The Cybersecurity and Infrastructure Security Agency (CISA) has launched a new Software Acquisition Guide: Supplier Response Web Tool to strengthen cybersecurity in software procurement, reports Infosecurity Magazine. The resource is designed for IT leaders, procurement officers, and software vendors who need practical ways to assess supplier risk and software assurance.The tool builds on CISA’s existing Software Acquisition Guide, but instead of a static document and spreadsheet, it offers an interactive, digital platform. Users can move through adaptive sections tailored to their procurement context, highlight the most relevant security questions, and generate exportable summaries for decision-makers. By doing so, CISA makes it easier for non-technical acquisition professionals to integrate cybersecurity into their due diligence.Interest in CISA’s framework has been growing, with more than 10,000 users and 4,000 downloads of the original guide and spreadsheet. The shift to a web-based format reflects the growing demand for accessible resources that help federal, state, and local governments, as well as small and mid-sized businesses, adopt stronger procurement practices without requiring deep technical expertise.This release comes at a time when software supply chain vulnerabilities remain a common entry point for major cyberattacks. By digitizing its acquisition framework, CISA aims to provide organizations with a more practical way to build resilience into procurement. The tool complements other CISA initiatives, such as the Secure by Demand Guide, and continues the agency’s push to embed secure-by-design and secure-by-default principles into everyday technology buying decisions.