Executive Order 14028 · Signed May 12, 2021

86 FR 26633 · Published May 17, 2021 · Effective on signing

Share

Improving the Nation's Cybersecurity

cybersecurityfederal IT modernizationsoftware supply chaingovernment contractingdata security

Signed by President Joseph R. Biden Jr.

The order directs federal agencies and their IT contractors to overhaul U.S. government cybersecurity across five major areas: removing barriers to threat-information sharing, modernizing government systems toward Zero Trust and cloud security, securing the software supply chain, standardizing incident response, and improving detection of intrusions on federal networks.

It also establishes a permanent Cyber Safety Review Board — modeled on aviation and chemical-safety boards — to analyze significant cyber incidents and recommend improvements, reflecting a judgment that piecemeal fixes will no longer suffice against nation-state and criminal cyber actors.

What this order does

What it orders

The order directs a sweeping overhaul of federal cybersecurity on multiple parallel tracks. It requires IT and operational-technology service providers under federal contracts to share cyber threat and incident data with agencies, CISA, and the FBI, and directs OMB and the FAR Council to rewrite contracting rules to mandate that sharing. It tells all federal agencies to develop Zero Trust Architecture plans, adopt multi-factor authentication and encryption within 180 days, and deploy Endpoint Detection and Response tools across federal networks. It requires NIST to publish software supply chain security guidelines, directs agencies to obtain a Software Bill of Materials (SBOM — a formal ingredient list of software components) for products they buy, and mandates standardized incident-response procedures. It also establishes a Cyber Safety Review Board within DHS to review significant cyber incidents.

The order does not itself rewrite the FAR or impose legal obligations on private-sector software vendors; those changes depend on future rulemaking by the FAR Council after agencies submit recommendations. Most software supply chain requirements reach vendors only after a separate notice-and-comment rulemaking process. Agencies may request extensions or waivers from OMB for requirements they cannot meet on the prescribed timelines, and the order preserves all existing agency and National Security Council legal authorities.

Who it affects

Federal civilian executive branch agencies and their IT and operational-technology service providers — including cloud-service providers and software vendors — are directly directed to act. Private-sector software developers who sell to the federal government will eventually face new supply chain security and SBOM requirements once FAR rules are finalized.

Why it matters

Federal agencies must rebuild IT practices around Zero Trust and multi-factor authentication within tight deadlines. Software companies selling to the government face coming requirements to document every component in their products via an SBOM, raising development costs and transparency obligations. Taxpayers gain a new independent board to scrutinize major government cyber failures.

What must happen and when

How the order is supposed to work

Implementation follows a staged cascade: within weeks, NIST and CISA issue definitions and guidelines; within months, OMB translates those guidelines into binding agency requirements; within one year, DHS forwards recommended FAR contract language to the FAR Council, which then runs a public notice-and-comment process. CISA validates agencies' incident-response results and can trigger a Cyber Safety Review Board convening after major incidents. OMB controls the compliance timeline through extensions and waivers granted on a case-by-case basis with documented remediation plans.

Actions and deadlines

  • Secretary of Homeland Security provides logging and event-retention recommendations to OMB DirectorWithin 14 days of signing
  • NIST Director solicits input to develop software security standards, tools, and best practicesWithin 30 days of signing
  • Secretary of Homeland Security recommends FAR contract language for cyber incident reporting requirementsWithin 45 days of signing
  • NSA Director recommends actions for improving cyber-incident detection on National Security SystemsWithin 45 days of signing
  • OMB Director reviews FAR and DFARS requirements for IT/OT service providers and recommends updatesWithin 60 days of signing
  • Agency heads develop Zero Trust Architecture implementation plans and report to OMB and APNSAWithin 60 days of signing
  • CISA develops and issues a cloud-service governance framework for federal civilian agenciesWithin 60 days of signing
  • Commerce Department publishes minimum required elements for a Software Bill of MaterialsWithin 60 days of signing
  • NIST publishes guidance on security measures for critical software, including least-privilege and network segmentationWithin 60 days of signing
  • GSA Administrator begins modernizing FedRAMP, including training, automation, and streamlined documentationWithin 60 days of signing
  • NIST publishes definition of 'critical software' for use in supply chain security guidanceWithin 45 days of signing
  • Agencies establish or update Memoranda of Agreement with CISA for the Continuous Diagnostics and Mitigation ProgramWithin 75 days of signing
  • OMB develops a federal cloud-security strategy and issues guidance to agenciesWithin 90 days of signing
  • CISA develops cloud-security technical reference architecture documentation for agenciesWithin 90 days of signing
  • DoD, DoJ, DHS, and DNI jointly develop procedures for sharing cyber incident reports among agenciesWithin 90 days of signing
  • CISA develops standard incident-response playbook for federal civilian agenciesWithin 120 days of signing
  • Federal civilian agencies fully adopt multi-factor authentication and encryption for data at rest and in transitWithin 180 days of signing
  • NIST publishes preliminary guidelines for enhancing software supply chain securityWithin 180 days of signing
  • NIST identifies IoT cybersecurity criteria and secure software development criteria for consumer labeling programsWithin 270 days of signing
  • Secretary of Homeland Security recommends FAR contract language requiring software suppliers to attest to supply chain security complianceWithin 1 year of signing
  • NIST publishes updated software supply chain security guidelines with periodic review proceduresWithin 360 days of signing
  • Commerce Secretary provides President a report reviewing software supply chain security progress and additional steps neededWithin 1 year of signing

Agencies directed to act

Office of Management and BudgetCybersecurity and Infrastructure Security AgencyDepartment of Homeland SecurityNational Institute of Standards and TechnologyDepartment of CommerceGeneral Services AdministrationFederal Acquisition Regulatory CouncilDepartment of DefenseNational Security AgencyDepartment of JusticeFederal Bureau of InvestigationOffice of the Director of National IntelligenceFederal Trade CommissionNational Telecommunications and Information Administration

Authority and reach

Authorities cited

Article II

Constitutional grant of executive power to the President.

Homeland Security Act of 2002, § 871

Authorizes the DHS Secretary to establish advisory committees and boards within DHS.

Public Law 116-283

FY2021 National Defense Authorization Act; authorizes CISA threat-hunting on federal networks and creates the National Cyber Director.

Executive Order

Ask GovernmentReporter about this order

Ask anything about what this order does, who it affects, and how it changes policy.

Executive Order 14028: Improving the Nation's Cybersecurity | EO Reporter