BIDDA × CISA
3 PROGRAMS · 2 READY · 1 DRAFT
Built for America's defenders
The Cybersecurity and Infrastructure Security Agency (CISA) runs three public surfaces a credible compliance-intelligence platform should land on: the No-Cost Cybersecurity Services and Tools registry, the Secure by Design Pledge, and a working Cybersecurity Performance Goals crosswalk. Bidda meets the bar for each. This is the consolidated entry point for the three programs described below.
10,108
VERIFIED NODES
39
SOVEREIGN PILLARS
$0
COST FOR DEFENDERS
8
CPG OUTCOME AREAS
WHY CISA · THE TRUST LOOP
CISA is where US defenders look first
FEDERAL · SLTT · CRITICAL INFRA
CISA's No-Cost Cybersecurity Services and Tools registry is the canonical place federal agencies, state, local, tribal, and territorial governments, and critical-infrastructure operators look for vetted no-cost tooling. Bidda's discovery API, free sample node, bidda-shield SDK and /scan endpoint meet the no-cost bar.
PUBLIC ACCOUNTABILITY
Secure by Design Pledge signatories appear on a public CISA page beside hundreds of named software manufacturers. The pledge is a public commitment that researchers, customers, and partners can hold Bidda to over time, which is the opposite of marketing-only security claims.
CPG BIDIRECTIONAL
CISA's voluntary Cybersecurity Performance Goals are the de-facto baseline for US critical-infrastructure cybersecurity. A working bidirectional crosswalk between a CPG outcome and a Bidda node lets a defender move from "what does CISA expect of me" to "what do I execute" without leaving the registry.
Programs
CISA · NO-COST-TOOLS
DRAFT
No-Cost Cybersecurity Services & Tools
CISA No-Cost Cybersecurity Services and Tools registry
CISA maintains a public list of no-cost tools that vulnerable and under-resourced critical-infrastructure operators can use right now. Bidda's discovery API, free sample node, bidda-shield SDK and /scan endpoint all meet the no-cost bar.
PROCESS
Self-nomination via the official CISA webform. Listed publicly on cisa.gov once accepted.
BAR TO CLEAR
Tool must be no-cost, with no trial limitation and no auto-enrolment, must be generally available, and must be hosted by a US-based organisation. The last item is the gating prerequisite for Bidda.
OPEN PAGE →
CISA · SBD-PLEDGE
DRAFT
Secure by Design Pledge
CISA Secure by Design Pledge, the public manufacturer commitment
A voluntary public commitment by software manufacturers to seven security-first goals. Signatories appear on the official CISA signatories page alongside hundreds of other named software manufacturers.
PROCESS
Public attestation against each goal with linked evidence. No fee. International signatories accepted.
BAR TO CLEAR
Demonstrable progress against MFA-default, no-default-passwords, vuln-class reduction, patch cadence, published VDP, CVE issuance, and intrusion evidence.
OPEN PAGE →
CISA · CPG
READY
CPG × Bidda Crosswalk
CISA Cybersecurity Performance Goals × Bidda nodes
CISA's voluntary CPG baseline covers eight outcome areas across information-technology and operational-technology environments. Bidda's cybersecurity, infrastructure, AI-governance and supply-chain pillars already speak to each area, and the crosswalk presents that coverage as an analyst-readable table.
PROCESS
8 CPG areas mapped to Bidda pillars + named example nodes per area.
BAR TO CLEAR
Bidirectional: a CPG outcome resolves to executable nodes; a Bidda node names the CPG outcomes it satisfies.
OPEN PAGE →
How the three programs fit together
The three programs above are complementary, not competing. Each speaks to a different audience and a different question a defender will ask.
FREE TOOLS · DISCOVERABILITY
Answers "is there a free tool that helps with this?". The Free Tools registry is the discovery surface defenders consult before procurement.
SBD PLEDGE · TRUST
Answers "how do I know this vendor takes security seriously?". A signed, public pledge against seven measurable goals is independent attestation.
CPG CROSSWALK · EXECUTION
Answers "how do I actually implement CISA's recommended baseline?". The crosswalk turns each CPG outcome into an executable Bidda node chain.
INDEPENDENT VERIFICATION · KEY ROTATION
Verifiable without trusting Bidda, and rotation-safe
A defender or auditor should never have to take a vendor's word for it. Every Bidda signed record can be checked independently, offline, with no Bidda account, on a page that runs entirely in the browser. The exact signing method is published, and command-line checkers for Node and Python are provided. As a routine security practice we rotate our signing key from time to time. Every key we have ever used stays published, so a record signed by an older key keeps verifying for as long as the holder keeps it. Rotation changes only which key signs new records; it never invalidates a record already issued.
VERIFY IT YOURSELF
Ed25519 signature checked locally in your browser, or in your terminal. Nothing is uploaded.
OPEN THE VERIFIER →
PUBLISHED METHOD
The full verification specification is public, so any correct Ed25519 implementation can confirm a record.
READ THE SPEC →
EVERY KEY PUBLISHED
Current and retired signing keys are all published, each with its key id, so older records stay verifiable.
VIEW PUBLISHED KEYS →
ALREADY ON THE SITE
The CISA narrative does not require new infrastructure, because Bidda already publishes an RFC 9116 security contact, a coordinated vulnerability disclosure policy with safe-harbour terms, a tamper-evidence verifier, and the full source-verification methodology. The CISA pages below frame what already exists.
/SECURITY · VDP
/VERIFY · TAMPER-EVIDENCE
/METHODOLOGY · 4-GATE PIPELINE