Executive Order 13984 · Signed Jan 19, 2021

86 FR 6837 · Published Jan 25, 2021 · Effective on signing

Share

Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber- Enabled Activities

cybersecuritycloud computingforeign threatsnational securitytechnology regulation

Signed by President Donald Trump

The order directs the Secretary of Commerce to propose regulations requiring U.S. cloud computing providers to verify the identities of foreign customers and maintain secure account records, and separately authorizes Commerce to block or restrict foreign access to U.S. cloud services when a country or individual is found to be enabling cyberattacks.

It builds on a national emergency declared in 2015 over malicious foreign cyber activity, targeting a specific gap: foreign actors who rent U.S. server infrastructure to launch attacks and then erase their tracks before investigators can act.

What this order does

What it orders

The order directs the Secretary of Commerce to propose regulations — within 180 days — requiring U.S. Infrastructure as a Service (IaaS) providers, meaning cloud computing companies that rent server capacity, to verify the identities of foreign customers and keep secure records covering payment details, contact information, and IP addresses. It also directs Commerce to propose separate regulations enabling the Secretary to impose special measures — including blocking or conditioning foreign access to U.S. cloud accounts — when a foreign country or individual is determined to be enabling malicious cyber activities. Exemptions are available for providers or account types that meet security best practices.

The Attorney General and Secretary of Homeland Security must engage cloud industry stakeholders within 120 days and submit a report to the President within 240 days recommending ways to expand voluntary information sharing among providers and with federal agencies. Critically, account-restriction special measures cannot be imposed until at least 180 days after the identity-verification regulations are finalized, meaning the order's most consequential restrictions depend entirely on future rulemaking outcomes.

Who it affects

U.S. cloud computing companies that rent server capacity to foreign customers, foreign individuals and entities that use U.S. cloud services, foreign resellers of U.S. cloud products, and federal agencies including Commerce, Justice, and Homeland Security directed to develop and implement the new rules.

Why it matters

Once regulations are finalized, foreign customers of U.S. cloud providers will face identity-verification requirements, and providers will carry new record-keeping obligations. Foreign individuals or jurisdictions linked to cyberattacks could ultimately be denied or restricted from accessing U.S. cloud infrastructure, raising compliance costs and access questions for the cloud industry.

What must happen and when

How the order is supposed to work

The order works in two sequential stages. Commerce must first propose and finalize identity-verification regulations; only after those rules are final — and 180 additional days have elapsed — can special-measure account restrictions be imposed on foreign actors or jurisdictions. The Secretary of Commerce can grant exemptions to providers or account types meeting security best practices. IEEPA's broad economic-sanctions powers, delegated to the Secretary, provide the legal enforcement foundation, but the actual impact on cloud providers and their customers depends entirely on the outcome of future notice-and-comment rulemaking.

Actions and deadlines

  • Engage cloud industry stakeholders on information sharing and collaboration recommendationsWithin 120 days of signing
  • Propose for notice and comment regulations requiring IaaS providers to verify foreign customer identities and maintain account recordsWithin 180 days of signing
  • Propose for notice and comment regulations authorizing special measures against foreign jurisdictions or persons enabling cyberattacksWithin 180 days of signing
  • Submit report to the President recommending ways to encourage voluntary information sharing among IaaS providers and with federal agenciesWithin 240 days of signing
  • Identify funding requirements to support order implementation and incorporate into annual budget submissions to OMBNo deadline specified

Agencies directed to act

Department of CommerceDepartment of JusticeDepartment of Homeland SecurityDepartment of StateDepartment of the TreasuryDepartment of DefenseOffice of the Director of National IntelligenceOffice of Management and Budget

Authority and reach

Authorities cited

International Emergency Economic Powers Act (IEEPA)

Grants the President broad authority to regulate economic transactions during a declared national emergency.

National Emergencies Act

Establishes the legal framework for declaring and managing national emergencies.

3 U.S.C. § 301

Authorizes the President to delegate functions and duties to executive branch officers.

What this order changes

Amends Executive Order 13694

Executive Order

Ask GovernmentReporter about this order

Ask anything about what this order does, who it affects, and how it changes policy.