CISA Secure by Demand: Questions for Software Vendors
CISA Secure by Demand (August 2024) is the buyer list: is MFA extra, do default passwords still exist, how do patches install, is there a public VDP. Design is the maker pledge. Demand is what you ask before you sign.
CISA Secure by Demand questions for software vendors are a buyer's list you can paste into an email before you sign. Ask whether MFA is extra, whether default passwords still exist, how patches actually get installed, and whether there is a public way to report a hole. CISA published that list for customers in August 2024.
A default password is the same factory password on every box. MFA is a second check besides that password. If those are paid add-ons, you are buying a product that treats your safety as an upgrade. Secure by Design is the pledge software makers take. Secure by Demand is the email you send before anyone falls in love with the walkthrough.
I run Kief Studio with Brian, from Shrewsbury, Massachusetts. I served as Secretary of the TRaViS board until May 2026, so I still read a vendor PDF as a progress report rather than a logo on a slide. If you and I were on a Zoom with the quote on the table, this is the email I would send with you before the demo starts.
Secure by Design is the maker pledge. Secure by Demand is the buyer email. A logo on a landing page is not a progress report.
Design is the pledge. Demand is your email.
Secure by Design is CISA telling software makers to ship a safer product: MFA, logging, and single sign-on included in what you open. The pledge launched in May 2024. Later hundreds of companies signed. It has seven goals, including MFA, killing default passwords, patches customers can install, and a vulnerability disclosure policy. A vulnerability disclosure policy, or VDP, is a public page that says how a researcher can report a bug without being treated as a criminal.
Secure by Demand is CISA telling you, the customer, to ask for that product. The August 2024 Demand guide opens with two questions: has the maker taken the pledge, and what progress reports exist. You do not need to be a federal agency to use the list. You need a contract and a pulse. Print the PDF. Highlight MFA, default passwords, patches, VDP, and logging. Send those lines back as questions.
CISA's January 2025 update said more than 250 companies had joined the pledge. Joining is a start. The Demand guide wants measurable progress: MFA adoption, default-password reduction, patch installation. A logo on a landing page is not a report. Ask for the latest progress note, dated, with numbers. If they cannot produce one, write that sentence next to the quote. Looking good in a meeting is not the same as shipping MFA in the base SKU.
Five asks before kickoff: MFA in the base SKU, no published default passwords, patches a customer can install, a public VDP, and logs you can actually use.
The questions, in the order I send them
Has the company signed the Secure by Design pledge, and where is the latest progress note? A logo is a marketing asset. A progress note is an operations asset. I want a URL I can open without a salesperson on the call. If they have not signed, that is allowed. Then the rest of the list still applies. A non-signer who ships MFA by default may be further along in the part you can see than a signer with no report.
Is MFA included, or is it a SKU? A SKU is a priced line on the quote. If the quote adds a line for advanced authentication, you are subsidizing a default that CISA already called table stakes. Same for single sign-on, one login that opens several apps. If SSO is extra, write it down next to the seat price. That is total cost of ownership, sitting in plain sight. Seat price without MFA is an incomplete number.
Do products still ship a published default password? CISA defines default passwords as universally shared passwords present by default. They keep showing up in incidents because nobody changed admin. Ask whether first boot forces a unique password. If the field engineer uses a shared setup login, you have the same problem with extra steps. Unique at first boot is the bar. A sticker on the box with one password for every customer is the failure mode.
How do patches reach me without a hero? A patch is a fix. If installing it requires a professional-services weekend, it will not get installed. CISA's pledge goal is a measurable increase in customer patch installation. Ask about automatic updates. Ask how they tell you a fix is urgent without flooding you into ignoring them. If every notice is labeled critical, none of them are. People stop opening the mail. That is how a real fix sits unread next to three marketing notes.
A second factor that costs extra is a product telling you who they built it for. Ask the price of the safe default before you fall in love with the demo.
Logging and disclosure, without the scare poster
Logging is the diary. You want to know who signed in and what changed. If logs are a higher tier, you will not have them when you need them. Exportable logs mean you can pull a file without a support ticket that takes three days. Retention means how long the diary is kept. Ask both. Ask whether timestamps are in UTC and whether admin actions are in the same stream as user logins.
The Demand guide also asks how the maker makes security patches simple. Pair that with a public VDP. No VDP means you might be emailing info@ and hoping. A good VDP names an address or a form, a reasonable response window, and a statement that good-faith research will not be treated as an attack. Open that page yourself. If it 404s, you have the answer.
Google's people-first page is the public E-E-A-T source I point operators to. Name the author. Keep titles current. Cite CISA, then say what it means on a quote. Outbound to cisa.gov. At Kief Studio we treat these questions as buyer work. We are two people, so we do not have a procurement department to hide behind. LTFI is the department if you want the list run as ops. kief.dev is the engineering public square. Brian's architecture notes live on briansgagne.com.
A thirty-minute vendor email
Link the Demand guide. Ask them to answer the MFA, default-password, patch, VDP, and logging questions in writing. Ask for the pledge page and the latest progress report, or a sentence that they have not signed. Ask whether MFA and SSO are in the base SKU, with the dollar difference if they are not. Ask how a customer installs a critical patch without a services engagement, and how urgent notices are throttled. Ask for the public VDP URL and a sample log export from a demo tenant. File the answers next to the quote. If they will only demo, you already know the defaults.
That is buyer work. It is also how you avoid paying twice: once for the tool, again for the safety that should have been on when you opened the box. Take the answers into the same folder as the contract. If a later incident review asks what you asked before you signed, you will have a dated email instead of a memory of a demo. You can use this list on a $400 tool and on a platform that will sit in a regulated workflow. The questions do not get smarter because the invoice is larger. The answers get more rehearsed. Rehearsed is fine if they still include a URL, a SKU, and a patch path. Rehearsed without those three is still a demo.
Read the Demand guide once with a highlighter. The MFA question is about whether the second factor ships in the base product. The default-password question is about first boot forcing a unique password. A wiki that tells the customer to change admin later is only a hope. The patch question is about a path a tired operator can finish on a Tuesday. The VDP question is a public URL. The logging question is an export you can open. Those five answers, dated, next to the quote, are the whole job.
If the salesperson wants to walk you through a dashboard instead of answering in writing, that is data. Dashboards do not survive a contract review. Email does. Put who owns the site, host, and login in the same folder if this purchase also touches the box that serves your public site. Software you cannot patch, and a host login you cannot find, are the same Saturday problem in two costumes. The walkthrough is built to look finished. After ten minutes of that, people skip the questions. Do not skip the questions.
If we had the quote on the table, I would highlight three lines before anyone talks features. MFA in the base SKU, or the dollar difference if it is not. First boot that forces a unique password, or a wiki that hopes someone changes admin later. A public VDP URL that loads, or an info@ address that goes to marketing. Those three lines tell you who the product was built for. The demo will not. Then I would ask them to send the latest progress note, dated, with numbers. If they signed the pledge in 2024 and the last public note is a logo, write that next to the seat price. You are allowed to buy from a non-signer. You are not required to treat a landing page as a report. Keep the email. Keep the PDF. Keep the date. That folder is the buyer work CISA already wrote down for you.
CISA Secure by Demand is an August 2024 guide that tells software customers what to ask makers: pledge status, MFA, default passwords, patches, disclosure, and logging you can actually use.
What is Secure by Design?
Secure by Design is the maker-side program. The pledge has seven goals. Demand is how you check whether any of that reached the product you are buying this quarter.
What is a vulnerability disclosure policy?
A vulnerability disclosure policy is a public page that says how to report a bug in good faith, and that the company will not treat that report as an attack.
Do I only buy from pledge signers?
No. Use the questions either way. A signer with no progress report is still a question mark. A non-signer who ships MFA by default may be further along in the part you can see.
Is MFA supposed to cost extra?
CISA treats MFA as table stakes in the Design pledge. If the quote adds a SKU for advanced authentication, write that dollar figure next to the seat price before you sign.
What should I do with the answers?
File them next to the quote with the Demand guide PDF. If the vendor will only demo and will not answer in writing, you already know how the defaults will be treated after kickoff.
Questions to ask business internet providers about cybersecurity: who can change routing, which logs you can export, the incident clock, MFA on the portal, and credits that land on the invoice. CISA's Demand guide is the shopping list. Get it in writing.
Your vendor's security posture is part of your security posture. When they have access to your systems, your data, or your clients — their breach is your breach.