In 2025, software procurement was a practical security lever: buyers could vet products before purchase, require evidence of secure development, put security expectations into contracts, and make any accepted residual risk visible to the executive who owns it. This article treats 2025 as a historical frame. The EU Cyber Resilience Act (CRA) had been adopted but its main obligations were scheduled in stages after 2025; the dates below reflect the legal text available on 28 September 2026.
What an accountable buyer controls
Procurement does not make software vulnerability-free. It does determine which products enter an environment, what evidence a supplier must provide, what support is contractually expected, and who approves an exception when the risk is understood but accepted.
CISA’s Software Acquisition Guide for Government Enterprise Consumers describes this accountability model: involve internal security staff in product vetting, use requests for information (RFIs), requests for proposals (RFPs) and contract language to influence purchases, and obtain executive backing when purchasing decisions are enforced. If an insecure or otherwise risky product is selected, the decision and its inherent risk should be formally documented and approved by the senior business executives who own enterprise risk.
Start before the solicitation
Define the software’s consequences
- Identify the software’s business role and whether it is hosted, installed on endpoints, embedded in another product or delivered as a service.
- Map the data, credentials, network paths and administrative privileges it can access.
- Record the consequence of compromise, outage, manipulation or loss of supplier support.
- List important dependencies and integration points so that the review covers the system you will actually operate, not only the vendor’s product description.
Put security in the requirements
Bring security reviewers into the requirements and evaluation process before award. Describe the evidence, reporting, update support and remediation expectations that match the product’s role and consequences. CISA’s guidance supports using the solicitation itself to influence supplier behavior; it does not provide a universal clause set that fits every purchase.
#1 Best Overall
- PKI FIDO2 SECURITY KEY: This USB-A security key combines X509 digital certificates (PKI) and FIDO for maximum protection. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Linux and USB-A devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, ensuring secure use across various platforms, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
Ask suppliers for evidence, not promises
NIST’s Software Cybersecurity for Producers and Purchasers was issued under Executive Order 14028, section 4(e), to help federal procurement staff know what information to request from software producers about secure-development practices. The page was created on 1 February 2022 and updated on 5 May 2022.
For a purchase, request a clear description of the supplier’s development and security practices and any relevant evidence or attestation. Define what the evidence covers, which product and version it concerns, the period assessed and any exclusions. An attestation supports an assurance process; it is not a guarantee that the software contains no vulnerabilities.
Rank #2
- PKI FIDO2 SECURITY KEY: This USB-A security key combines X509 digital certificates (PKI) and FIDO for maximum protection. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Linux and USB-A devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, ensuring secure use across various platforms, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
Use an SBOM as an operating input
An SBOM is a formal record of software components and supply-chain relationships. Where appropriate, require access in a machine-readable format and clarify how the information will be delivered, updated and stored. NIST’s SBOM guidance describes repositories, enrichment with context, integration with vulnerability detection and continuing risk monitoring.
The operational test is whether the buyer can use the data. An organization that cannot ingest, analyze and act on an SBOM is unlikely to improve its supply-chain risk posture. Assign an owner and connect the SBOM to asset records, vulnerability alerting and remediation workflows before treating delivery as a completed control.
Rank #3
- PKI FIDO2 SECURITY KEY: This USB-C security key combines X509 digital certificates (PKI) and FIDO to support multiple use cases with one single authenticator. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
Make expectations enforceable after selection
Contract for the product’s risk
Tailor terms to the software and its exposure. Potential subjects include vulnerability and incident reporting, remediation targets, supported versions, security update delivery, cooperation with investigations, continuing evidence delivery and SBOM access. The precise obligations should follow the buyer’s requirements and negotiating authority; neither the cited CISA guide nor the NIST material establishes a universal checklist.
Record accepted exceptions
If the business chooses a product with material known or inherent risk, create a decision record that identifies the product, the risk, the rationale, compensating measures and the executive who approved acceptance. Risk acceptance belongs with the enterprise risk owner, not solely with a procurement desk or technical reviewer.
Rank #4
- PKI FIDO2 SECURITY KEY: This USB-C security key combines X509 digital certificates (PKI) and FIDO to support multiple use cases with one single authenticator. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
Keep the review alive after award
Procurement is a continuing relationship rather than a one-time questionnaire. Maintain the supplier evidence and SBOM information, watch for vulnerability notices and product changes, and route findings to the teams that can prioritize remediation, compensating controls or replacement. This monitoring only works when the organization has the capability and authority to act on the information it receives.
Procurement guidance and product regulation are different mechanisms
| Question | Buyer-led procurement guidance | EU Cyber Resilience Act |
|---|---|---|
| Who carries the duty? | The purchaser controls solicitation, evaluation, contracting and any risk-acceptance decision. | The regulation places obligations on economic operators for products with digital elements within its scope. |
| What is demanded? | Information about secure development, evidence or attestations, SBOM access, contract commitments and governance. | Product cybersecurity requirements, including risk-based measures and, where applicable, availability without known exploitable vulnerabilities and secure-by-default configuration. |
| Where does it apply? | NIST and CISA materials have federal or enterprise audiences; they are not automatically binding on every public or private buyer. | Products with digital elements that fall within the CRA’s EU scope. |
| When does it apply? | It can inform a buyer’s current process, subject to the buyer’s jurisdiction and policy. | Application is staged under Article 71 rather than beginning wholesale in 2025. |
How the U.S. sources fit together
NIST purchaser guidance
NIST’s purchaser-facing guidance is an evidence-request framework for federal agency staff. It is useful for structuring supplier questions and assurance reviews, but it does not turn every recommendation into a statutory obligation for all government, business or consumer purchases.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCISA enterprise acquisition guidance
CISA’s guide supplies the accountability pattern: vet with security staff, use RFIs, RFPs and contracts to set expectations, secure executive support for enforcement, and document and approve the risk when a risky product is chosen. Its July 2024 publication path makes it a current policy reference for that approach, not a substitute for the terms governing a particular transaction.
Federal supply-chain acquisition context
GSAM Subpart 504.70 describes federal agency responsibilities for managing cyber-supply-chain risk in federal information systems. It is one part of the federal acquisition framework. For a named agency, contract or clause, consult the live provision and the applicable transaction-specific requirements rather than treating this subpart as a complete statement of every federal, state, local or private-sector duty.
CRA dates a 2025 buyer should not blur
| Date | Provision | What it means for a 2025 retrospective |
|---|---|---|
| 11 June 2026 | Chapter IV, Articles 35–51 | These provisions were scheduled to apply after 2025. |
| 11 September 2026 | Article 14 reporting obligations | The reporting start date was after 2025 and should not be described as a 2025 obligation. |
| 11 December 2027 | General application under Article 71 | The CRA’s general requirements were not generally applicable in 2025. |
Regulation (EU) 2024/2847 was adopted on 23 October 2024 and published on 20 November 2024. Because amendments or implementation details can change, verify the current EUR-Lex text and application dates when making a live compliance decision.
Keep an auditable procurement file
A defensible decision record should let a later reviewer follow the chain from business need to residual risk. Retain:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute- the software role, data access, deployment model and consequence assessment;
- security requirements and the identity of the security reviewer;
- supplier responses, evidence scope and attestation limitations;
- SBOM format, access route, update expectations and the internal system that consumes it;
- contractual reporting, remediation, update and evidence commitments;
- any exception, compensating controls and approval by the enterprise risk owner; and
- the post-award monitoring owner and escalation path.
This record distinguishes an informed business decision from an undocumented purchase, while preserving the jurisdictional distinction between guidance, contract terms and binding product regulation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




