The software development cycle goes through many processes, and HLSD and LLSD are just two parts.
The Software Development Life Cycle (SDLC) goes through various phases like planning, requirements assessment, analysis, design, execution, documentation, testing, etc. Each phase is further divided into tasks with properly defined objectives and results.
Analysis and Design are phases where the actual architecture, working model, and execution process of building a software product is laid down.
Two crucial steps in these phases are High-Level System Design and Low-Level System Design.
High-Level Design (HLD) provides a comprehensive overview of the software development process along with the system architecture, applications, database management, and complete flowchart of the system and navigation. It’s a blueprint that consolidates the various steps and modules, their objectives, variable components, results, architecture, and timeline to develop the software. HLD translates a business plan into a software product or service.
Examples of HLD in software development include system architecture documents, app development flowcharts, etc.
Low-Level Design (LLD) deals with the planning, coding, and execution of the various components, modules, and steps in the HLD, at an individual level. Each module in an HLD has a unique LLD document that provides comprehensive details about how the module will be coded, executed, tested for quality, and integrated into the larger program. LLD provides actionable plans by deconstructing HLD components into working solutions.
Examples of LLD in software development include cart integration, security testing, user interface design, etc.
HLD and LLD also serve different functions and purposes like high-level programming languages and low-level programming languages.
HLD is a macro-level design that provides a bird’s eye view of the software development process. It includes diagrams, flowcharts, navigational details, and other technical requirements that will form the crux of the development process.
In addition to flowcharts, diagrams, navigational information, and technical requirements, LLD also has comprehensive information about the step-by-step execution of each component of the HLD. It deals with software development at the micro-level.
Every component of an HLD has a unique LLD document.
HLD precedes the LLD phase. Once the HLD is in place and approved for execution, work on the individual LLDs can begin.
HLD begins once the planning and requirements stages are dealt with and has no other dependencies.
On the other hand, LLD needs to be executed in a particular order. Some modules must await execution until others have been completed.
LLD falls under the Design phase of the SDLC, whereas the HLD falls under the Analysis phase of the SDLC.
Solution architects are responsible for creating an HLD document. It can have internal and external stakeholders like the review team that takes cognizance of the software metrics, the design team, clients, and managers.
LLD is handled by software developers, web admins, security engineers, etc., who are part of the company or vendor teams. LLDs are generally restricted to internal stakeholders.
HLD documents have the target audience of managers, clients, and software development teams.
Software engineers, coders, testers, and developers working on the project are the target audience for LLD documents.
Software design documents outline the structural, functional, and logical aspects of developing a software product or service in addition to the technical requirements and other implementation details. Whether the design deals with macro-level or micro-level execution, programmers and other stakeholders should knowq and understand the scope and the various steps of the software development process.
Former corporate communications specialist who's worked with Uber, Google, and TCS, Al Kaatib has ten years of experience as a freelance writer specializing in B2B and B2C content.
An official website of the United States government Here’s how you know
This joint Cybersecurity Advisory (CSA) was coauthored by cybersecurity authorities of the United States, Australia, Canada, New Zealand, and the United Kingdom: the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), Australian Cyber Security Centre (ACSC), Canadian Centre for Cyber Security (CCCS), New Zealand National Cyber Security Centre (NZ NCSC), and United Kingdom’s National Cyber Security Centre (NCSC-UK). This advisory provides details on the top 15 Common Vulnerabilities and Exposures (CVEs) routinely exploited by malicious cyber actors in 2021, as well as other CVEs frequently exploited.
U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities assess, in 2021, malicious cyber actors aggressively targeted newly disclosed critical software vulnerabilities against broad target sets, including public and private sector organizations worldwide. To a lesser extent, malicious cyber actors continued to exploit publicly known, dated software vulnerabilities across a broad spectrum of targets.
The cybersecurity authorities encourage organizations to apply the recommendations in the Mitigations section of this CSA. These mitigations include applying timely patches to systems and implementing a centralized patch management system to reduce the risk of compromise by malicious cyber actors.
Download the Joint Cybersecurity Advisory: 2021 top Routinely Exploited Vulnerabilities (pdf, 777kb).
Globally, in 2021, malicious cyber actors targeted internet-facing systems, such as email servers and virtual private network (VPN) servers, with exploits of newly disclosed vulnerabilities. For most of the top exploited vulnerabilities, researchers or other actors released proof of concept (POC) code within two weeks of the vulnerability’s disclosure, likely facilitating exploitation by a broader range of malicious actors.
To a lesser extent, malicious cyber actors continued to exploit publicly known, dated software vulnerabilities—some of which were also routinely exploited in 2020 or earlier. The exploitation of older vulnerabilities demonstrates the continued risk to organizations that fail to patch software in a timely manner or are using software that is no longer supported by a vendor.
Table 1 shows the top 15 vulnerabilities U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities observed malicious actors routinely exploiting in 2021, which include:
Three of the top 15 routinely exploited vulnerabilities were also routinely exploited in 2020: CVE-2020-1472, CVE-2018-13379, and CVE-2019-11510. Their continued exploitation indicates that many organizations fail to patch software in a timely manner and remain vulnerable to malicious cyber actors.
Table 1: Top 15 Routinely Exploited Vulnerabilities in 2021
CVE
Vulnerability Name
Vendor and Product
Type
CVE-2021-44228
Log4Shell
Apache Log4j
Remote code execution (RCE)
CVE-2021-40539
Zoho ManageEngine AD SelfService Plus
RCE
CVE-2021-34523
ProxyShell
Microsoft Exchange Server
Elevation of privilege
CVE-2021-34473
ProxyShell
Microsoft Exchange Server
RCE
CVE-2021-31207
ProxyShell
Microsoft Exchange Server
Security feature bypass
CVE-2021-27065
ProxyLogon
Microsoft Exchange Server
RCE
CVE-2021-26858
ProxyLogon
Microsoft Exchange Server
RCE
CVE-2021-26857
ProxyLogon
Microsoft Exchange Server
RCE
CVE-2021-26855
ProxyLogon
Microsoft Exchange Server
RCE
CVE-2021-26084
Atlassian Confluence Server and Data Center
Arbitrary code execution
CVE-2021-21972
VMware vSphere Client
RCE
CVE-2020-1472
ZeroLogon
Microsoft Netlogon Remote Protocol (MS-NRPC)
Elevation of privilege
CVE-2020-0688
Microsoft Exchange Server
RCE
CVE-2019-11510
Pulse Secure Pulse Connect Secure
Arbitrary file reading
CVE-2018-13379
Fortinet FortiOS and FortiProxy
Path traversal
In addition to the 15 vulnerabilities listed in table 1, U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities identified vulnerabilities, listed in table 2, that were also routinely exploited by malicious cyber actors in 2021.
These vulnerabilities include multiple vulnerabilities affecting internet-facing systems, including Accellion File Transfer Appliance (FTA), Windows Print Spooler, and Pulse Secure Pulse Connect Secure. Three of these vulnerabilities were also routinely exploited in 2020: CVE-2019-19781, CVE-2019-18935, and CVE-2017-11882.
Table 2: Additional Routinely Exploited Vulnerabilities in 2021
CVE
Vendor and Product
Type
CVE-2021-42237
Sitecore XP
RCE
CVE-2021-35464
ForgeRock OpenAM server
RCE
CVE-2021-27104
Accellion FTA
OS command execution
CVE-2021-27103
Accellion FTA
Server-side request forgery
CVE-2021-27102
Accellion FTA
OS command execution
CVE-2021-27101
Accellion FTA
SQL injection
CVE-2021-21985
VMware vCenter Server
RCE
CVE-2021-20038
SonicWall Secure Mobile Access (SMA)
RCE
CVE-2021-40444
Microsoft MSHTML
RCE
CVE-2021-34527
Microsoft Windows Print Spooler
RCE
CVE-2021-3156
Sudo
Privilege escalation
CVE-2021-27852
Checkbox Survey
Remote arbitrary code execution
CVE-2021-22893
Pulse Secure Pulse Connect Secure
Remote arbitrary code execution
CVE-2021-20016
SonicWall SSLVPN SMA100
Improper SQL command neutralization, allowing for credential access
CVE-2021-1675
Windows Print Spooler
RCE
CVE-2020-2509
QNAP QTS and QuTS hero
Remote arbitrary code execution
CVE-2019-19781
Citrix Application Delivery Controller (ADC) and Gateway
Arbitrary code execution
CVE-2019-18935
Progress Telerik UI for ASP.NET AJAX
Code execution
CVE-2018-0171
Cisco IOS Software and IOS XE Software
Remote arbitrary code execution
CVE-2017-11882
Microsoft Office
RCE
CVE-2017-0199
Microsoft Office
RCE
Note: see CISA Capacity Enhancement Guide – Implementing Strong Authentication and ACSC guidance on Implementing Multi-Factor Authentication for more information on hardening authentication systems.
The information in this report is being provided “as is” for informational purposes only. CISA, the FBI, NSA, ACSC, CCCS, NZ NCSC, and NCSC-UK do not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring.
This document was developed by U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities in furtherance of their respective cybersecurity missions, including their responsibilities to develop and issue cybersecurity specifications and mitigations.
[1] CISA’s Apache Log4j Vulnerability Guidance
CVE
Vendor
Affected Products
Patch Information
Resources
CVE-2021-42237
Sitecore
Sitecore XP 7.5.0 – Sitecore XP 7.5.2
Sitecore XP 8.0.0 – Sitecore XP 8.2.7
Sitecore Security Bulletin SC2021-003-499266
ACSC Alert Active Exploitation of vulnerable Sitecore Experience Platform Content Management Systems
CVE-2021-35464
ForgeRock
Access Management (AM) 5.x, 6.0.0.x, 6.5.0.x, 6.5.1, 6.5.2.x and 6.5.3
OpenAM 9.x, 10.x, 11.x, 12.x and 13.x
ForgeRock AM Security Advisory #202104
ACSC Advisory Active exploitation of ForgeRock Access Manager / OpenAM servers
CCCS ForgeRock Security Advisory
CVE-2021-27104
Accellion
FTA 9_12_370 and earlier
Accellion Press Release: Update to Recent FTA Security Incident
Joint CSA Exploitation of Accellion File Transfer Appliance
ACSC Alert Potential Accellion File Transfer Appliance compromise
CVE-2021-27103
FTA 9_12_411 and earlier
CVE-2021-27102
FTA versions 9_12_411 and earlier
CVE-2021-27101
FTA 9_12_370 and earlier
CVE-2021-21985
VMware
vCenter Server 7.0, 6.7, 6.5
Cloud Foundation (vCenter Server) 4.x and 3.x
VMware Advisory VMSA-2021-0010
CCCS VMware Security Advisory
CVE-2021-21972
VMware
vCenter Server 7.0, 6.7, 6.5
Cloud Foundation (vCenter Server) 4.x and 3.x
VMware Advisory VMSA-2021-0002
ACSC Alert VMware vCenter Server plugin remote code execution vulnerability
CCCS VMware Security Advisory
CCCS Alert APT Actors Target U.S. and Allied Networks – Update 1
CVE-2021-20038
SonicWall
SMA 100 Series (SMA 200, 210, 400, 410, 500v), versions 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv
SonicWall Security Advisory SNWLID-2021-0026
ACSC Alert Remote code execution vulnerability present in SonicWall SMA 100 series appliances
CCCS SonicWall Security Advisory
CVE-2021-44228
Apache
Log4j, all versions from 2.0-beta9 to 2.14.1
For other affected vendors and products, see CISA’s GitHub repository.
Log4j: Apache Log4j Security Vulnerabilities
For additional information, see joint CSA: Mitigating Log4Shell and Other Log4j-Related Vulnerabilities
CISA webpage Apache Log4j Vulnerability Guidance
CCCS Active exploitation of Apache Log4j vulnerability – Update 7
CVE-2021-40539
Zoho ManageEngine
ADSelfService Plus version 6113 and prior
Zoho ManageEngine: ADSelfService Plus 6114 Security Fix Release
Joint CSA APT Actors Exploiting Newly Identified Vulnerability in ManageEngine ADSelfService Plus
CCCS Zoho Security Advisory
CVE-2021-40444
Microsoft
Multiple Windows products; see Microsoft Security Update Guide: MSHTML Remote Code Execution Vulnerability, CVE-2021-40444
Microsoft Security Update Guide: MSHTML Remote Code Execution Vulnerability, CVE-2021-40444
CVE-2021-34527
Microsoft
Multiple Windows products; see Microsoft Security Update Guide: Windows Print Spooler Remote Code Execution Vulnerability, CVE-2021-34527
Microsoft Security Update Guide: Windows Print Spooler Remote Code Execution Vulnerability, CVE-2021-34527
Joint CSA Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and “PrintNightmare” Vulnerability
CCCS Alert Windows Print Spooler Vulnerability Remains Unpatched – Update 3
CVE-2021-34523
Microsoft
Microsoft Exchange Server 2013 Cumulative Update 23
Microsoft Exchange Server 2016 Cumulative Updates 19 and 20
Microsoft Exchange Server 2019 Cumulative Updates 8 and 9
Microsoft Security Update Guide: Microsoft Exchange Server Elevation of Privilege Vulnerability, CVE-2021-34523
Joint CSA Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities
ACSC Alert Microsoft Exchange ProxyShell Targeting in Australia
CVE-2021-34473
Microsoft
Multiple Exchange Server versions; see: Microsoft Security Update Guide: Microsoft Exchange Server Remote Code Execution Vulnerability, CVE-2021-34473
Microsoft Security Update Guide: Microsoft Exchange Server Remote Code Execution Vulnerability, CVE-2021-34473
CVE-2021-31207
Microsoft
Multiple Exchange Server versions; see Microsoft Update Guide: Microsoft Exchange Server Security Feature Bypass Vulnerability, CVE-2021-31207
Microsoft Update Guide: Microsoft Exchange Server Security Feature Bypass Vulnerability, CVE-2021-31207
CVE-2021-3156
Sudo
Sudo before 1.9.5p2
Sudo Stable Release 1.9.5p2
CVE-2021-27852
Checkbox Survey
Checkbox Survey versions prior to 7
CVE-2021-27065
Microsoft Exchange Server
Multiple versions; see: Microsoft Security Update Guide: Microsoft Exchange Server Remote Code Execution Vulnerability, CVE-2021-27065
Microsoft Security Update Guide: Microsoft Exchange Server Remote Code Execution Vulnerability, CVE-2021-27065
CISA Alert: Mitigate Microsoft Exchange Server Vulnerabilities
ACSC Advisory Active exploitation of Vulnerable Microsoft Exchange servers
CCCS Alert Active Exploitation of Microsoft Exchange Vulnerabilities – Update 4
CVE-2021-26858
Microsoft
Exchange Server, multiple versions; see Microsoft Security Update Guide: Microsoft Exchange Server Remote Code Execution Vulnerability, CVE-2021-26858
Microsoft Security Update Guide: Microsoft Exchange Server Remote Code Execution Vulnerability, CVE-2021-26858
CVE-2021-26857
Microsoft
Exchange Server, multiple versions; see Microsoft Security Update Guide: Microsoft Exchange Server Remote Code Execution Vulnerability, CVE-2021-26857
Microsoft Security Update Guide: Microsoft Exchange Server Remote Code Execution Vulnerability, CVE-2021-26857
CVE-2021-26855
Microsoft
Exchange Server, multiple versions; see Microsoft Security Update Guide: Microsoft Exchange Server Remote Code Execution Vulnerability, CVE-2021-26855
Microsoft Security Update Guide: Microsoft Exchange Server Remote Code Execution Vulnerability, CVE-2021-26855
CVE-2021-26084
Jira Atlassian
Confluence Server and Data Center, versions 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
Jira Atlassian: Confluence Server Webwork OGNL injection – CVE-2021-26084
ACSC Alert Remote code execution vulnerability present in certain versions of Atlassian Confluence
CCCS Atlassian Security Advisory
CVE-2021-22893
Pulse Secure
PCS 9.0R3/9.1R1 and Higher
Pulse Secure SA44784 – 2021-04: Out-of-Cycle Advisory: Multiple Vulnerabilities Resolved in Pulse Connect Secure 9.1R11.4
CCCS Alert Active Exploitation of Pulse Connect Secure Vulnerabilities – Update 1
CVE-2021-20016
SonicWall
SMA 100 devices (SMA 200, SMA 210, SMA 400, SMA 410, SMA 500v)
SonicWall Security Advisory SNWLID-2021-0001
CVE-2021-1675
Microsoft
Multiple Windows products; see Microsoft Security Update Guide Windows Print Spooler Remote Code Execution Vulnerability, CVE-2021-1675
Microsoft Security Update Guide: Windows Print Spooler Remote Code Execution Vulnerability, CVE-2021-1675
CCCS Alert Windows Print Spooler Vulnerability Remains Unpatched – Update 3
CVE-2020-2509
QNAP
QTS, multiple versions; see QNAP: Command Injection Vulnerability in QTS and QuTS hero
QuTS hero h4.5.1.1491 build 20201119 and later
QNAP: Command Injection Vulnerability in QTS and QuTS hero
CVE-2020-1472
Microsoft
Windows Server, multiple versions; see Microsoft Security Update Guide: Netlogon Elevation of Privilege Vulnerability, CVE-2020-1472
Microsoft Security Update Guide: Netlogon Elevation of Privilege Vulnerability, CVE-2020-1472
ACSC Alert Netlogon elevation of privilege vulnerability (CVE-2020-1472)
Joint CSA APT Actors Chaining Vulnerabilities Against SLTT, Critical Infrastructure, and Elections Organizations
CCCS Alert Microsoft Netlogon Elevation of Privilege Vulnerability – CVE-2020-1472 – Update 1
CVE-2020-0688
Microsoft
Exchange Server, multiple versions; see Microsoft Security Update Guide: Microsoft Exchange Validation Key Remote Code Execution Vulnerability, CVE-2020-0688
Microsoft Security Update Guide: Microsoft Exchange Validation Key Remote Code Execution Vulnerability, CVE-2020-0688
CISA Alert Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity
Joint CSA Russian State-Sponsored Cyber Actors Target Cleared Defense Contractor Networks to Obtain Sensitive U.S. Defense Information and Technology
CCCS Alert Microsoft Exchange Validation Key Remote Code Execution Vulnerability
CVE-2019-19781
Citrix
ADC and Gateway version 13.0 all supported builds before 13.0.47.24
NetScaler ADC and NetScaler Gateway, version 12.1 all supported builds before 12.1.55.18; version 12.0 all supported builds before 12.0.63.13; version 11.1 all supported builds before 11.1.63.15; version 10.5 all supported builds before 10.5.70.12
SD-WAN WANOP appliance models 4000-WO, 4100-WO, 5000-WO, and 5100-WO all supported software release builds before 10.2.6b and 11.0.3b
Citrix Security Bulletin CTX267027
Joint CSA APT Actors Chaining Vulnerabilities Against SLTT, Critical Infrastructure, and Elections Organizations
CISA Alert Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity
CCCS Alert Detecting Compromises relating to Citrix CVE-2019-19781
CVE-2019-18935
Progress Telerik
UI for ASP.NET AJAX through 2019.3.1023
Telerik UI for ASP.NET AJAX Allows JavaScriptSerializer Deserialization
ACSC Alert Active exploitation of vulnerability in Microsoft Internet Information Services
CVE-2019-11510
Pulse Secure
Pulse Connect Secure 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4
Pulse Secure: SA44101 – 2019-04: Out-of-Cycle Advisory: Multiple vulnerabilities resolved in Pulse Connect Secure / Pulse Policy Secure 9.0RX
CISA Alert Continued Exploitation of Pulse Secure VPN Vulnerability
CISA Alert Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity
ACSC Advisory Recommendations to mitigate vulnerability in Pulse Connect Secure VPN Software
Joint CSA APT Actors Chaining Vulnerabilities Against SLTT, Critical Infrastructure, and Elections Organizations
CCCS Alert APT Actors Target U.S. and Allied Networks – Update 1
CVE-2018-13379
Fortinet
FortiProxy 2.0.2, 2.0.1, 2.0.0, 1.2.8, 1.2.7, 1.2.6, 1.2.5, 1.2.4, 1.2.3, 1.2.2, 1.2.1, 1.2.0, 1.1.6
Fortinet FortiGuard Labs: FG-IR-20-233
Joint CSA Russian State-Sponsored Cyber Actors Target Cleared Defense Contractor Networks to Obtain Sensitive U.S. Defense Information and Technology
Joint CSA Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities
Joint CSA APT Actors Chaining Vulnerabilities Against SLTT, Critical Infrastructure, and Elections Organizations
ACSC Alert APT exploitation of Fortinet Vulnerabilities
CCCS Alert Exploitation of Fortinet FortiOS vulnerabilities (CISA, FBI) – Update 1
CVE-2018-0171
Cisco
See Cisco Security Advisory: cisco-sa-20180328-smi2
Cisco Security Advisory: cisco-sa-20180328-smi2
CCCS Action Required to Secure the Cisco IOS and IOS XE Smart Install Feature
CVE-2017-11882
Microsoft
Office, multiple versions; see Microsoft Security Update Guide: Microsoft Office Memory Corruption Vulnerability, CVE-2017-11882
Microsoft Security Update Guide: Microsoft Office Memory Corruption Vulnerability, CVE-2017-11882
CCCS Alert Microsoft Office Security Update
CVE-2017-0199
Microsoft
Multiple products; see Microsoft Security Update Guide: Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows, CVE-2017-0199
Microsoft Security Update Guide: Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows, CVE-2017-0199
CCCS Microsoft Security Updates
U.S. organizations: all organizations should report incidents and anomalous activity to CISA 24/7 Operations Center at report@cisa.gov or (888) 282-0870 and/or to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov. When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact. For NSA client requirements or general cybersecurity inquiries, contact Cybersecurity_Requests@nsa.gov. Australian organizations: visit cyber.gov.au or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. Canadian organizations: report incidents by emailing CCCS at contact@cyber.gc.ca. New Zealand organizations: report cyber security incidents to incidents@ncsc.govt.nz or call 04 498 7654. United Kingdom organizations: report a significant cyber security incident: ncsc.gov.uk/report-an-incident (monitored 24 hours) or, for urgent assistance, call 03000 200 973.
This product is provided subject to this Notification and this Privacy & Use policy.
Please share your thoughts.
We recently updated our anonymous product survey; we’d welcome your feedback.
(888)282-0870
Send us email
Download PGP/GPG keys
Submit website feedback
Receive security alerts, tips, and other updates.
CISA is part of the Department of Homeland Security
By clicking “TRY IT”, I agree to receive newsletters and promotions from Money and its partners. I agree to Money’s Terms of Use and Privacy Notice and consent to the processing of my personal information.
Many companies featured on Money advertise with us. Opinions are our own, but compensation and
in-depth research determine where and how companies may appear. Learn more about how we make money.
https://money.com/best-construction-project-management-software/
Today’s construction companies rely on digital solutions more than ever to manage projects across their entire project lifecycle. From bidding on opportunities to creating estimates, developing project plans, tracking labor and material usage and even marketing for new businesses, the opportunity to automate and digitize work is significant.
We picked the best construction project management software by focusing on several critical factors, including price, user feedback and features. Read on to learn more about the best construction project management software.
Best Construction Project Management Software Reviews
- Industry focused
- Competitive pricing tiers
- Mobile capability
- Great customer reviews
- Document storage is lacking
- Can be expensive to scale
- Users say the app can be unreliable in the field
Why we chose it: Fieldwire, a Group Company of Hilti, gives users the tools to build project plans, view and share drawings, create schedules, manage punch lists, conduct inspections and more, making it the best industry solution software.
FieldWire offers solutions for several management types, including owners, general and specialty contractors, architects and designers. We like the focus on solutions specific to the construction industry, with helpful features like an RFI management tool, an as-built drawings viewing and editing feature, and a BIM viewer with an in-app management tool. FieldWire has an open API, allowing companies to integrate the software they’re using today for a seamless experience.
Pricing is competitive; we like that the basic, no-cost plan offers up to five users, whereas other companies touting a ‘free’ plan might only offer one free license. The Premier plan, the top plan offered by FieldWire, comes in at an affordable $99 a month and includes the end-to-end feature set.
A majority of online reviews say FieldWire is intuitive, user-friendly and simple to implement. They like that the app is easy to use in the field and appreciate key features like the ability to upload photos and videos from the job site. Being able to repeat schedules and build from a project management template is another feature users highlight. While some users say that the app can occasionally freeze in the field, most say the FieldWire app is a critical part of their day-to-day construction business.
- Unlimited cloud-based storage
- In-app photo markup and camera
- No device limits
- Sophisticated people management and scheduling
- Lacking some features found in other software
- No end-to-end dashboard
- Knowledge Base can use more content
Why we chose it: Contractor Foreman is our pick as the best project management software for unlimited storage — key for companies hoping to store all relevant data and documents — including photos, files, reports, forms, checklists, proposals and drawings — all in one place.
Contractor Foreman is a cloud-based software offering unlimited cloud-based storage for a wide range of documents, including PDFs, Excel files, photos, Word documents and more. Documents can be edited within the platform, with helpful features like in-application photo markup, bulk image download, drawing and PDF editing. The in-app camera is a handy feature to easily bring photos into the tool. However, the software lacks a few features and modules we’ve seen elsewhere, like bidding and estimation tools and a dedicated quality check module.
Pricing is comparable to others in the industry, with tiers starting at $49 a month and an option to save money by paying an annual fee. We like the unique 100-day money-back guarantee, which is more competitive than others offering a 30-day software warranty.
In online reviews, most users like the unlimited document storage and the ability to save and view legacy documents, photos and drawings. While most say it’s easy to use, some consumers have noted that Contractor Foreman’s Knowledge Base needs more content to help users on their way.
- Affordable price points
- Drag-and-drop scheduling
- Built-in CRM and marketing tool
- Specific features useful for home builders and remodelers
- No integration with other client relationship management tools
- Lacking some features
- No general contractor management type
Why we chose it: The construction company on a budget will appreciate BuilderTrend, our pick for the best prices for construction project management software.
Pricing is based on three tiers:
BuilderTrend also offers a 30-day no-penalty trial period — helpful for small businesses just starting their construction planning software journeys. Users say they like the affordability, scalability and in-app marketing. However, they feel the software could improve issues related to the core tenets of project management, with the need for more sophisticated document sharing and editing, and project tracking. There’s also a lack of essential features for general contractors, a large population that regularly uses construction management software.
While its features and functionality might be less sophisticated than other software providers, BuilderTrend provides the critical components of good construction project management software at the right price point.
Why we chose it: Part project management software, part goal setting program, and part chat platform for project participants — Clickup has a little of everything construction project managers need in a software solution, making it our pick for Best Features.
The platform is full of handy tools and applications for every project management and planning step. A few of our favorite highlights include:
Clickup offers a free basic program for individual use, which could be helpful to the individual contractor hoping to manage their work. From there, pricing increases based on the number of users and features available. Enterprise pricing is also available for larger contracting organizations.
Users reviewing the software say it is well built for what it does but can be overwhelming for someone simply hoping to estimate and track their time and to-do lists. Compared to other software on our list, ClickUp does not provide some of the construction-focused tools a user might require.
- Easy-to-use project management tools
- User-friendly dashboard and collaboration
- Rich integrations library
- Hundreds of workflows
- General software not customized for construction
- Expensive price point for multiple users
- Less emphasis on pure document management
Why we chose it: Monday.com is a project management platform popular with teams of all sizes due to its ease of use and comprehensive project and task management tools. Monday.com is a good software choice for pure project management functionality because of these tools.
Key features helpful to the construction industry include:
Pricing is not as affordable as other software options on this list. While there is a free option for individual use, the price escalates quickly for multiple users. However, project management through Monday.com might be a good choice if a company’s focus is to grow.
We found online reviews from users across multiple industries that rave about the user-friendly experience, intuitive interfaces and attractive design. Some have noted that the task tracking features need work but that, overall, the project management tools on Monday.com can’t be beaten.
- Multiple project tracking styles, including Gantt, Kanban and calendar
- Sophisticated process and workflow automation
- Visual workload tracker
- Reasonable and variable price points based on team size
- General software not customized for construction
- Better for complex projects
- Most integrations available for higher-tier plans
Why we chose it: While it’s not a dedicated project planning software for the construction management industry, Asana helps companies tackle large-scale projects with sophisticated project-management technologies and techniques, including an automated workflow builder, to keep your teams on track.
We picked Asana as the best choice for bigger-picture planning because of the wide variety of views it offers users, including timelines in Gantt chart form, a shared calendar and Kanban boards, allowing you to plan several months ahead and track multiple busy schedules. The highly visual presentation of information in various forms is an excellent way for teams to get on the same page and plan multiple work streams for the coming months and even years.
Asana also provides a few handy holistic features to look at project planning and success at a macro level. The Goals feature gives teams a shared, transparent space for long-term planing, and the reporting tool gives project managers the feedback they need to track progress rates and forecast future workload and output. When giving product feedback, users say they love the ability to build a multi-year project and track its progress in real-time.
Pricing is less affordable than others on the list; like many, a free version is available, but the scalability can come with a hefty price tag. Some users reviewing the software have remarked that the functionality and the price tag might not always match up.
- Project and marketing management in one app
- Powerful advertising opportunities
- Strong technology that works well on mobile
- Not a fit for commercial construction
- Higher price point
- Some report poor customer service
Why we chose it: Houzz Pro is a segment of Houzz, the platform design and sourcing software that offers project management and marketing support for architects, homeowners, residential contractors and interior designers. Features include a point-and-click estimation generator and a client-side dashboard allowing your customers to see real-time progress.
What sets Houzz apart is its sophisticated lead generation and management functionality. Beyond the CRM and lead generation tools seen in other platforms, Houzz Plus offers targeted local advertising via their app. Companies can pay to be featured as a premium listing in their ‘Find Pros’ section, which connects individuals and companies with contractors. Houzz Pro’s website services might also be helpful for a construction company struggling to build an online presence and convert its digital customer inquiries into leads.
While Houzz Pro does offer a basic toolset at no cost, its Starter, Essential and Ultimate price points might be too high for a smaller company. However, the cost of combining project management and marketing should be considered.
OpenDocMan is a simple, bare-bones document management solution that could work well for a small construction company looking just for document review and file organization. The idea of a free service is attractive, but the features are limited and the lack of a mobile app limits this program’s functionality.
A newer software solution on the market, Methvin shows promise but offers bare-bones functionality with a limited feature set. Users have noted that some basic features they would expect (copying plans, refining drawings, etc.) are missing.
PlanGrid, now part of the Autodesk Construction Cloud, is an app-based solution focused on streamlining workflows in the field. It has iterative features, positive customer reviews and a focus on mobile-first technology. However, the price point is high, and some users might not want to purchase Autodesk Build to access the PlanGrid app.
Procore checks many boxes for construction project management software as a full-suite solution with an industry focus. However, integrations are limited, the price point is high and users might not find every module useful.
Construction project management software is an app- or web-based digital tool to help construction companies manage some or all aspects of their work, including but not limited to:
Many construction-focused project management applications and software are available across the internet, each one with its own strengths and weaknesses. Some platforms promise an all-in-one solution touching every aspect of work for construction companies of all sizes, specialties and revenue streams. Others are hyper-focused on one specific aspect of the project management discipline, such as document workflow, bids and tenders, pre-construction estimation and more.
At its most basic level, construction project management software should be a tool that business owners, project managers and frontline construction managers use daily. It is also a valuable and critical part of companies’ business processes.
Project management software can work in a number of ways, depending on the type of software selected, the use case, the features deployed, the number of users in the system, active integrations and other factors. When thinking about how project management software works and optimizing your project management software for your company, think about how it may be used to help your business. For example:
Creating a checklist of the features and functionality your organization requires will help you narrow down the options available. From there, you’ll better understand how your chosen software works and how it can benefit you and your business.
Selecting the best construction project management software for your organization is a complex decision that involves carefully evaluating several factors. Beyond the basic criteria — like available features, cost and support — companies shopping for construction management software might want to think about usability, document management, integrations, lead generation and construction accounting management tools.
The best software shouldn’t require endless onboarding, extensive training and frequent customer service tickets with questions and clarifications. Construction professionals are busy and need an iterative and easy tool available on both browsers and mobile apps. The construction management software you choose should be user-friendly and straightforward to understand for users at all levels of technological experience.
Construction, like many industries, is full of documents to create, edit, distribute and manage. A crucial part of guiding a project is document management — from estimates to contracts to drawings, photos, permits, and invoices. The best software for construction project management should include workflows, storage and document management for your project work.
Users do not want to have to employ multiple programs, enter duplicate data entries into more than one platform, or complete other redundant tasks between systems. Integration between your construction management software and other software performing tangential tasks is critical. For the construction industry, some essential software integrations could include:
When selecting your software, you should understand what integrations exist today and the processes and costs for deploying these integrations. Do any of these integrations involve software you use now or hope to use in the future?
Many project management software packages offer built-in lead generation modules to support your marketing efforts. Having this data in sync with your project management plans can help in several ways.
First, you’ll be able to plan and forecast future projects against the marketing campaigns you plan to launch and measure the success of those campaigns versus booked customer projects. Syncing your marketing and lead generation campaigns with your project management software also ensures your customer information is all in one place, avoiding the need for duplicate data entry and redundant administrative work.
A critical component of project management involves financial considerations, including payments, costs and budgeting. A good software platform will help you analyze, plan and track your spending and payments to stay on budget.
We looked at key features, usability, customer reviews, pricing and management types to select the best project management software.
When considering software cost, it’s essential to understand a few important facets of what you’re paying for and your return on investment. From costs for add-on features, free trial periods and integration fees, cost was a critical part of these rankings.
As part of our methodology to pick the best construction software, we read customer reviews on the software sales sites and independent review message boards. The themes we found — particularly around feature availability and development, customer service and support, and in-the-field application — tell the story of the software’s success.
When searching for the best construction project management software, we looked at not only the key features available in each software suite but the usability and efficacy of these features in real-life applications.
Who is going to be working with the software every day? Who is managing the software and acting as the administrator? Consider what management types are available, if you can customize them and how they will scale with the growth of your organization as you select your software.
When identifying the best construction management software options, the platform’s ease of use is vital to consider. The best software should be mobile-responsive, support simple workflows and deliver a clean and simple user experience.
Connect
Physical Address
Money Group, LLC
Lots 81-82 Street C
Dorado, PR 00646
Mailing Address
Metro Office Park
7 calle 1, Suite 204
Guaynabo, PR 00968











