Secure by Design
Secure by Design is an approach in which security is built into products and systems from the very beginning of their development, rather than added on later as an afterthought. It treats protecting customers as a core business priority instead of an optional technical feature. The aim is to reduce vulnerabilities before code is written or a product ships.
Secure by Design (SbD) is a cybersecurity and systems engineering concept that calls for security to be incorporated into systems from the outset, embedded into software architecture and design decisions before implementation, rather than bolted on after development. As articulated in CISA's joint guidance (initially published April 2023), it urges software manufacturers to prioritize customer security as a core business requirement and to take proactive steps in how products are built and shipped. Frameworks such as the OWASP Secure-by-Design Framework provide practical guidance for embedding security into architecture early in the lifecycle, and government programs (for example, the UK's Secure by Design guidance) frame it as promoting a shared security culture across project teams. Scope note: SbD is a design and development philosophy for the producer of a system or product; it addresses how security is engineered into what is built and does not, by itself, constitute a certification, attestation, or verification of a given product's security posture. It also does not, on its own, address non-security dimensions of supplier risk such as financial, operational, geopolitical, or ESG risk, and its effectiveness depends on how consistently the principles are applied in practice.
Why it matters
For third-party and supply chain risk professionals, Secure by Design reframes where accountability for product security sits. Traditionally, buyers have carried much of the burden of hardening, patching, and compensating for vulnerabilities in the products they procure. CISA's joint guidance, initially published in April 2023, urges software manufacturers to prioritize the security of their customers as a core business requirement rather than treating it as an optional technical feature. When a supplier genuinely adopts this posture, some categories of risk can be reduced upstream, before a product is shipped and integrated into a buyer's environment.
The concept matters to procurement and vendor risk teams because it offers a lens for evaluating how a supplier approaches security engineering, not just whether a supplier can point to a completed questionnaire after the fact. A vendor that embeds security into architecture and design decisions early, consistent with frameworks such as the OWASP Secure-by-Design Framework, may present a different risk profile than one that relies on post-release patching. That said, Secure by Design describes a producer's development philosophy; it is not itself a certification, attestation, or independent verification of any given product's security posture, and buyers should not treat a vendor's claim of following it as equivalent to validated assurance.
Its value in practice is also conditional. Secure by Design addresses how security is engineered into what a supplier builds, but it does not, on its own, cover non-security dimensions of supplier risk such as financial, operational, geopolitical, or ESG exposure. Its effectiveness depends heavily on how consistently the principles are applied across a manufacturer's teams and product lines, which is difficult to observe from the outside. Assessors should treat a supplier's stated commitment to Secure by Design as one input to be corroborated, not as a standalone guarantee.
Who it's relevant to
Inside SbD
Common questions
Answers to the questions practitioners most commonly ask about SbD.