Government Guidance

Public guidance increasingly asks technology producers to address memory safety, secure-by-design development, and long-term product resilience.

Governments and national cybersecurity authorities are treating memory safety as a strategic product-security issue. Their guidance focuses on outcomes: preventing recurring vulnerability classes, reducing attacker access, maintaining products, and making progress measurable.

Guidance to follow

Several public sources help place memory safety and CHERI in a wider security strategy:

Where CHERI fits

Memory-safe languages are a strong default for new software. CHERI addresses a related problem: how to enforce fine-grained memory access in low-level and existing code, and how to limit what a compromised component can reach. A roadmap can use both.

For example, an organisation might require Rust for new network services, compile an established C library for a pure-capability target, and place that library in a compartment. The roadmap should say which code each measure covers and how success will be verified.

Turn guidance into action

  1. Measure the organisation’s memory-unsafe code and vulnerability baseline.
  2. Segment software by exposure, privilege, lifespan, and feasibility of change.
  3. Choose language migration, CHERI protection, compartmentalisation, replacement, or combined controls for each segment.
  4. Set milestones for prototypes, production coverage, and evidence.
  5. Publish progress and limitations in language that customers can verify.

Guidance is not the same as law. Check the current source, applicable jurisdiction, and sector obligations before relying on it for compliance.

Where next

Cybersecurity law increasingly places responsibility on manufacturers, service providers, operators, and senior leaders to manage risk across the product or service lifecycle.

Cybersecurity Regulation →