Secure by design pledge of CISA and the CRA compared

More than 60 companies have voluntarily committed to CISA’s Secure by Design Pledge. We put the seven goals into context and compare them with the CRA.

The participants in the initiative have committed to achieving significant progress within twelve months in seven areas:

  • Increased use of multi-factor authentication
  • Replacing default passwords with secure alternatives
  • Reducing susceptibility to common vulnerabilities such as SQL injection
  • Improving the installation of security patches by customers
  • Establishing a vulnerability disclosure policy
  • Rapid assignment of CVE IDs to reported vulnerabilities
  • Facilitating the collection of information following security incidents

Although this pledge is an important step, it remains voluntary and legally non-binding. In contrast, the European Cyber Resilience Act (CRA) promises a stronger and binding effect on the industry through its regulatory measures and possible sanctions for non-compliance. Because of the size of the European single market, the CRA also serves as a model that influences American companies and can thus contribute to higher security standards worldwide.

Experience shows that, despite the good intentions behind voluntary commitments, binding requirements are often necessary to ensure broad and sustainable implementation of secure practices. The future of cybersecurity needs both voluntary initiatives and strict laws.

More information on the pledge and the specific measures can be found here: https://www.cisa.gov/securebydesign/pledge