufacturers (CISA)
| Code | Title |
|---|---|
| secure-by-design-a-guide-for-manufacturers-cisa::P3-1 | Report the secure by design programme in corporate financial reports |
| secure-by-design-a-guide-for-manufacturers-cisa::P3-2 | Report product security regularly to the board |
| secure-by-design-a-guide-for-manufacturers-cisa::P3-3 | Empower the secure by design executive |
| secure-by-design-a-guide-for-manufacturers-cisa::P3-4 | Create meaningful internal incentives |
| secure-by-design-a-guide-for-manufacturers-cisa::P3-5 | Create a secure by design council |
| secure-by-design-a-guide-for-manufacturers-cisa::P3-6 | Create and evolve customer councils |
Recommendations for customers: secure by demand – Secure by Design: A Guide for Manufacturers (CISA)
| Code | Title |
|---|---|
| secure-by-design-a-guide-for-manufacturers-cisa::CR-1 | Hold suppliers accountable through purchasing criteria |
| secure-by-design-a-guide-for-manufacturers-cisa::CR-2 | Fund core enterprise IT services as critical functions |
| secure-by-design-a-guide-for-manufacturers-cisa::CR-3 | Build strategic relationships with key IT suppliers |
| secure-by-design-a-guide-for-manufacturers-cisa::CR-4 | Coordinate with peers and understand cloud shared responsibility |
Secure by Design Pledge (May 2024): seven goals – Secure by Design: A Guide for Manufacturers (CISA)
| Code | Title |
|---|---|
| secure-by-design-a-guide-for-manufacturers-cisa::PLEDGE-1 | Pledge goal 1: Multi-factor authentication |
| secure-by-design-a-guide-for-manufacturers-cisa::PLEDGE-2 | Pledge goal 2: Default passwords |
| secure-by-design-a-guide-for-manufacturers-cisa::PLEDGE-3 | Pledge goal 3: Reducing entire classes of vulnerability |
| secure-by-design-a-guide-for-manufacturers-cisa::PLEDGE-4 | Pledge goal 4: Security patches |
| secure-by-design-a-guide-for-manufacturers-cisa::PLEDGE-5 | Pledge goal 5: Vulnerability disclosure policy |
| secure-by-design-a-guide-for-manufacturers-cisa::PLEDGE-6 | Pledge goal 6: CVEs |
| secure-by-design-a-guide-for-manufacturers-cisa::PLEDGE-7 | Pledge goal 7: Evidence of intrusions |
Secure by default tactics: product configuration practices – Secure by Design: A Guide for Manufacturers (CISA)
| Code | Title |
|---|---|
| secure-by-design-a-guide-for-manufacturers-cisa::DF-1 | Eliminate default passwords |
| secure-by-design-a-guide-for-manufacturers-cisa::DF-2 | Mandate MFA for privileged users |
| secure-by-design-a-guide-for-manufacturers-cisa::DF-3 | Single sign-on |
| secure-by-design-a-guide-for-manufacturers-cisa::DF-4 | Secure logging |
| secure-by-design-a-guide-for-manufacturers-cisa::DF-5 | Software authorization profiles |
| secure-by-design-a-guide-for-manufacturers-cisa::DF-6 | Forward-looking security over backwards compatibility |
| secure-by-design-a-guide-for-manufacturers-cisa::DF-7 | Track and reduce hardening guide size |
| secure-by-design-a-guide-for-manufacturers-cisa::DF-8 | Weigh the user experience cost of security settings |
| secure-by-design-a-guide-for-manufacturers-cisa::DF-9 | Replace hardening guides with loosening guides |
Secure by design tactics: development roadmap practices – Secure by Design: A Guide for Manufacturers (CISA)
| Code | Title |
|---|---|
| secure-by-design-a-guide-for-manufacturers-cisa::DT-1 | Memory safe programming languages (SSDF PW.6.1) |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-10 | CVE completeness |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-11 | Defense in depth |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-12 | Satisfy the Cybersecurity Performance Goals |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-2 | Secure hardware foundation |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-3 | Secure software components (SSDF PW.4.1) |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-4 | Web template frameworks (SSDF PW.5.1) |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-5 | Parameterized queries (SSDF PW.5.1) |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-6 | Static and dynamic application security testing (SSDF PW.7.2, PW.8.2) |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-7 | Code review (SSDF PW.7.1, PW.7.2) |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-8 | Software bill of materials (SSDF PS.3.2, PW.4.1) |
| secure-by-design-a-guide-for-manufacturers-cisa::DT-9 | Vulnerability disclosure programmes (SSDF RV.1.3) |
Your Compliance Coverage
If you comply with Secure by Design: A Guide for Manufacturers (CISA), you already cover:
FTC GLBA Safeguards Rule (16 CFR Part 314)
6%
6 controls mapped
Compare →FFIEC Cybersecurity Assessment Tool (CAT)
6%
6 controls mapped
Compare →Singapore Government Instruction Manual on ICT&SS Management (IM8)
6%
6 controls mapped
Compare →+ 98 more: ISO/IEC 27011:2024 (6%), BSI IT-Grundschutz (6%)
See all 101 mapped frameworks ↓Maps to 101 other frameworks
Coverage is not the same as your position
This page shows what Secure by Design: A Guide for Manufacturers (CISA) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is Secure by Design: A Guide for Manufacturers (CISA) and who does it apply to?
Secure by Design: A Guide for Manufacturers (CISA) is a compliance framework from International (CISA-led joint guidance; eighteen authoring organisations) with 7 domains and 69 controls. CISA's Secure by Design guidance (Shifting the Balance of Cybersecurity Risk, April 2023, updated October 2023 with eighteen authoring agencies) and the voluntary Secure by Design Pledge (May 2024): three principles for software manufacturers (own customer security outcomes, radical transparency and accountability, lead from the top) with their demonstration practices, secure by design and secure by default tactics, recommendations for customers, and the pledge's seven goals. Voluntary guidance, not law. 69 leaves read against the October 2023 text and the pledge. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Secure by Design: A Guide for Manufacturers (CISA) actually require?
Secure by Design: A Guide for Manufacturers (CISA) has 69 controls organised across 7 domains. The largest domains are Principle 1: Take ownership of customer security outcomes – Secure by Design: A Guide for Manufacturers (CISA) (18 controls), Principle 2: Embrace radical transparency and accountability – Secure by Design: A Guide for Manufacturers (CISA) (13 controls), Secure by design tactics: development roadmap practices – Secure by Design: A Guide for Manufacturers (CISA) (12 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Secure by Design: A Guide for Manufacturers (CISA) do I already cover?
Secure by Design: A Guide for Manufacturers (CISA) maps to 101 other compliance frameworks. The top mapping partners are FTC GLBA Safeguards Rule (16 CFR Part 314) (6% coverage), FFIEC Cybersecurity Assessment Tool (CAT) (6% coverage), Singapore Government Instruction Manual on ICT&SS Management (IM8) (6% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Secure by Design: A Guide for Manufacturers (CISA)?
Start your Secure by Design: A Guide for Manufacturers (CISA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Secure by Design: A Guide for Manufacturers (CISA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 69 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 908 frameworks.
Get Started Free →Free forever — no credit card required