Bidda Sovereign Intelligence · 10,108 Verified Nodes · 39 Sovereign Pillars

Bidda x CISA: Built to the Public-Trust Standards

Bidda's consolidated position against CISA's three public-trust surfaces for software vendors and defender tooling: a bidirectional Cybersecurity Performance Goals crosswalk, a public Secure by Design Pledge attestation, and the no-cost capabilities available to defenders. Built on 10,108 verified compliance nodes.

BIDDA × CISA
3 PROGRAMS · 2 READY · 1 DRAFT
Built for America's defenders

The Cybersecurity and Infrastructure Security Agency (CISA) runs three public surfaces a credible compliance-intelligence platform should land on: the No-Cost Cybersecurity Services and Tools registry, the Secure by Design Pledge, and a working Cybersecurity Performance Goals crosswalk. Bidda meets the bar for each. This is the consolidated entry point for the three programs described below.

10,108

VERIFIED NODES

39

SOVEREIGN PILLARS

$0

COST FOR DEFENDERS

8

CPG OUTCOME AREAS

WHY CISA · THE TRUST LOOP

CISA is where US defenders look first

FEDERAL · SLTT · CRITICAL INFRA

CISA's No-Cost Cybersecurity Services and Tools registry is the canonical place federal agencies, state, local, tribal, and territorial governments, and critical-infrastructure operators look for vetted no-cost tooling. Bidda's discovery API, free sample node, bidda-shield SDK and /scan endpoint meet the no-cost bar.

PUBLIC ACCOUNTABILITY

Secure by Design Pledge signatories appear on a public CISA page beside hundreds of named software manufacturers. The pledge is a public commitment that researchers, customers, and partners can hold Bidda to over time, which is the opposite of marketing-only security claims.

CPG BIDIRECTIONAL

CISA's voluntary Cybersecurity Performance Goals are the de-facto baseline for US critical-infrastructure cybersecurity. A working bidirectional crosswalk between a CPG outcome and a Bidda node lets a defender move from "what does CISA expect of me" to "what do I execute" without leaving the registry.

Programs

CISA · NO-COST-TOOLS

DRAFT
No-Cost Cybersecurity Services & Tools

CISA No-Cost Cybersecurity Services and Tools registry

CISA maintains a public list of no-cost tools that vulnerable and under-resourced critical-infrastructure operators can use right now. Bidda's discovery API, free sample node, bidda-shield SDK and /scan endpoint all meet the no-cost bar.

PROCESS

Self-nomination via the official CISA webform. Listed publicly on cisa.gov once accepted.

BAR TO CLEAR

Tool must be no-cost, with no trial limitation and no auto-enrolment, must be generally available, and must be hosted by a US-based organisation. The last item is the gating prerequisite for Bidda.

OPEN PAGE →

CISA · SBD-PLEDGE

DRAFT
Secure by Design Pledge

CISA Secure by Design Pledge, the public manufacturer commitment

A voluntary public commitment by software manufacturers to seven security-first goals. Signatories appear on the official CISA signatories page alongside hundreds of other named software manufacturers.

PROCESS

Public attestation against each goal with linked evidence. No fee. International signatories accepted.

BAR TO CLEAR

Demonstrable progress against MFA-default, no-default-passwords, vuln-class reduction, patch cadence, published VDP, CVE issuance, and intrusion evidence.

OPEN PAGE →

CISA · CPG

READY
CPG × Bidda Crosswalk

CISA Cybersecurity Performance Goals × Bidda nodes

CISA's voluntary CPG baseline covers eight outcome areas across information-technology and operational-technology environments. Bidda's cybersecurity, infrastructure, AI-governance and supply-chain pillars already speak to each area, and the crosswalk presents that coverage as an analyst-readable table.

PROCESS

8 CPG areas mapped to Bidda pillars + named example nodes per area.

BAR TO CLEAR

Bidirectional: a CPG outcome resolves to executable nodes; a Bidda node names the CPG outcomes it satisfies.

OPEN PAGE →
How the three programs fit together

The three programs above are complementary, not competing. Each speaks to a different audience and a different question a defender will ask.

FREE TOOLS · DISCOVERABILITY

Answers "is there a free tool that helps with this?". The Free Tools registry is the discovery surface defenders consult before procurement.

SBD PLEDGE · TRUST

Answers "how do I know this vendor takes security seriously?". A signed, public pledge against seven measurable goals is independent attestation.

CPG CROSSWALK · EXECUTION

Answers "how do I actually implement CISA's recommended baseline?". The crosswalk turns each CPG outcome into an executable Bidda node chain.

INDEPENDENT VERIFICATION · KEY ROTATION

Verifiable without trusting Bidda, and rotation-safe

A defender or auditor should never have to take a vendor's word for it. Every Bidda signed record can be checked independently, offline, with no Bidda account, on a page that runs entirely in the browser. The exact signing method is published, and command-line checkers for Node and Python are provided. As a routine security practice we rotate our signing key from time to time. Every key we have ever used stays published, so a record signed by an older key keeps verifying for as long as the holder keeps it. Rotation changes only which key signs new records; it never invalidates a record already issued.

VERIFY IT YOURSELF

Ed25519 signature checked locally in your browser, or in your terminal. Nothing is uploaded.

OPEN THE VERIFIER →

PUBLISHED METHOD

The full verification specification is public, so any correct Ed25519 implementation can confirm a record.

READ THE SPEC →

EVERY KEY PUBLISHED

Current and retired signing keys are all published, each with its key id, so older records stay verifiable.

VIEW PUBLISHED KEYS →

ALREADY ON THE SITE

The CISA narrative does not require new infrastructure, because Bidda already publishes an RFC 9116 security contact, a coordinated vulnerability disclosure policy with safe-harbour terms, a tamper-evidence verifier, and the full source-verification methodology. The CISA pages below frame what already exists.

/SECURITY · VDP
/VERIFY · TAMPER-EVIDENCE
/METHODOLOGY · 4-GATE PIPELINE

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.