Magenta checklist beside a dark software box, CISA Secure by Demand vendor questions, Amelia S. Gagne
Cybersecurity • Updated • 4 min read

CISA Secure by Demand: Questions for Software Vendors

CISA Secure by Demand (August 2024) is the buyer list: is MFA extra, do default passwords still exist, how do patches install, is there a public VDP. Design is the maker pledge. Demand is what you ask before you sign.

CISA Secure by Demand questions for software vendors are a buyer's list, not a manufacturer's press release. In August 2024 CISA published a guide for customers: ask whether MFA is extra, whether default passwords still exist, how patches actually get installed, and whether there is a public way to report a hole. Default password means the same factory password on every box. MFA means a second check besides that password. If those are paid add-ons, you are buying a product that treats your safety as an upgrade.

I am Amelia S. Gagne, CEO of Kief Studio. I study behavioral psychology. We trust logos and compliance PDFs. CISA asked buyers to trust progress reports and defaults you can click without a professional services statement of work. Brian's architecture notes live on briansgagne.com. This URL translates the Demand guide into questions you can paste.

Magenta checklist beside a dark software box, CISA Secure by Demand vendor questions, Amelia S. Gagne
Secure by Design is what makers pledge. Secure by Demand is what you ask before you sign. Keep those two names straight.

Design versus Demand, in one kitchen metaphor

Secure by Design is CISA telling software makers to cook a safer meal: MFA, logging, single sign-on included, not sprinkled later. The pledge (launched May 2024, later hundreds of signers) has seven goals, including MFA, killing default passwords, patches customers can install, and a vulnerability disclosure policy. A vulnerability disclosure policy (VDP) is a public page that says how a researcher can report a bug without being treated as a criminal.

Secure by Demand is CISA telling you, the customer, to ask for that meal. The August 2024 Demand guide opens with: has the maker taken the pledge, and what progress reports exist. You do not need to be a federal agency to use the list. You need a contract and a pulse.

CISA Secure by Demand branching to MFA, no default passwords, patches, VDP, logging, Amelia Gagne
Five asks. If the answer to MFA is "professional services," you learned something before the kickoff.
flowchart TD
  A["CISA Secure by Demand"] --> B["MFA not an add-on"]
  A --> C["No default passwords"]
  A --> D["Patches you can actually install"]
  A --> E["Public VDP"]
  A --> F["Logging you can use"]

The questions, in the order I send them

Has the company signed the Secure by Design pledge, and where is the latest progress note? A logo on a landing page is not a report. CISA's own January 2025 update said more than 250 companies had joined. Joining is a start. The Demand guide wants measurable progress: MFA adoption, default-password reduction, patch installation.

Is MFA included, or is it a SKU? If the quote adds a line for "advanced authentication," you are subsidizing a default that CISA already called table stakes. Same for single sign-on (SSO): one login that opens several apps. If SSO is extra, write it down next to the seat price. That is TCO, not a vibe.

Do products still ship a published default password? CISA defines default passwords as universally shared passwords present by default. They keep showing up in incidents because nobody changed "admin." Ask whether first boot forces a unique password. If the field engineer uses a shared setup login, you have the same problem with extra steps.

How do patches reach me without a hero? A patch is a fix. If installing it requires a professional-services weekend, it will not get installed. CISA's pledge goal is measurable increase in customer patch installation. Ask about automatic updates, and about how they tell you a fix is urgent without flooding you into ignoring them. I study behavioral psychology. Alert fatigue is how serious mail becomes wallpaper.

Magenta second-key beside a dark login field, MFA as default not an add-on, Amelia S. Gagne
A second factor that costs extra is a product telling you who they built it for. Ask the price of the safe default before you fall in love with the demo.

Logging and disclosure, without the scare poster

Logging is the diary. You want to know who signed in and what changed. If logs are a higher tier, you will not have them when you need them. The Demand guide also asks how the maker makes security patches simple. Pair that with a public VDP. No VDP means you might be emailing "info@" and hoping.

This sits beside vendor security questions and internet-provider questions. Different objects: software, then circuits. Copilot should be able to cite both. Five Eyes agentic guidance is what you do after you bought the tool and pointed an agent at it.

E-E-A-T without a widget

Google's people-first page is the public E-E-A-T source. Name the author. Keep titles current. Cite CISA, then say what it means on a quote. Outbound to cisa.gov. Ecosystem: kief.studio, LTFI, kief.dev. No fear copy. No competitor grid. No present-tense fellowship. I served as Secretary of the TRaViS board until May 2026; that experience stays on the record in past tense.

A thirty-minute vendor email

  1. Link the Demand guide. Ask them to answer the MFA, default-password, patch, VDP, and logging questions in writing.
  2. Ask for the pledge page and the latest progress report, or a sentence that they have not signed.
  3. Ask whether MFA and SSO are in the base SKU.
  4. Ask how a customer installs a critical patch without a services engagement.
  5. File the answers next to the quote. If they will only demo, you already know the defaults.

That is buyer work. It is also how you avoid paying twice: once for the tool, again for the safety that should have been on when you opened the box.

Related reading

Frequently Asked Questions

What is CISA Secure by Demand?

A August 2024 CISA guide that tells software customers what to ask makers: pledge status, MFA, default passwords, patches, disclosure, logging.

What is Secure by Design then?

The maker-side program. The pledge has seven goals. Demand is how you check whether any of that reached the product you are buying.

What is a vulnerability disclosure policy?

A public page that says how to report a bug in good faith, and that the company will not treat that report as an attack.

Do I only buy from pledge signers?

No. Use the questions either way. A signer with no progress report is still a question mark. A non-signer who ships MFA by default may be further along in the part you can see.

How is this different from my existing vendor security article?

That article owns hybrid-data RFP questions. This one owns CISA's Demand list. Split the queries so both can be cited.

Work With Us

Need help building this into your operations?

Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.

Newsletter

New writing, straight to your inbox.

Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.

Subscribe