Secure by Design pledge – cyber regulation

More than 60 companies have committed to CISA’s Secure by Design pledge to improve software security. The voluntary initiative is discussed alongside the binding EU Cyber Resilience Act.

Participants in the initiative have pledged to make significant progress in seven areas within twelve months:

  • Increased use of multi-factor authentication,
  • Replacing default passwords with secure alternatives,
  • Reducing susceptibility to common vulnerabilities such as SQL injection,
  • Improving how customers install security patches,
  • Creating a vulnerability disclosure policy,
  • Rapid assignment of CVE IDs to reported vulnerabilities,
  • Facilitating the collection of information following security incidents.

Although this commitment is an important step, it remains voluntary and legally non-binding. In comparison, the European Cyber Resilience Act (CRA) — with its regulatory measures and potential sanctions for non-compliance — promises a stronger, binding effect on industry. Due to the size of the European single market, the CRA can act as a model that also influences American companies and thereby contribute to higher security levels worldwide.

Experience shows that, despite the good intentions behind self-commitments, binding requirements are often necessary to ensure broad and sustainable implementation of secure practices. The future of cybersecurity needs both voluntary initiatives and strict laws.

More information about the pledge and the concrete measures can be found here: https://www.cisa.gov/securebydesign/pledge