Security1 distinct publisher2 min readUpdated
The guidance is non-binding. It is also a named list a critical-infrastructure buyer can read back to a vendor, starting with memory-unsafe code and the published plan for getting out of it.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The enforcement mechanism is stated in the document itself. CISA writes that following the recommendations will signal to customers that a manufacturer is taking ownership of customer security outcomes, which it calls a key secure by design principle [7]. That is a sentence about who does the checking, and it is not the agency. The wording came from CISA and the FBI [3]; the leverage arrives at renewal, in the hands of whoever signs the purchase order.
The memory safety roadmap is the part of this that survives contact with a lawyer, because it is an artifact with a date on it. Publishing one is not the whole ask. Manufacturers are expected to demonstrate that the roadmap will lead to a significant, prioritized reduction in memory safety vulnerabilities, and to demonstrate that they are making a reasonable effort to follow it [13]. That second clause is what separates a PDF from a commitment, and it hands a buyer a question for the following year's review: what actually moved.
Then there is the carve-out. Publication of a roadmap does not apply to products with an announced end-of-support date prior to Jan. 1, 2030 [14]. Anything a vendor still intends to sell into a water utility or a hospital in 2031 does not fit through that gap. Either answer is informative to the customer, which is the quiet effect of the clause: it turns a security question into a lifecycle disclosure, and vendors have historically been reluctant to put support horizons in writing at all.
The note attached to the item concedes the cost rather than pretending it away. CISA acknowledges that significant time and resources are needed to migrate to memory-safe languages, and suggests writing new components in memory-safe languages while hardware or compiler controls mitigate what remains [15]. So "we still ship C" is an answerable position, provided the other half of the sentence exists. What is no longer easy is the position that nothing is planned, since the absence of a plan is now the named bad practice, not merely the presence of old code.
Read as a whole, the list is a triage output. The authoring organizations say the items were chosen based on the threat landscape as the most dangerous and pressing practices to avoid [9], and the document also carries a change record [16], which is how a living checklist announces that it intends to grow. For anyone building a vendor questionnaire, the memory safety item is the one with a calendar date in it, and dated requirements are the ones that get quoted back first.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
CISA's Secure by Design initiative holds that software manufacturers should ensure security is a core consideration from the onset of software development and throughout the entire development lifecycle.
The voluntary guidance describes product security bad practices considered exceptionally risky, particularly for software manufacturers producing software used in service of critical infrastructure or national critical functions.
CISA and the Federal Bureau of Investigation developed the guidance and are referred to in it as the authoring organizations.
The guidance states that it is non-binding and that, while the authoring organizations encourage avoiding the bad practices, the document imposes no requirement to do so.
The document is intended for manufacturers of on-premises software, cloud services and software as a service, and also applies to software products that run on operational technology products or embedded systems.
The bad practices are divided into three categories: product properties, security features, and organizational processes and policies.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary text, uncorroborated effects
Every factual claim in this cluster is drawn from the authoritative primary document itself, so what the guidance says, who authored it, its scope, its non-binding status, the roadmap expectations and the pre-2030 carve-out are all directly verifiable at first hand. What is not evidenced anywhere in the supplied material is effect: no data links these practices to measured vulnerability reduction, and no second publisher or independent analysis appears in the cluster.
No uptake data in sources
The only adoption-shaped signal is the authoring agencies publishing their own guidance. The supplied source contains no record of any software manufacturer publishing a memory safety roadmap, conforming to the listed practices, or being assessed against them, and no procurement contract, pledge count, or attestation data. Adoption cannot be scored without inferring facts the source does not provide.
Strong risk language, non-binding force
Slightly overstated. The guidance repeatedly asserts that specific engineering choices 'significantly elevate risk to national security, national economic security, and national public health and safety' without presenting supporting data in the supplied text, and the roadmap item can be satisfied on paper either by a published plan or by announcing an end-of-support date before Jan. 1, 2030. Against that, the document is unusually candid about its own limits, stating that it is non-binding and that the list is focused rather than exhaustive, and the cluster framing itself is restrained, so the gap is small rather than large.
Agency advancing its own initiative
The sole source is the authoring agencies' own publication, and it advances CISA's Secure by Design programme directly, framing conformance as a signal to customers and cross-referencing CISA's own Secure by Design Pledge and memory-safe-roadmaps material. That is a real institutional interest in the guidance being seen as authoritative and widely followed. It is a public-sector, non-commercial interest with no product to sell, and the document discloses its own non-binding, non-exhaustive nature, which keeps the score mid-range rather than high.
Solid on text, thin on consequence
Confidence is high for what the guidance states, because the primary document is in hand and the wording is quoted, and low for what follows from it. The cluster has one publisher, the source body is truncated mid-way through the second bad practice so later categories are unseen, and there is no adoption or outcome evidence at all, which caps overall confidence in the middle band.
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
security
The ransom is for silence now, and your restore drill does not price that1 distinct publisher
security
CISA orders Ray patched as RondoDox folds cluster software into a 174-exploit arsenal1 distinct publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 22, 2026