Prohibition on Use by the United States Government of Commercial Spyware That Poses Risks to National Security
The order prohibits all U.S. federal executive agencies from making operational use of commercial spyware that poses significant counterintelligence or security risks, or that has been misused by foreign governments to suppress dissent, target journalists, or surveil Americans without legal authorization.
It establishes a government-wide vetting and certification framework — anchored by recurring classified intelligence assessments from the Director of National Intelligence — to ensure that any spyware the government touches does not contribute to human rights abuses or expose U.S. systems and personnel to foreign exploitation.
What this order does
What it orders
The order directs all federal executive agencies to refrain from operational use of commercial spyware when a credible determination shows that the spyware poses significant counterintelligence or security risks to the U.S. government, or that it has been or risks being misused by a foreign government or person. Before any agency deploys commercial spyware operationally, a designated senior official — limited to the Secretary of Defense, Attorney General, Secretary of Homeland Security, Director of National Intelligence, CIA Director, or NSA Director — must personally certify that the product clears these risk standards. The agency must also notify the National Security Advisor at least seven days before operational use begins. The Director of National Intelligence must issue a classified intelligence assessment within 90 days and semiannually thereafter to keep agencies informed of known risks.
Agencies must review all existing commercial spyware uses within 90 days of the first intelligence assessment and discontinue any that fail the risk test as quickly as possible without compromising ongoing operations. Within 180 days of signing, each agency that may use such spyware must develop internal controls and oversight procedures. Waivers are available for up to one year in extraordinary circumstances, but only from the same short list of senior officials, and the President must be notified within 72 hours. Testing, research, cybersecurity, and criminal-investigation uses are explicitly exempted from the operational-use ban.
Who it affects
All federal executive departments and agencies that procure or operationally use commercial spyware; senior officials (Secretary of Defense, Attorney General, DNI, CIA and NSA Directors, DHS Secretary) who bear personal certification and waiver authority; the Federal Acquisition Security Council; and commercial spyware vendors whose products may be barred from U.S. government contracts.
Why it matters
Federal agencies can no longer quietly adopt commercial surveillance tools without senior-level sign-off tied to specific risk criteria. Existing spyware contracts must be audited and may be terminated. Vendors whose products have been misused by repressive governments risk being effectively locked out of the U.S. government market.
What must happen and when
How the order is supposed to work
The framework works in stages: the DNI issues a classified risk assessment within 90 days and every six months thereafter, pulling together intelligence, financial, sanctions, and export-control data. Agencies use that assessment as a baseline before procuring or deploying spyware. A named senior official must personally certify every operational deployment — that obligation cannot be delegated further down the chain — and must notify the National Security Advisor at least seven days in advance. The Federal Acquisition Security Council folds the assessments into supply-chain risk reviews. Waivers of up to one year require both a senior official's sign-off and Presidential notification within 72 hours, creating a paper trail but no hard external enforcement mechanism.
Actions and deadlines
- Director of National Intelligence issues first classified intelligence assessment on foreign commercial spyware risks
- Director of National Intelligence issues semiannual classified intelligence assessments on commercial spyware risks
- APNSA convenes agencies to discuss each intelligence assessment and share commercial spyware information
- Each agency reviews all existing operational commercial spyware uses and discontinues those posing significant risks
- Each agency that may operationally use commercial spyware develops internal controls and oversight procedures
- Agency heads submit report to APNSA on findings from review of existing commercial spyware uses
- Agency heads notify APNSA of commercial spyware procured for exempt purposes (testing, research, cybersecurity)
- Agency heads submit report to APNSA on actions taken to implement this order, including internal controls developed
- Agency heads submit annual report to APNSA identifying existing, terminated, and newly purchased commercial spyware
- Relevant official notifies President through APNSA of any decision to issue or revoke a spyware-use waiver