DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Secure software procurement in 2025: A call for accountability

Accountable software procurement uses security vetting, supplier evidence, SBOM workflows, tailored contract terms and documented executive risk acceptance. NIST and CISA guidance can shape buyer practice, while the EU Cyber Resilience Act follows its own scope and staged dates.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2025, software procurement was a practical security lever: buyers could vet products before purchase, require evidence of secure development, put security expectations into contracts, and make any accepted residual risk visible to the executive who owns it. This article treats 2025 as a historical frame. The EU Cyber Resilience Act (CRA) had been adopted but its main obligations were scheduled in stages after 2025; the dates below reflect the legal text available on 28 September 2026.

What an accountable buyer controls

Procurement does not make software vulnerability-free. It does determine which products enter an environment, what evidence a supplier must provide, what support is contractually expected, and who approves an exception when the risk is understood but accepted.

CISA’s Software Acquisition Guide for Government Enterprise Consumers describes this accountability model: involve internal security staff in product vetting, use requests for information (RFIs), requests for proposals (RFPs) and contract language to influence purchases, and obtain executive backing when purchasing decisions are enforced. If an insecure or otherwise risky product is selected, the decision and its inherent risk should be formally documented and approved by the senior business executives who own enterprise risk.

Start before the solicitation

Define the software’s consequences

  • Identify the software’s business role and whether it is hosted, installed on endpoints, embedded in another product or delivered as a service.
  • Map the data, credentials, network paths and administrative privileges it can access.
  • Record the consequence of compromise, outage, manipulation or loss of supplier support.
  • List important dependencies and integration points so that the review covers the system you will actually operate, not only the vendor’s product description.

Put security in the requirements

Bring security reviewers into the requirements and evaluation process before award. Describe the evidence, reporting, update support and remediation expectations that match the product’s role and consequences. CISA’s guidance supports using the solicitation itself to influence supplier behavior; it does not provide a universal clause set that fits every purchase.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Thales - SafeNet eToken Fusion - Phishing-Resistant FIDO2 Certified Security Key for Digital Certificates or Web Apps & Desktop Authentication - USB-A, Pack of 50
  • PKI FIDO2 SECURITY KEY: This USB-A security key combines X509 digital certificates (PKI) and FIDO for maximum protection. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Linux and USB-A devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, ensuring secure use across various platforms, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts

Ask suppliers for evidence, not promises

NIST’s Software Cybersecurity for Producers and Purchasers was issued under Executive Order 14028, section 4(e), to help federal procurement staff know what information to request from software producers about secure-development practices. The page was created on 1 February 2022 and updated on 5 May 2022.

For a purchase, request a clear description of the supplier’s development and security practices and any relevant evidence or attestation. Define what the evidence covers, which product and version it concerns, the period assessed and any exclusions. An attestation supports an assurance process; it is not a guarantee that the software contains no vulnerabilities.

Rank #2
Thales - SafeNet eToken Fusion - Phishing-Resistant FIDO2 Certified Security Key for Digital Certificates or Web Apps & Desktop Authentication - USB-A, Pack of 10
  • PKI FIDO2 SECURITY KEY: This USB-A security key combines X509 digital certificates (PKI) and FIDO for maximum protection. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Linux and USB-A devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, ensuring secure use across various platforms, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts

Use an SBOM as an operating input

An SBOM is a formal record of software components and supply-chain relationships. Where appropriate, require access in a machine-readable format and clarify how the information will be delivered, updated and stored. NIST’s SBOM guidance describes repositories, enrichment with context, integration with vulnerability detection and continuing risk monitoring.

The operational test is whether the buyer can use the data. An organization that cannot ingest, analyze and act on an SBOM is unlikely to improve its supply-chain risk posture. Assign an owner and connect the SBOM to asset records, vulnerability alerting and remediation workflows before treating delivery as a completed control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Thales - SafeNet eToken Fusion - Phishing-Resistant FIDO2 Certified Security Key for Digital certificates or FIDO2 authentication to Web apps and desktops - USB-C, Pack of 50
  • PKI FIDO2 SECURITY KEY: This USB-C security key combines X509 digital certificates (PKI) and FIDO to support multiple use cases with one single authenticator. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts

Make expectations enforceable after selection

Contract for the product’s risk

Tailor terms to the software and its exposure. Potential subjects include vulnerability and incident reporting, remediation targets, supported versions, security update delivery, cooperation with investigations, continuing evidence delivery and SBOM access. The precise obligations should follow the buyer’s requirements and negotiating authority; neither the cited CISA guide nor the NIST material establishes a universal checklist.

Record accepted exceptions

If the business chooses a product with material known or inherent risk, create a decision record that identifies the product, the risk, the rationale, compensating measures and the executive who approved acceptance. Risk acceptance belongs with the enterprise risk owner, not solely with a procurement desk or technical reviewer.

Rank #4
Thales - SafeNet eToken Fusion - Phishing-Resistant FIDO2 Certified Security Key for Digital certificates or FIDO2 authentication to Web apps and desktops - USB-C, Pack of 10
  • PKI FIDO2 SECURITY KEY: This USB-C security key combines X509 digital certificates (PKI) and FIDO to support multiple use cases with one single authenticator. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts

Keep the review alive after award

Procurement is a continuing relationship rather than a one-time questionnaire. Maintain the supplier evidence and SBOM information, watch for vulnerability notices and product changes, and route findings to the teams that can prioritize remediation, compensating controls or replacement. This monitoring only works when the organization has the capability and authority to act on the information it receives.

Procurement guidance and product regulation are different mechanisms

Question Buyer-led procurement guidance EU Cyber Resilience Act
Who carries the duty? The purchaser controls solicitation, evaluation, contracting and any risk-acceptance decision. The regulation places obligations on economic operators for products with digital elements within its scope.
What is demanded? Information about secure development, evidence or attestations, SBOM access, contract commitments and governance. Product cybersecurity requirements, including risk-based measures and, where applicable, availability without known exploitable vulnerabilities and secure-by-default configuration.
Where does it apply? NIST and CISA materials have federal or enterprise audiences; they are not automatically binding on every public or private buyer. Products with digital elements that fall within the CRA’s EU scope.
When does it apply? It can inform a buyer’s current process, subject to the buyer’s jurisdiction and policy. Application is staged under Article 71 rather than beginning wholesale in 2025.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How the U.S. sources fit together

NIST purchaser guidance

NIST’s purchaser-facing guidance is an evidence-request framework for federal agency staff. It is useful for structuring supplier questions and assurance reviews, but it does not turn every recommendation into a statutory obligation for all government, business or consumer purchases.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA enterprise acquisition guidance

CISA’s guide supplies the accountability pattern: vet with security staff, use RFIs, RFPs and contracts to set expectations, secure executive support for enforcement, and document and approve the risk when a risky product is chosen. Its July 2024 publication path makes it a current policy reference for that approach, not a substitute for the terms governing a particular transaction.

Federal supply-chain acquisition context

GSAM Subpart 504.70 describes federal agency responsibilities for managing cyber-supply-chain risk in federal information systems. It is one part of the federal acquisition framework. For a named agency, contract or clause, consult the live provision and the applicable transaction-specific requirements rather than treating this subpart as a complete statement of every federal, state, local or private-sector duty.

CRA dates a 2025 buyer should not blur

Date Provision What it means for a 2025 retrospective
11 June 2026 Chapter IV, Articles 35–51 These provisions were scheduled to apply after 2025.
11 September 2026 Article 14 reporting obligations The reporting start date was after 2025 and should not be described as a 2025 obligation.
11 December 2027 General application under Article 71 The CRA’s general requirements were not generally applicable in 2025.

Regulation (EU) 2024/2847 was adopted on 23 October 2024 and published on 20 November 2024. Because amendments or implementation details can change, verify the current EUR-Lex text and application dates when making a live compliance decision.

Keep an auditable procurement file

A defensible decision record should let a later reviewer follow the chain from business need to residual risk. Retain:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • the software role, data access, deployment model and consequence assessment;
  • security requirements and the identity of the security reviewer;
  • supplier responses, evidence scope and attestation limitations;
  • SBOM format, access route, update expectations and the internal system that consumes it;
  • contractual reporting, remediation, update and evidence commitments;
  • any exception, compensating controls and approval by the enterprise risk owner; and
  • the post-award monitoring owner and escalation path.

This record distinguishes an informed business decision from an undocumented purchase, while preserving the jurisdictional distinction between guidance, contract terms and binding product regulation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.