Bidda x CISA: Built to the Public-Trust Standards ================================================= JS-free text mirror for AI crawlers. Canonical page: https://bidda.com/cisa Last updated: 2026-07-11 BIDDA × CISA 3 PROGRAMS · 2 READY · 1 DRAFT Built for America's defenders The Cybersecurity and Infrastructure Security Agency (CISA) runs three public surfaces a credible compliance-intelligence platform should land on: the No-Cost Cybersecurity Services and Tools registry, the Secure by Design Pledge, and a working Cybersecurity Performance Goals crosswalk. Bidda meets the bar for each. This is the consolidated entry point for the three programs described below. 10,108 VERIFIED NODES 39 SOVEREIGN PILLARS $0 COST FOR DEFENDERS 8 CPG OUTCOME AREAS WHY CISA · THE TRUST LOOP CISA is where US defenders look first FEDERAL · SLTT · CRITICAL INFRA CISA's No-Cost Cybersecurity Services and Tools registry is the canonical place federal agencies, state, local, tribal, and territorial governments, and critical-infrastructure operators look for vetted no-cost tooling. Bidda's discovery API, free sample node, bidda-shield SDK and /scan endpoint meet the no-cost bar. PUBLIC ACCOUNTABILITY Secure by Design Pledge signatories appear on a public CISA page beside hundreds of named software manufacturers. The pledge is a public commitment that researchers, customers, and partners can hold Bidda to over time, which is the opposite of marketing-only security claims. CPG BIDIRECTIONAL CISA's voluntary Cybersecurity Performance Goals are the de-facto baseline for US critical-infrastructure cybersecurity. A working bidirectional crosswalk between a CPG outcome and a Bidda node lets a defender move from "what does CISA expect of me" to "what do I execute" without leaving the registry. Programs CISA · NO-COST-TOOLS DRAFT No-Cost Cybersecurity Services & Tools CISA No-Cost Cybersecurity Services and Tools registry CISA maintains a public list of no-cost tools that vulnerable and under-resourced critical-infrastructure operators can use right now. Bidda's discovery API, free sample node, bidda-shield SDK and /scan endpoint all meet the no-cost bar. PROCESS Self-nomination via the official CISA webform. Listed publicly on cisa.gov once accepted. BAR TO CLEAR Tool must be no-cost, with no trial limitation and no auto-enrolment, must be generally available, and must be hosted by a US-based organisation. The last item is the gating prerequisite for Bidda. OPEN PAGE → CISA · SBD-PLEDGE DRAFT Secure by Design Pledge CISA Secure by Design Pledge, the public manufacturer commitment A voluntary public commitment by software manufacturers to seven security-first goals. Signatories appear on the official CISA signatories page alongside hundreds of other named software manufacturers. PROCESS Public attestation against each goal with linked evidence. No fee. International signatories accepted. BAR TO CLEAR Demonstrable progress against MFA-default, no-default-passwords, vuln-class reduction, patch cadence, published VDP, CVE issuance, and intrusion evidence. OPEN PAGE → CISA · CPG READY CPG × Bidda Crosswalk CISA Cybersecurity Performance Goals × Bidda nodes CISA's voluntary CPG baseline covers eight outcome areas across information-technology and operational-technology environments. Bidda's cybersecurity, infrastructure, AI-governance and supply-chain pillars already speak to each area, and the crosswalk presents that coverage as an analyst-readable table. PROCESS 8 CPG areas mapped to Bidda pillars + named example nodes per area. BAR TO CLEAR Bidirectional: a CPG outcome resolves to executable nodes; a Bidda node names the CPG outcomes it satisfies. OPEN PAGE → How the three programs fit together The three programs above are complementary, not competing. Each speaks to a different audience and a different question a defender will ask. FREE TOOLS · DISCOVERABILITY Answers "is there a free tool that helps with this?". The Free Tools registry is the discovery surface defenders consult before procurement. SBD PLEDGE · TRUST Answers "how do I know this vendor takes security seriously?". A signed, public pledge against seven measurable goals is independent attestation. CPG CROSSWALK · EXECUTION Answers "how do I actually implement CISA's recommended baseline?". The crosswalk turns each CPG outcome into an executable Bidda node chain. INDEPENDENT VERIFICATION · KEY ROTATION Verifiable without trusting Bidda, and rotation-safe A defender or auditor should never have to take a vendor's word for it. Every Bidda signed record can be checked independently, offline, with no Bidda account, on a page that runs entirely in the browser. The exact signing method is published, and command-line checkers for Node and Python are provided. As a routine security practice we rotate our signing key from time to time. Every key we have ever used stays published, so a record signed by an older key keeps verifying for as long as the holder keeps it. Rotation changes only which key signs new records; it never invalidates a record already issued. VERIFY IT YOURSELF Ed25519 signature checked locally in your browser, or in your terminal. Nothing is uploaded. OPEN THE VERIFIER → PUBLISHED METHOD The full verification specification is public, so any correct Ed25519 implementation can confirm a record. READ THE SPEC → EVERY KEY PUBLISHED Current and retired signing keys are all published, each with its key id, so older records stay verifiable. VIEW PUBLISHED KEYS → ALREADY ON THE SITE The CISA narrative does not require new infrastructure, because Bidda already publishes an RFC 9116 security contact, a coordinated vulnerability disclosure policy with safe-harbour terms, a tamper-evidence verifier, and the full source-verification methodology. The CISA pages below frame what already exists. /SECURITY · VDP /VERIFY · TAMPER-EVIDENCE /METHODOLOGY · 4-GATE PIPELINE