Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber- Enabled Activities
The order directs the Secretary of Commerce to propose regulations requiring U.S. cloud computing providers to verify the identities of foreign customers and maintain secure account records, and separately authorizes Commerce to block or restrict foreign access to U.S. cloud services when a country or individual is found to be enabling cyberattacks.
It builds on a national emergency declared in 2015 over malicious foreign cyber activity, targeting a specific gap: foreign actors who rent U.S. server infrastructure to launch attacks and then erase their tracks before investigators can act.
What this order does
What it orders
The order directs the Secretary of Commerce to propose regulations — within 180 days — requiring U.S. Infrastructure as a Service (IaaS) providers, meaning cloud computing companies that rent server capacity, to verify the identities of foreign customers and keep secure records covering payment details, contact information, and IP addresses. It also directs Commerce to propose separate regulations enabling the Secretary to impose special measures — including blocking or conditioning foreign access to U.S. cloud accounts — when a foreign country or individual is determined to be enabling malicious cyber activities. Exemptions are available for providers or account types that meet security best practices.
The Attorney General and Secretary of Homeland Security must engage cloud industry stakeholders within 120 days and submit a report to the President within 240 days recommending ways to expand voluntary information sharing among providers and with federal agencies. Critically, account-restriction special measures cannot be imposed until at least 180 days after the identity-verification regulations are finalized, meaning the order's most consequential restrictions depend entirely on future rulemaking outcomes.
Who it affects
U.S. cloud computing companies that rent server capacity to foreign customers, foreign individuals and entities that use U.S. cloud services, foreign resellers of U.S. cloud products, and federal agencies including Commerce, Justice, and Homeland Security directed to develop and implement the new rules.
Why it matters
Once regulations are finalized, foreign customers of U.S. cloud providers will face identity-verification requirements, and providers will carry new record-keeping obligations. Foreign individuals or jurisdictions linked to cyberattacks could ultimately be denied or restricted from accessing U.S. cloud infrastructure, raising compliance costs and access questions for the cloud industry.
What must happen and when
How the order is supposed to work
The order works in two sequential stages. Commerce must first propose and finalize identity-verification regulations; only after those rules are final — and 180 additional days have elapsed — can special-measure account restrictions be imposed on foreign actors or jurisdictions. The Secretary of Commerce can grant exemptions to providers or account types meeting security best practices. IEEPA's broad economic-sanctions powers, delegated to the Secretary, provide the legal enforcement foundation, but the actual impact on cloud providers and their customers depends entirely on the outcome of future notice-and-comment rulemaking.
Actions and deadlines
- Engage cloud industry stakeholders on information sharing and collaboration recommendations
- Propose for notice and comment regulations requiring IaaS providers to verify foreign customer identities and maintain account records
- Propose for notice and comment regulations authorizing special measures against foreign jurisdictions or persons enabling cyberattacks
- Submit report to the President recommending ways to encourage voluntary information sharing among IaaS providers and with federal agencies
- Identify funding requirements to support order implementation and incorporate into annual budget submissions to OMB
Agencies directed to act
Authority and reach
What this order changes
Amends Executive Order 13694