Improving the Nation's Cybersecurity
The order directs federal agencies and their IT contractors to overhaul U.S. government cybersecurity across five major areas: removing barriers to threat-information sharing, modernizing government systems toward Zero Trust and cloud security, securing the software supply chain, standardizing incident response, and improving detection of intrusions on federal networks.
It also establishes a permanent Cyber Safety Review Board — modeled on aviation and chemical-safety boards — to analyze significant cyber incidents and recommend improvements, reflecting a judgment that piecemeal fixes will no longer suffice against nation-state and criminal cyber actors.
What this order does
What it orders
The order directs a sweeping overhaul of federal cybersecurity on multiple parallel tracks. It requires IT and operational-technology service providers under federal contracts to share cyber threat and incident data with agencies, CISA, and the FBI, and directs OMB and the FAR Council to rewrite contracting rules to mandate that sharing. It tells all federal agencies to develop Zero Trust Architecture plans, adopt multi-factor authentication and encryption within 180 days, and deploy Endpoint Detection and Response tools across federal networks. It requires NIST to publish software supply chain security guidelines, directs agencies to obtain a Software Bill of Materials (SBOM — a formal ingredient list of software components) for products they buy, and mandates standardized incident-response procedures. It also establishes a Cyber Safety Review Board within DHS to review significant cyber incidents.
The order does not itself rewrite the FAR or impose legal obligations on private-sector software vendors; those changes depend on future rulemaking by the FAR Council after agencies submit recommendations. Most software supply chain requirements reach vendors only after a separate notice-and-comment rulemaking process. Agencies may request extensions or waivers from OMB for requirements they cannot meet on the prescribed timelines, and the order preserves all existing agency and National Security Council legal authorities.
Who it affects
Federal civilian executive branch agencies and their IT and operational-technology service providers — including cloud-service providers and software vendors — are directly directed to act. Private-sector software developers who sell to the federal government will eventually face new supply chain security and SBOM requirements once FAR rules are finalized.
Why it matters
Federal agencies must rebuild IT practices around Zero Trust and multi-factor authentication within tight deadlines. Software companies selling to the government face coming requirements to document every component in their products via an SBOM, raising development costs and transparency obligations. Taxpayers gain a new independent board to scrutinize major government cyber failures.
What must happen and when
How the order is supposed to work
Implementation follows a staged cascade: within weeks, NIST and CISA issue definitions and guidelines; within months, OMB translates those guidelines into binding agency requirements; within one year, DHS forwards recommended FAR contract language to the FAR Council, which then runs a public notice-and-comment process. CISA validates agencies' incident-response results and can trigger a Cyber Safety Review Board convening after major incidents. OMB controls the compliance timeline through extensions and waivers granted on a case-by-case basis with documented remediation plans.
Actions and deadlines
- Secretary of Homeland Security provides logging and event-retention recommendations to OMB Director
- NIST Director solicits input to develop software security standards, tools, and best practices
- Secretary of Homeland Security recommends FAR contract language for cyber incident reporting requirements
- NSA Director recommends actions for improving cyber-incident detection on National Security Systems
- OMB Director reviews FAR and DFARS requirements for IT/OT service providers and recommends updates
- Agency heads develop Zero Trust Architecture implementation plans and report to OMB and APNSA
- CISA develops and issues a cloud-service governance framework for federal civilian agencies
- Commerce Department publishes minimum required elements for a Software Bill of Materials
- NIST publishes guidance on security measures for critical software, including least-privilege and network segmentation
- GSA Administrator begins modernizing FedRAMP, including training, automation, and streamlined documentation
- NIST publishes definition of 'critical software' for use in supply chain security guidance
- Agencies establish or update Memoranda of Agreement with CISA for the Continuous Diagnostics and Mitigation Program
- OMB develops a federal cloud-security strategy and issues guidance to agencies
- CISA develops cloud-security technical reference architecture documentation for agencies
- DoD, DoJ, DHS, and DNI jointly develop procedures for sharing cyber incident reports among agencies
- CISA develops standard incident-response playbook for federal civilian agencies
- Federal civilian agencies fully adopt multi-factor authentication and encryption for data at rest and in transit
- NIST publishes preliminary guidelines for enhancing software supply chain security
- NIST identifies IoT cybersecurity criteria and secure software development criteria for consumer labeling programs
- Secretary of Homeland Security recommends FAR contract language requiring software suppliers to attest to supply chain security compliance
- NIST publishes updated software supply chain security guidelines with periodic review procedures
- Commerce Secretary provides President a report reviewing software supply chain security progress and additional steps needed